A security analyst is conducting live evidence acquisition on a compromised application server following a suspected data exfiltration attempt. The analyst needs to preserve network statistics, system RAM, swap space, and non-volatile storage while minimizing data alteration. According to the standard order of volatility, which of the following evidence types should the analyst acquire FIRST?
- Routing table and active network connectionsCevap
- BContents of the system swap file and pagefile
- CBit-stream disk image of the main partition
- DCentralized SIEM event log repository
Cevap
Routing table and active network connections must be acquired first because they are the most volatile form of evidence listed.
In digital forensics, the order of volatility governs evidence collection sequence to prevent data loss. According to RFC 3227, highly dynamic system states—such as CPU registers, routing tables, ARP caches, kernel statistics, and active network connections—must be captured before secondary storage like swap space or local hard drives.
Adım Adım Çözüm
Anahtar Kavram
Order of Volatility in Digital Forensics