A cybersecurity analyst is responding to an active incident on a powered-on workstation. The analyst must capture digital evidence while strictly adhering to the order of volatility. Which of the following evidence sources should the analyst capture FIRST?
- System RAM (Random Access Memory)Answer
- BLocal hard disk drive image
- CNetwork shared drive logs
- DArchival magnetic tape backups
Answer
System RAM (Random Access Memory) must be captured first because it is the most volatile evidence source among the given choices.
System RAM contains transient data that is permanently lost if the machine is powered off or restarted. Forensic standards require capturing volatile memory before non-volatile media to preserve active processes, network connections, and unencrypted data.
Step-by-Step Solution
Key Concept
Order of Volatility in Digital Forensics