Courseiva

CHFI Incident Response and First Responder Skills Practice Question

A security team suspects a data breach via an external attacker. The incident response plan requires preservation of evidence for legal proceedings. Which order of volatility should the first responder follow?

⚠ Common exam trap

EC-Council often tests the misconception that disk images are the most critical evidence, leading candidates to prioritize them over volatile memory and network state, which is the exact opposite of the correct order of volatility.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Capture memory, record network connections, acquire disk image, then collect backups.

The order of volatility (OOV) dictates that the most volatile data (memory/registers) must be captured first, followed by network connections, then disk images, and finally backups. This sequence minimizes data loss and ensures evidence integrity for legal proceedings, as volatile data is lost when power is removed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Capture disk image, then memory, then network connections.

    Why it's wrong here

    This order violates the order of volatility by starting with disk, which is persistent, before capturing memory and active network connections. Memory holds live attacker artifacts—such as decrypted data, process memory, and injected code—that vanish immediately on power loss, while network sessions can terminate before a disk image completes. Additionally, running an acquisition tool on the live system while prioritizing disk can alter volatile evidence. Therefore, disk imaging must come after memory and network state are secured.

  • ✗

    Record network connections, capture disk image, then memory.

    Why it's wrong here

    This order incorrectly captures network connections before memory, but more critically it saves memory for last. Memory is the most volatile category and must be acquired first; active TCP/UDP connections are also volatile, but they can be re-identified from memory and later from packet captures, whereas the contents of RAM cannot be recovered after a reboot. Placing disk imaging before memory means the RAM image, which could contain the attacker's active tooling, encryption keys, or staged exfiltration data, is lost. The correct sequence is memory, then network state, then disk, not the reverse.

  • ✓

    Capture memory, record network connections, acquire disk image, then collect backups.

    Why this is correct

    This is the correct order of volatility: memory first because RAM contains live evidence like decryption keys, running processes, and transient malware that disappears on shutdown; network connections second because they show active command-and-control sessions and can vanish with session teardown; disk image third because persistence preserves it for later analysis; and backups last because they are the least volatile and can be obtained at any time. This sequence maximizes evidence preservation and aligns with RFC 3227 and NIST forensic guidelines, while also supporting a defensible chain of custody.

  • ✗

    Collect backups first, then disk image, then memory.

    Why it's wrong here

    This order is wrong on two counts: backups are the least volatile evidence and should be collected last, and memory is the most volatile and must be captured first. Collecting backups first adds significant time and I/O overhead, during which RAM and active sessions may be lost, and any pre-existing backups are unaffected by the incident timeline—so they pose no preservation urgency. Moreover, performing a disk image before memory means that the most volatile evidence is gone, making this sequence ineffective for capturing an ongoing breach.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.