A digital forensics examiner is performing evidence collection on a powered-on enterprise server following a suspected breach. To ensure maximum preservation of transient evidence, the examiner must adhere strictly to the forensic Order of Volatility. Sequence the following evidence sources from most volatile (highest priority for acquisition) to least volatile (lowest priority for acquisition).
- 1Processor cache and CPU registers
- 2Physical system RAM and running process tables
- 3Swap files and pagefile space on local disk storage
- 4Offline archival backup tapes
Answer
The correct acquisition sequence from most volatile to least volatile is: Processor cache and CPU registers, followed by Physical system RAM and running process tables, followed by Swap files and pagefile space on local disk storage, and ending with Offline archival backup tapes.
Standard digital forensics practices (RFC 3227) require collecting evidence in order of volatility to prevent losing perishable data. CPU registers and cache change at instruction-level speeds and are most volatile. Physical RAM loses contents upon reboot or power-off. Swap and pagefiles reside on disk but hold temporary, frequently modified memory blocks. Offline archival tapes are static physical media stored offsite, making them the least volatile.
Step-by-Step Solution
Key Concept
Order of Volatility in Digital Forensics