A forensic investigator started the process of gathering evi - CompTIA CAS-005

Question

A forensic investigator started the process of gathering evidence on a laptop in response to an incident. The investigator took a snapshot of the hard drive, copied relevant log files, and then performed a memory dump. Which of the following steps in the process should have occurred FIRST? 

Answers
  1. correct
Explanation

The correct answer is: C. Collect the most volatile data.

In digital forensics, the order of volatility dictates the sequence of evidence collection, starting with the most volatile (easily lost or altered) data. The investigator should have collected the most volatile data first, such as system memory (RAM), network connections, and running processes, because this data is temporary and could be lost if the system is powered down or restarted.

The correct sequence for evidence collection is:

  1. Most volatile data: Memory (RAM), network connections, active processes.
  2. Moderately volatile data: Temporary files, system logs.
  3. Least volatile data: Hard drive contents, archived logs.

In this case, the investigator performed a memory dump after other actions, which violates the principle of collecting volatile data first.

Why the other options are incorrect:

Preserve secure storage:

  • Incorrect: Secure storage is essential for maintaining the integrity of the evidence after collection but is not the first step in the evidence collection process.

Clone the disk:

  • Incorrect: Cloning the disk is a method of preserving non-volatile data (e.g., hard drive contents). However, this should occur after collecting volatile data, as it is less likely to be lost or altered.

Copy the relevant log files:

  • Incorrect: Log files are less volatile than memory and should be collected after more volatile data has been preserved.

No Payment Cards Needed

Related Courses

Discover a range of courses designed to provide you with the knowledge and skills needed to excel in your chosen field.

a prepsaret exam featured image
CompTIA Prep

220-1201 - CompTIA A+ Exam Core 1

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

220-1202 - CompTIA A+ Exam Core 2

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud Essentials+ CLO-002

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Network+ N10-009

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Security+ SY0-701

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Data + DA0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Pentest+

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Linux+ XK0-005

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA CySA+ CSO-003

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA DataSys+ DS0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Tech+ FC0-U71

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud+ CV0-004

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Server+ SK0-005

Start Course Prep

Easy way to pass your test within a week with prepsaret

You don’t need one month to study and pass your test.
With Prepsaret, it takes you a few days to grasp all the concepts needed to pass your exams

View Courses Offered