nerdexam
CompTIA

CAS-003 · Question #112

An investigator wants to collect the most volatile data first in an incident to preserve the data that runs the highest risk of being lost. After memory, which of the following BEST represents the…

The correct answer is C. System processes, network processes, file system information, swap files and raw disk blocks. The order in which you should collect evidence is referred to as the Order of volatility. Generally, evidence should be collected from the most volatile to the least volatile. The order of volatility from most volatile to least volatile is as follows: Data in RAM, including CPU…

Enterprise Security Operations

Question

An investigator wants to collect the most volatile data first in an incident to preserve the data that runs the highest risk of being lost. After memory, which of the following BEST represents the remaining order of volatility that the investigator should follow?

Options

  • AFile system information, swap files, network processes, system processes and raw disk blocks.
  • BRaw disk blocks, network processes, system processes, swap files and file system information.
  • CSystem processes, network processes, file system information, swap files and raw disk blocks.
  • DRaw disk blocks, swap files, network processes, system processes, and file system information.

How the community answered

(59 responses)
  • A
    5% (3)
  • B
    15% (9)
  • C
    71% (42)
  • D
    8% (5)

Explanation

The order in which you should collect evidence is referred to as the Order of volatility. Generally, evidence should be collected from the most volatile to the least volatile. The order of volatility from most volatile to least volatile is as follows: Data in RAM, including CPU cache and recently used data and applications Data in RAM, including system and network processes Swap files (also known as paging files) stored on local disk drives Data stored on local disk drives Logs stored on remote systems

Topics

#order of volatility#digital forensics#evidence collection#incident investigation

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice