Soru

Zorluk: OrtaDigital Forensics and Chain of Custody

During an active incident investigation on an enterprise Linux application server, an incident responder detects suspicious process execution originating from a kernel module. The server remains powered on and connected to the internal network segment. To preserve evidence while minimizing the loss of transient data, which of the following actions should the analyst perform FIRST according to the order of volatility?

  1. Capture the system RAM using a specialized live memory acquisition tool.Cevap
  2. B
    Power down the system immediately and make a bit-stream copy of the storage drive.
  3. C
    Generate a cryptographic hash of the active system log files directly on the live file system.
  4. D
    Encrypt the primary storage partition using a newly generated asymmetric public key.

Cevap

The incident responder should capture the system RAM using a specialized live memory acquisition tool prior to acquiring non-volatile storage or altering system state.
Capturing system RAM using a live acquisition tool is the correct initial action because volatile memory contains temporary process states, network connections, and loaded kernel modules that are permanently erased when the machine is shut down. According to the order of volatility, memory collection must precede persistent drive imaging.

Adım Adım Çözüm

1
Identify the volatility level of candidate evidence sources.
System RAM and CPU registers are categorized as highly volatile, while local disk storage and network logs are far less volatile.
The order of volatility dictates collecting the most transient data first before it is modified or permanently lost.
2
Perform live acquisition of volatile memory.
A memory dump image is saved to secure external storage.
Preserving running processes, kernel structures, and active connections requires live RAM capture before system power state alterations occur.
3
Calculate and record cryptographic hashes of the memory dump file.
Integrity baseline is established for chain of custody tracking.
Ensures that acquired forensic artifacts can be validated against subsequent modifications during legal proceedings.

Anahtar Kavram

Order of Volatility in Digital Forensics
Bu soruyu puanla