Courseiva
hardMultiple Choice

CISM Practice Question: An organization's incident response policy…

An organization's incident response policy requires preserving evidence in its original state. During a live incident on a critical server, the incident response team needs to capture volatile data, such as running processes and network connections, which would be lost if the system were shut down. The team has a forensic workstation with various tools. What tool should the team use to capture the volatile data before taking the system offline?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Memory dump tool (e.g., winpmem)

Volatile data from memory is best captured using a dedicated memory acquisition tool like winpmem or similar. FTK Imager and WinHex are primarily for disk imaging. The dd command is used for disk copying, not memory. Memory dumps capture volatile data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    WinHex

    Why it's wrong here

    WinHex is a disk and file editor for examining stored data at sector level, not a live-response collector; it cannot enumerate running processes or active network connections on the running server. It suits offline forensic examination of captured disk images or file structures after acquisition.

  • ✗

    dd command

    Why it's wrong here

    The dd command copies raw disk or partition contents; it cannot list running processes or active network connections, and imaging a live mounted disk risks inconsistency. Volatile data capture needs a live-response tool. dd suits bit-for-bit acquisition of a powered-off drive or unmounted volume.

  • ✗

    FTK Imager

    Why it's wrong here

    FTK Imager acquires disk images and mounted file systems; it does not enumerate running processes, open sockets or network connections from a live host. Volatile memory capture requires a dedicated live-response or memory acquisition tool. FTK Imager suits creating forensic images of drives for later analysis.

  • ✓

    Memory dump tool (e.g., winpmem)

    Why this is correct

    A memory dump tool captures RAM contents — running processes, network connections, injected code — that vanish on shutdown, satisfying the policy's requirement to preserve evidence in its original state while still collecting volatile data from the live critical server.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.