During a security incident, the incident response team needs to preserve evidence for potential legal action. Which of the following is the most important action to take when collecting volatile data from a compromised server?
Capturing the contents of RAM is crucial because memory holds highly volatile data that would be irretrievably lost upon system shutdown or reboot. This includes active processes, network connections, loaded kernel modules, and potentially malicious code residing solely in memory. Preserving RAM contents directly addresses the requirement to collect 'volatile data' for forensic analysis, ensuring critical evidence is secured before it becomes ephemeral and unusable for potential legal action.
Why this answer
Volatile data in RAM is lost when power is removed. Capturing RAM preserves evidence that might contain running processes, network connections, and encryption keys. Disk images are non-volatile and can be collected later.