CAS-004 Security Operations Practice Question
During a digital forensics investigation of a compromised Linux server, the investigator needs to preserve the evidence in a forensically sound manner. The server is still running. Which of the following should the investigator do first?
⚠ Common exam trap
The trap is thinking 'preserve the disk first' — but on a live system, order of volatility means RAM must be captured before anything else, and pulling the plug is the worst possible action.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Capture the contents of RAM using a tool like LiME or fmem
On a live system, volatile data — RAM contents, running processes, network connections, and encryption keys — is lost the moment power is cut or the system is rebooted. Order of volatility (RFC 3227) dictates capturing RAM first using tools like LiME or fmem before touching the disk. This preserves evidence that may never exist on disk, such as in-memory malware or active sessions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Pull the power cord to preserve the disk state
Why it's wrong here
Pulling the power cord destroys volatile evidence in RAM — running processes, network connections and encryption keys — and can corrupt the filesystem, so it is not forensically sound. It is tempting because it freezes the disk instantly, which would suit a powered-off machine where live memory is irrelevant.
- ✗
Create a forensic image of the hard drive using dd over a network connection
Why it's wrong here
Imaging the disk over the network while the server runs changes the disk as dd reads it, producing an inconsistent, non-verifiable image. It is tempting because dd creates a bit-for-bit copy, which is correct once the system is halted or the volume is write-blocked.
- ✗
Run the 'history' command to see recent user commands
Why it's wrong here
Running 'history' alters the shell's state and only shows the current user's cached commands, not system-wide activity; it also overwrites evidence. It is tempting because command history is genuinely useful for tracing attacker actions, but only after volatile memory and disk have been captured in the correct order.
- ✓
Capture the contents of RAM using a tool like LiME or fmem
Why this is correct
RAM contents are volatile and lost on shutdown, so capturing memory with LiME or fmem first preserves evidence that would otherwise vanish. Order of volatility demands memory acquisition before disk imaging on a live system.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.