Following an automated alert indicating potential fileless malware activity on an operational database server, a security analyst must collect volatile digital evidence prior to server isolation. Adhering strictly to the standard order of volatility, which of the following data sources should the analyst acquire FIRST?
- CPU registers and cache contentsAnswer
- BPhysical RAM and active process tables
- CSwap space and temporary file systems
- DBit-stream image of the primary storage drive
Answer
CPU registers and cache contents should be acquired first because they represent the most volatile data layer on a system.
The correct answer identifies CPU registers and cache contents as the most volatile components. According to the forensic order of volatility, evidence collection must begin with the shortest-lived data sources to prevent evidence destruction.
Step-by-Step Solution
Key Concept
Order of Volatility in Digital Forensics
Estimated Time:1m 15s