nerdexam
CompTIA

SY0-501 · Question #264

Joe a computer forensic technician responds to an active compromise of a database server. Joe first collects information in memory, then collects network traffic and finally conducts an image of the…

The correct answer is A. Order of volatility. When collecting digital forensic evidence, technicians must gather data in order of volatility - most volatile (RAM) to least volatile (disk) - to preserve evidence that would otherwise be lost.

Submitted by anjalisingh· Mar 4, 2026Security operations

Question

Joe a computer forensic technician responds to an active compromise of a database server. Joe first collects information in memory, then collects network traffic and finally conducts an image of the hard drive. Which of the following procedures did Joe follow?

Options

  • AOrder of volatility
  • BChain of custody
  • CRecovery procedure
  • DIncident isolation

How the community answered

(46 responses)
  • A
    80% (37)
  • B
    11% (5)
  • C
    7% (3)
  • D
    2% (1)

Why each option

When collecting digital forensic evidence, technicians must gather data in order of volatility - most volatile (RAM) to least volatile (disk) - to preserve evidence that would otherwise be lost.

AOrder of volatilityCorrect

Order of volatility is a forensic principle dictating that evidence should be collected starting with the most transient data first. RAM (in-memory data) is lost when power is removed, network traffic dissipates in seconds, and hard drive images are stable and can be captured last. Joe followed this exact sequence: memory → network traffic → disk image.

BChain of custody

Chain of custody refers to the documented chronological record tracking who handled evidence and when, not the sequence in which evidence types are collected.

CRecovery procedure

Recovery procedure refers to the steps taken to restore a system to normal operation after an incident, not the prioritized order in which forensic evidence is gathered.

DIncident isolation

Incident isolation refers to containing or segmenting a compromised system to prevent further spread of an attack, not the methodology for collecting forensic evidence.

Concept tested: Digital forensics order of volatility evidence collection

Source: https://www.nist.gov/system/files/documents/2017/05/09/SP800-86.pdf

Topics

#order of volatility#digital forensics#incident response#memory forensics

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice