nerdexam
EC-Council

312-49 · Question #480

Volatile information can be easily modified or lost when the system is shut down or rebooted. It helps to determine a logical timeline of the security incident and the users who would be responsible.

The correct answer is A. True. This statement is True. Volatile information - such as running processes, active network connections, logged-in users, clipboard contents, and RAM contents - exists only while the system is powered on and is lost upon shutdown or reboot. Despite (or because of) its transient…

Submitted by carlos_mx· Apr 18, 2026Computer Forensics Investigation Process

Question

Volatile information can be easily modified or lost when the system is shut down or rebooted. It helps to determine a logical timeline of the security incident and the users who would be responsible.

Options

  • ATrue
  • BFalse

How the community answered

(29 responses)
  • A
    93% (27)
  • B
    7% (2)

Explanation

This statement is True. Volatile information - such as running processes, active network connections, logged-in users, clipboard contents, and RAM contents - exists only while the system is powered on and is lost upon shutdown or reboot. Despite (or because of) its transient nature, it is extremely valuable in digital forensics: it can reveal active attacker sessions, malicious processes, encryption keys in memory, and help construct a timeline of events. Forensic investigators must collect volatile data first, before any other action that might alter system state.

Topics

#Volatile Data#Forensic Evidence#Incident Response#Data Volatility

Community Discussion

No community discussion yet for this question.

Full 312-49 Practice