CS0-003 Incident Response and Management Practice Question
During forensic analysis of a compromised server, an analyst needs to preserve evidence in order of volatility. Which of the following actions should the analyst perform FIRST?
⚠ Common exam trap
The trap is prioritizing the disk image or logs because they feel like 'the evidence,' when the order of volatility demands the most ephemeral source — RAM — be captured first.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Acquire a memory dump using WinPmem
The order of volatility dictates collecting the most perishable evidence first. RAM contents — running processes, network connections, encryption keys, and injected code — vanish on reboot or power loss, so acquiring a memory dump with a tool like WinPmem must be the first action. Only after memory is captured should the analyst move to less volatile sources.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Collect log files from the system
Why it's wrong here
While log files contain critical audit trails and event data, they reside on non-volatile storage media. According to the Order of Volatility (RFC 3227), system memory (RAM) must be preserved before gathering persistent disk-based data like event logs. Collecting logs first risks overwriting volatile artifacts in memory due to disk I/O and process execution.
- ✗
Create a forensic image of the hard drive
Why it's wrong here
Creating a bit-stream image of a hard drive is a crucial step in forensic preservation, but it must occur after capturing volatile memory. The process of imaging a disk generates significant system activity and can overwrite active RAM contents, such as running processes, network connections, and decrypted keys. Therefore, disk imaging is prioritized lower on the volatility scale than memory acquisition.
- ✗
Run antivirus scan
Why it's wrong here
Executing an active antivirus scan on a compromised live system is highly destructive to forensic integrity. The scan modifies file access timestamps (atime), loads new drivers into memory, and may automatically quarantine or delete malicious artifacts. This compromises the chain of custody and destroys volatile evidence before it can be properly imaged and analyzed.
- ✓
Acquire a memory dump using WinPmem
Why this is correct
Volatile memory (RAM) contains transient data such as active network connections, running processes, and unencrypted cryptographic keys that are lost upon system shutdown or reboot. Utilizing a dedicated tool like WinPmem allows analysts to capture a physical memory dump immediately after securing the system. This adheres strictly to the Order of Volatility, ensuring critical, short-lived evidence is preserved before any disk-based collection occurs.
Go deeper
Related to this question
Learn chapter
Network Forensics: Packet Capture Analysis
Key term
Analysis
In incident response, analysis is the process of examining data and events to determine what happened, how it happened, and what actions to take.
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.