CS0-003 Incident Response and Management Practice Question
An analyst is investigating a suspected data breach. The analyst needs to identify which files were exfiltrated and preserve evidence. According to the order of volatility, which of the following should the analyst capture FIRST?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CPU registers and cache
Order of volatility prioritizes capturing volatile data first. CPU registers and cache are the most volatile, then RAM, swap, disk, etc.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Contents of the hard drive
Why it's wrong here
Hard drives contain non-volatile data that persists even after the system is powered down. According to RFC 3227 guidelines, physical storage media is positioned much lower on the order of volatility scale compared to CPU cache or system RAM. Capturing disk images first is a forensic error because the process will inevitably overwrite highly transient memory states.
- ✗
Network connections and listening ports
Why it's wrong here
While active network connections and open socket states are highly volatile and reside in RAM, they are less transient than CPU register states. Collecting network state data requires executing commands or tools that will inevitably alter the CPU registers and cache. Therefore, network state acquisition must occur after register and memory capture to prevent evidence contamination.
- ✓
CPU registers and cache
Why this is correct
CPU registers and L1/L2/L3 caches represent the absolute highest tier of volatility in digital forensics. This data changes nanosecond by nanosecond as the processor executes instructions, and it is completely lost the moment any tool is run or the system state changes. Analysts must capture this ultra-transient data first to preserve the immediate execution state of the system.
- ✗
System logs
Why it's wrong here
System logs are typically written to persistent storage media, such as solid-state drives or hard disks, or forwarded to a remote SIEM. Because this information is written to non-volatile disk space, it is highly stable and resilient to power loss. Consequently, logs are collected near the end of the forensic acquisition process, well after volatile memory has been secured.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.