During an incident response investigation involving a compromised enterprise database server suspected of running an in-memory fileless payload, a forensic team must preserve digital evidence for potential judicial proceedings. Which of the following procedures should the team perform FIRST to adhere strictly to the order of volatility?
- ADeploy a hardware write-blocker to acquire a bit-stream forensic image of the primary non-volatile storage drive.
- Capture the contents of volatile system memory to external forensic media.Cevap
- CGenerate and log cryptographic hashes for all database files directly on the live operating system volume.
- DInitiate a graceful system shutdown to prevent remote execution and isolate log files on disk.
Cevap
Capturing the contents of volatile system memory to external forensic media must be performed first.
Capturing the contents of volatile system memory to external forensic media is the correct action because system RAM ranks higher in the order of volatility than persistent disk drives. In-memory payloads and volatile system states (such as active network sockets and running processes) are completely lost if the system is powered off or modified prior to acquisition.
Adım Adım Çözüm
Anahtar Kavram
Order of Volatility in Digital Forensics
Tahmini Süre:1m 15s