CHFI Incident Response and First Responder Skills Practice Question
A first responder is handling a compromised Linux server that is still powered on and actively communicating with an unknown external IP. The responder needs to collect volatile evidence while minimizing disruption. Which TWO actions should be performed to preserve the most volatile data in the correct order? (Choose two.)
⚠ Common exam trap
The trap here is thinking that pulling the plug or imaging the disk first is acceptable, when volatile network and process data must be captured before any such actions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run 'netstat -antp' to capture current network connections and associated processes.
The most volatile data on a running Linux system includes network connections and running processes. Capturing netstat -antp and ps aux first preserves this time-sensitive evidence. Full disk imaging and permission changes are either non-volatile or destructive and should not be performed before volatile data is secured. Following the order of volatility ensures critical evidence is not lost.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Run 'netstat -antp' to capture current network connections and associated processes.
Why this is correct
Capturing network connections and associated processes is a high-priority volatile data source. netstat -antp shows active TCP connections, listening ports, and the PID/program name, which can reveal command-and-control channels. This should be done before any shutdown or service restart, as the information disappears once connections close. It aligns with the order of volatility by capturing network state early.
- ✗
Immediately pull the power plug to prevent further data exfiltration.
Why it's wrong here
Pulling the power plug is a destructive action that eliminates all volatile evidence in RAM and network state. It also may corrupt the file system. In incident response, live systems should be handled carefully to preserve evidence unless there is an immediate threat to life or safety. This action violates the order of volatility and would destroy critical artifacts.
- ✗
Run 'chmod -R 000 /var/log' to protect log files from tampering.
Why it's wrong here
Changing permissions on log directories modifies the system and can disrupt logging, potentially destroying evidence. It does not preserve volatile data and may alert an attacker. This action is not part of standard volatile evidence collection and could be considered tampering. Logs should be collected and preserved, not altered in place.
- ✓
Run 'ps aux' to capture the list of running processes.
Why this is correct
Running ps aux captures a snapshot of all running processes, including user, PID, CPU, and memory usage. This is volatile data that can reveal malicious processes. It should be collected early, before any process termination or system shutdown. Together with network connections, process listing provides a comprehensive view of live system activity for forensic analysis.
- ✗
Run 'dd if=/dev/sda of=/mnt/external/disk.img' to image the entire disk.
Why it's wrong here
Creating a full disk image is a non-volatile data collection step and should be done after volatile data is captured. It can take a long time and may alter system state by mounting external drives or consuming resources. Imaging the disk first would delay capturing network and process information that may disappear. The order of volatility requires volatile data first.
Go deeper
Related to this question
Learn chapter
Linux and Mac Forensics
Key term
Process Memory Dump
A process memory dump is a snapshot of all the data a specific running program has stored in RAM at a single moment, used for analyzing its behavior and contents.
Key term
Disk Imaging
Disk imaging is the process of creating an exact, bit-for-bit copy of a storage drive, preserving all data, deleted files, and unallocated space for forensic analysis or system recovery.
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official EC-Council exam blueprint
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.