Courseiva
Incident Management →easyMultiple Choice

CISM Incident Management Practice Question

During a security incident, the incident response team needs to preserve volatile evidence. Which of the following should be collected first?

⚠ Common exam trap

The trap here is assuming that hard drive files are the most critical evidence to collect first, ignoring the rapid loss of volatile memory.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Contents of RAM.

The order of volatility dictates that the most volatile evidence, such as RAM contents, should be collected first because it is lost when the system is powered off or rebooted. Hard drives, logs, and backups are less volatile and can be collected later. This principle ensures that critical evidence is preserved for forensic analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Files on the hard drive.

    Why it's wrong here

    Hard drive files are less volatile than RAM; they persist after shutdown. While important, they should be collected after more volatile evidence. Collecting hard drive files first risks losing RAM contents, which may contain unique evidence not found on disk. Therefore, this is not the first priority in evidence collection.

  • ✗

    Network traffic logs.

    Why it's wrong here

    Network traffic logs are typically stored on external systems and are less volatile than RAM. They can be collected later without significant risk of loss. However, if logs are only in memory, they might be volatile, but generally, network logs are not the most volatile. The order of volatility prioritizes RAM and other memory contents over logs.

  • ✗

    Backup tapes.

    Why it's wrong here

    Backup tapes are archival and non-volatile; they are not affected by system state. They are the least volatile and should be collected last, if at all. Collecting them first would not only be inefficient but also risk losing more volatile evidence. The order of volatility dictates that backups are at the bottom of the priority list.

  • ✓

    Contents of RAM.

    Why this is correct

    RAM contains highly volatile data such as running processes, network connections, and encryption keys, which are lost when the system is powered off. Collecting RAM first is critical to preserve this evidence. This follows the order of volatility, a fundamental concept in digital forensics. Failing to capture RAM first could result in loss of crucial evidence for the investigation.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.