A security team suspects a data breach via an external attacker. The incident response plan requires preservation of evidence for legal proceedings. Which order of volatility should the first responder follow?
This is the correct order of volatility: memory first because RAM contains live evidence like decryption keys, running processes, and transient malware that disappears on shutdown; network connections second because they show active command-and-control sessions and can vanish with session teardown; disk image third because persistence preserves it for later analysis; and backups last because they are the least volatile and can be obtained at any time. This sequence maximizes evidence preservation and aligns with RFC 3227 and NIST forensic guidelines, while also supporting a defensible chain of custody.
Why this answer
The order of volatility (OOV) dictates that the most volatile data (memory/registers) must be captured first, followed by network connections, then disk images, and finally backups. This sequence minimizes data loss and ensures evidence integrity for legal proceedings, as volatile data is lost when power is removed.
Exam trap
EC-Council often tests the misconception that disk images are the most critical evidence, leading candidates to prioritize them over volatile memory and network state, which is the exact opposite of the correct order of volatility.
How to eliminate wrong answers
Option A is wrong because it starts with capturing a disk image, which is less volatile than memory and network connections; memory and network state would be lost or altered before the disk is imaged. Option B is wrong because it captures network connections before memory, but memory (RAM) is more volatile and must be acquired first to preserve transient data like running processes and encryption keys. Option D is wrong because it collects backups first, which are the least volatile and can be acquired later; starting with backups risks losing volatile evidence in memory and network connections.