Following an automated alert indicating potential fileless malware activity on an operational database server, a security analyst must collect volatile digital evidence prior to server isolation. Adhering strictly to the standard order of volatility, which of the following data sources should the analyst acquire FIRST?
- CPU registers and cache contentsCevap
- BPhysical RAM and active process tables
- CSwap space and temporary file systems
- DBit-stream image of the primary storage drive
Cevap
CPU registers and cache contents should be acquired first because they represent the most volatile data layer on a system.
The correct answer identifies CPU registers and cache contents as the most volatile components. According to the forensic order of volatility, evidence collection must begin with the shortest-lived data sources to prevent evidence destruction.
Adım Adım Çözüm
Anahtar Kavram
Order of Volatility in Digital Forensics
Tahmini Süre:1m 15s