CAS-004 Security Engineering Practice Question
A security analyst is investigating a compromised Linux web server. The analyst needs to preserve volatile evidence before shutting the system down for forensic imaging. Which action should the analyst perform FIRST?
⚠ Common exam trap
The trap here is equating thoroughness with starting at the disk image, when the perishable memory and network state must be captured before any shutdown or lengthy disk operation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Capture the contents of physical memory and the current network connections.
Forensic handling follows the order of volatility, so the most transient data is collected first. RAM and network connections vanish on power loss or reboot, while disk contents persist. Capturing memory and live connections before imaging or analysis preserves evidence that would otherwise be unrecoverable.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a forensic image of the server's disk drives.
Why it's wrong here
A disk image is essential evidence, but disks are far less volatile than memory and network state. Imaging first delays the capture of RAM and active sockets, which may disappear during the imaging process, so this order violates the principle of volatility.
- ✗
Review the application and system logs for signs of intrusion.
Why it's wrong here
Log review is investigative work that can be done later from preserved copies. Doing it first consumes time while volatile memory and network connections continue to change or vanish, and it risks altering file access timestamps on the original system.
- ✓
Capture the contents of physical memory and the current network connections.
Why this is correct
Order of volatility dictates that the most perishable evidence, such as RAM contents and active network connections, must be collected before anything else because it is lost on shutdown or even over time. Capturing memory and live connections first preserves artifacts that no disk image can recover.
- ✗
Shut down the server gracefully to prevent further attacker activity.
Why it's wrong here
Shutting down the system destroys RAM contents, running processes, and established network connections, eliminating the most volatile evidence. Containment matters, but graceful shutdown is the wrong first step when live forensic data still needs to be preserved.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.