Courseiva
mediumMultiple ChoiceObjective-mapped

ISC2 CC Practice Question: During a security incident, the incident response…

During a security incident, the incident response team needs to preserve evidence for potential legal action. Which of the following is the most important action to take when collecting volatile data from a compromised server?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Capture the contents of RAM.

Volatile data in RAM is lost when power is removed. Capturing RAM preserves evidence that might contain running processes, network connections, and encryption keys. Disk images are non-volatile and can be collected later.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Capture the contents of RAM.

    Why this is correct

    Capturing the contents of RAM is crucial because memory holds highly volatile data that would be irretrievably lost upon system shutdown or reboot. This includes active processes, network connections, loaded kernel modules, and potentially malicious code residing solely in memory. Preserving RAM contents directly addresses the requirement to collect 'volatile data' for forensic analysis, ensuring critical evidence is secured before it becomes ephemeral and unusable for potential legal action.

  • Make a bit-for-bit copy of all storage.

    Why it's wrong here

    Involves non-volatile storage; volatile data is more critical to collect first.

  • Create a forensic image of the hard drive.

    Why it's wrong here

    Non-volatile; can be done after powering down, but volatile data is lost first.

  • Review system logs.

    Why it's wrong here

    Logs are important but can be collected later; volatile data has highest priority.

About these practice questions

This CC question is part of Courseiva's 976-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CC

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. During a security incident, the incident response team needs to preserve evidence. Which of the following actions should be performed first?

medium
  • A.Notify law enforcement
  • B.Capture a memory dump
  • C.Power off the system
  • D.Run antivirus scan

Why B: Capturing a memory dump (volatile data) is the first priority because it contains critical evidence such as running processes, network connections, and encryption keys that will be lost when the system is powered off. The order of volatility dictates that volatile data must be collected before any non-volatile data, and before any actions that could alter system state.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.