Courseiva
Security OperationseasyMultiple ChoiceObjective-mapped

Order of Volatility: Capture RAM First Before Shutdown

A laptop is suspected of being compromised, and the responder wants to preserve useful evidence before shutting it down. What should be done first?

Quick Answer

The correct answer is to capture volatile data such as memory and running processes first. This is because of the forensic principle known as the order of volatility, which dictates that the most fragile and easily lost evidence must be collected before anything else; RAM contents, active network connections, and process lists vanish the instant the laptop loses power or is shut down. On the Security+ SY0-701 exam, this concept tests your understanding of evidence preservation and incident response procedures, often appearing in scenario-based questions where a responder must prioritize actions. A common trap is to immediately pull the plug or image the hard drive, but that destroys the very evidence of active malware or attacker footholds. Remember the memory tip: “RAM is the first to scram” — capture what’s in memory before you even think about powering off.

⚠ Common exam trap

Many exam-takers think immediate shutdown stops the attack, but CompTIA tests the forensic principle that volatile data must be captured first to preserve evidence that disappears on power loss.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Capture volatile data such as memory and running processes if possible.

Volatile data (e.g., RAM contents, running processes, network connections) is lost when the laptop is powered off. Capturing this data first preserves critical evidence of the attacker's current activity, such as malware in memory or active network connections, which is essential for forensic analysis. This aligns with the forensic principle of order of volatility, where the most volatile data is collected first.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Power off the laptop immediately to stop all attacker activity.

    Why it's wrong here

    Immediate power-off can destroy volatile evidence such as running processes, network connections, and memory-resident malware. It may help containment, but not before evidence is considered.

  • Capture volatile data such as memory and running processes if possible.

    Why this is correct

    Capturing volatile data is the best first step when preserving evidence matters. Memory can contain malware code, encryption keys, active network sessions, and signs of lateral movement that disappear after shutdown. In incident response, responders try to preserve the most time-sensitive evidence before disrupting the system, as long as doing so is safe and approved.

  • Install a new antivirus product before collecting evidence.

    Why it's wrong here

    Installing software changes the system state and can overwrite important forensic evidence. It is better to preserve the original condition first.

  • Reimage the laptop so the user can return to work quickly.

    Why it's wrong here

    Reimaging too early destroys evidence and can make root-cause analysis impossible. Recovery should happen after containment and evidence capture.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on SY0-701

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A laptop is suspected of being used in a malware incident. It is still powered on and connected to Wi-Fi. What should the responder do before shutting it down?

easy
  • A.Install endpoint protection updates on the laptop right away.
  • B.Capture volatile evidence such as running processes and memory contents.
  • C.Delete suspicious files so the malware can no longer spread.
  • D.Reboot the laptop immediately to clear the suspected malware.

Why B: Volatile evidence, such as running processes, network connections, and memory contents, is lost when the system is powered off. Capturing this data first preserves critical forensic artifacts that can reveal the malware's behavior, persistence mechanisms, and indicators of compromise (IOCs). In a live incident, the responder must follow the order of volatility (RFC 3227) to collect the most ephemeral data before it disappears.

Variation 2. A Windows laptop is believed to be involved in a credential-theft incident. It is still powered on, connected to Wi-Fi, and the user reports that the screen recently locked by itself. The SOC can reach the device remotely through EDR. Which two actions should be taken before the laptop is shut down? Select two.

hard
  • A.Capture volatile data such as running processes and active network connections while the system is still live.
  • B.Place the endpoint into network isolation through the EDR console to stop further attacker communication.
  • C.Run a full antivirus scan immediately, because the scan report will serve as the primary evidence.
  • D.Reboot the laptop into Safe Mode so the attacker’s code will not load.
  • E.Power off the laptop immediately to prevent the incident from spreading further.

Why A: Capturing volatile data (e.g., running processes, active network connections, memory contents) is critical because it is lost when the system is powered off, so it must be collected while the laptop is still live to preserve evidence of the attacker's current activities. Additionally, placing the endpoint into network isolation through the EDR console stops further attacker communication and prevents additional data loss or lateral movement, and it does not destroy volatile evidence. Running a full antivirus scan, rebooting into Safe Mode, or powering off would destroy critical volatile evidence or alter the system state, so they must be avoided.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.