GCFA Enterprise Environment Incident Response Practice Question
During an enterprise-wide incident response, a Windows workstation is suspected of being compromised by a threat actor who used a spear-phishing document. The machine is still powered on and the user is logged in. You need to capture volatile evidence in a forensically sound manner. Which of the following is the correct order of volatility for collecting evidence, from most volatile to least volatile?
⚠ Common exam trap
The trap here is assuming that RAM is always the most volatile component, when CPU registers and cache are even more volatile and are often overlooked.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CPU registers and cache, routing table, RAM, temporary file systems, disk
The order of volatility dictates that the most perishable evidence be collected first. CPU registers and cache change with every instruction, routing tables and ARP caches expire quickly, and RAM loses its contents on power-off. Temporary file systems and disk are comparatively persistent. Following this sequence preserves the most fragile evidence before it is altered or destroyed by normal system activity or shutdown.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Temporary file systems, disk, RAM, routing table, CPU registers and cache
Why it's wrong here
Temporary file systems and disk are less volatile than RAM and routing tables. Collecting them first would likely cause the loss of more volatile data such as routing tables and CPU registers. The correct approach is to start with the most volatile (CPU registers/cache) and proceed to the least volatile (disk).
- ✓
CPU registers and cache, routing table, RAM, temporary file systems, disk
Why this is correct
This order correctly follows the RFC 3227 guidelines for order of volatility. CPU registers and cache are the most volatile, followed by routing tables, ARP cache, process table, kernel statistics, and memory. Temporary file systems and disk are less volatile. Collecting in this order minimizes loss of critical evidence that disappears when the system is powered down.
- ✗
Disk, RAM, temporary file systems, routing table, CPU registers and cache
Why it's wrong here
This order is reversed; it starts with the least volatile (disk) and ends with the most volatile (CPU registers). If you collect disk first, volatile data such as RAM and routing tables may be lost due to system changes or an unexpected shutdown. In incident response, you must capture the most volatile data first to preserve ephemeral evidence.
- ✗
RAM, CPU registers and cache, disk, temporary file systems, routing table
Why it's wrong here
Although RAM is highly volatile, CPU registers and cache are even more volatile because they are overwritten constantly by normal CPU operations. The routing table is also more volatile than disk. Placing disk before routing table and temporary file systems is incorrect because disk is less volatile. This order would risk losing critical network state information.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.