hardMultiple Choice
CS0-003 Practice Question: An incident responder is collecting evidence from…
An incident responder is collecting evidence from a compromised Linux server. The server is still running. Which order of collection adheres to the order of volatility?
⚠ Common exam trap
The CS0-004 exam often tests the misconception that swap space is less volatile than disk because it is on disk, but swap is actually more volatile due to frequent overwriting by the kernel's paging mechanism.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Memory → network connections → swap space → disk.
The order of volatility (OOV) dictates that the most volatile data (memory/registers) must be collected first, followed by network connections, then swap space, and finally disk. Memory contains running processes and encryption keys that vanish on power loss; network connections change rapidly; swap space persists longer but is still more volatile than disk. This sequence ensures maximum preservation of ephemeral evidence before it is lost.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Memory → network connections → disk → swap space.
Why it's wrong here
Collecting disk before swap space is an incorrect sequence in the order of volatility. While both reside on persistent storage, swap space functions as an extension of RAM, holding potentially active process data that is more transient and critical to capture early than general file system contents. Therefore, swap space is considered more volatile than the entire disk's static data and should precede it in forensic evidence collection to preserve dynamic system state.
- ✗
Disk → memory → network connections → swap space.
Why it's wrong here
Initiating evidence collection with disk is fundamentally flawed because disk storage is the least volatile component among the options presented. Critical volatile data residing in memory and active network connections would likely be lost or altered before collection could even begin if disk were prioritized. The principle of forensic evidence collection dictates securing the most ephemeral data first to preserve its integrity and prevent data degradation.
- ✓
Memory → network connections → swap space → disk.
Why this is correct
This sequence correctly adheres to the standard order of volatility for digital forensic evidence collection, ensuring the most ephemeral data is captured first. Memory (RAM) is the most volatile, holding active process data that is lost upon power loss. Network connections represent active communication states, followed by swap space, which contains spilled-over memory pages. Finally, persistent disk storage is the least volatile, preserving data even after power cycles.
- ✗
Network connections → memory → disk → swap space.
Why it's wrong here
Collecting network connections before memory is an incorrect approach in forensic evidence preservation. Memory (RAM) contains the live state of the operating system, including the very data structures and processes that establish and maintain network connections. Prioritizing network connections risks missing crucial in-memory artifacts that provide context and detail about those connections, making memory collection paramount to capture the complete picture of system activity.
Go deeper
Related to this question
Learn chapter
Lessons Learned and Post-Incident Activities
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.