SSCP Incident Response and Recovery Practice Question
A financial services firm's incident response team has just contained a malware outbreak on a file server. The server contains regulated customer data. The team lead instructs the responder to capture the current state of the system before any remediation. According to NIST SP 800-61, which action should the responder take FIRST to preserve the most volatile evidence?
⚠ Common exam trap
The trap here is assuming that disk imaging always comes first because it is the most familiar forensic step, when in fact volatile memory and network state must be captured before any shutdown or reboot.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Dump the contents of RAM and capture active network connections.
The order of volatility dictates that the most transient evidence be collected first. RAM contents, running processes, and active network connections disappear when a system is powered down or rebooted, so they must be captured before disk imaging, log export, or physical documentation. This aligns with NIST SP 800-61 guidance to preserve volatile data during containment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Dump the contents of RAM and capture active network connections.
Why this is correct
RAM contents, running processes, and active network connections are the most volatile evidence and are lost when the system is powered off or rebooted. NIST SP 800-61 recommends collecting these first during the containment phase. Capturing memory and network state preserves indicators such as injected code, encryption keys, and command-and-control sessions before any remediation disrupts them.
- ✗
Export the server's event logs to a remote syslog server.
Why it's wrong here
Exporting event logs is valuable, but log data resides on disk and is less volatile than RAM or network state. If the responder exports logs first, in-memory artifacts such as malicious processes or decrypted payloads may be lost when the system is later rebooted or remediated. Volatile evidence must be prioritized before persistent artifacts like log files.
- ✗
Capture a forensic image of the server's hard drive using a write blocker.
Why it's wrong here
A forensic disk image preserves persistent storage, but it does not capture volatile data such as RAM contents, network connections, or running processes that will be lost on shutdown or reboot. Because the question asks for the most volatile evidence first, imaging the hard drive is premature and may allow critical in-memory artifacts to be destroyed before they are collected.
- ✗
Document the server's physical location and hardware configuration.
Why it's wrong here
Physical documentation is part of evidence handling, but it does not capture volatile runtime state. The hardware configuration will remain unchanged and can be documented at any time, whereas RAM contents and network connections disappear quickly. Prioritizing documentation over volatile data collection would violate the order of volatility and risk losing critical investigative artifacts.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.