SY0-501 · Question #264
Joe a computer forensic technician responds to an active compromise of a database server. Joe first collects information in memory, then collects network traffic and finally conducts an image of the…
The correct answer is A. Order of volatility. When collecting digital forensic evidence, technicians must gather data in order of volatility - most volatile (RAM) to least volatile (disk) - to preserve evidence that would otherwise be lost.
Question
Joe a computer forensic technician responds to an active compromise of a database server. Joe first collects information in memory, then collects network traffic and finally conducts an image of the hard drive. Which of the following procedures did Joe follow?
Options
- AOrder of volatility
- BChain of custody
- CRecovery procedure
- DIncident isolation
How the community answered
(46 responses)- A80% (37)
- B11% (5)
- C7% (3)
- D2% (1)
Why each option
When collecting digital forensic evidence, technicians must gather data in order of volatility - most volatile (RAM) to least volatile (disk) - to preserve evidence that would otherwise be lost.
Order of volatility is a forensic principle dictating that evidence should be collected starting with the most transient data first. RAM (in-memory data) is lost when power is removed, network traffic dissipates in seconds, and hard drive images are stable and can be captured last. Joe followed this exact sequence: memory → network traffic → disk image.
Chain of custody refers to the documented chronological record tracking who handled evidence and when, not the sequence in which evidence types are collected.
Recovery procedure refers to the steps taken to restore a system to normal operation after an incident, not the prioritized order in which forensic evidence is gathered.
Incident isolation refers to containing or segmenting a compromised system to prevent further spread of an attack, not the methodology for collecting forensic evidence.
Concept tested: Digital forensics order of volatility evidence collection
Source: https://www.nist.gov/system/files/documents/2017/05/09/SP800-86.pdf
Topics
Community Discussion
No community discussion yet for this question.