Courseiva

CS0-003 Incident Response and Management Practice Question

During forensic analysis of a compromised server, an analyst needs to preserve evidence in order of volatility. Which of the following actions should the analyst perform FIRST?

⚠ Common exam trap

The trap is prioritizing the disk image or logs because they feel like 'the evidence,' when the order of volatility demands the most ephemeral source — RAM — be captured first.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Acquire a memory dump using WinPmem

The order of volatility dictates collecting the most perishable evidence first. RAM contents — running processes, network connections, encryption keys, and injected code — vanish on reboot or power loss, so acquiring a memory dump with a tool like WinPmem must be the first action. Only after memory is captured should the analyst move to less volatile sources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Collect log files from the system

    Why it's wrong here

    While log files contain critical audit trails and event data, they reside on non-volatile storage media. According to the Order of Volatility (RFC 3227), system memory (RAM) must be preserved before gathering persistent disk-based data like event logs. Collecting logs first risks overwriting volatile artifacts in memory due to disk I/O and process execution.

  • ✗

    Create a forensic image of the hard drive

    Why it's wrong here

    Creating a bit-stream image of a hard drive is a crucial step in forensic preservation, but it must occur after capturing volatile memory. The process of imaging a disk generates significant system activity and can overwrite active RAM contents, such as running processes, network connections, and decrypted keys. Therefore, disk imaging is prioritized lower on the volatility scale than memory acquisition.

  • ✗

    Run antivirus scan

    Why it's wrong here

    Executing an active antivirus scan on a compromised live system is highly destructive to forensic integrity. The scan modifies file access timestamps (atime), loads new drivers into memory, and may automatically quarantine or delete malicious artifacts. This compromises the chain of custody and destroys volatile evidence before it can be properly imaged and analyzed.

  • ✓

    Acquire a memory dump using WinPmem

    Why this is correct

    Volatile memory (RAM) contains transient data such as active network connections, running processes, and unencrypted cryptographic keys that are lost upon system shutdown or reboot. Utilizing a dedicated tool like WinPmem allows analysts to capture a physical memory dump immediately after securing the system. This adheres strictly to the Order of Volatility, ensuring critical, short-lived evidence is preserved before any disk-based collection occurs.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.