During an enterprise incident response involving a compromised Windows server, you need to acquire volatile evidence in a forensically sound manner. Which TWO of the following actions should be performed first to preserve the most volatile data? (Choose two.)
Physical memory is the most volatile evidence and contains running processes, network connections, and encryption keys. Capturing it first preserves data that would be lost on shutdown or reboot. Tools like WinPmem or DumpIt create a forensic image of RAM that can later be analyzed for artifacts not found on disk, making this a critical first step in volatile evidence collection.
Why this answer
The order of volatility dictates that physical memory and active network connections are the most perishable. Capturing RAM preserves running processes and encryption keys, while recording network connections captures transient command-and-control activity. These two actions must be performed first to prevent loss of critical evidence before moving to less volatile sources like disk images or event logs.
Exam trap
The trap here is assuming that disk imaging or event log export should be done first because they are commonly emphasized, but they are less volatile than RAM and network state.