An incident responder is preparing to collect digital evidence from a powered-on corporate workstation suspected of compromise. According to standard forensic evidence collection guidelines (Order of Volatility), in what sequence should the responder capture the following components, from MOST volatile to LEAST volatile?
- 1CPU registers and processor cache
- 2System RAM (Random Access Memory)
- 3Pagefile / Swap space on the local drive
- 4Off-site archival backup tape
Cevap
The correct sequence from most volatile to least volatile is: CPU registers and processor cache, System RAM (Random Access Memory), Pagefile / Swap space on the local drive, and Off-site archival backup tape.
Digital forensics principles dictate collecting evidence starting with the most fragile, transient data (CPU cache/registers), moving sequentially through dynamic main memory (RAM), temporary disk files (swap/pagefile), and ending with static offline media (archival tapes).
Adım Adım Çözüm
Anahtar Kavram
Order of Volatility in Digital Forensics