SSCP Incident Response and Recovery Practice Question
A forensic examiner is preparing to acquire a disk image from a compromised server. The server is still running and contains critical evidence in volatile memory. According to NIST SP 800-86, which of the following should the examiner do FIRST?
⚠ Common exam trap
The trap here is assuming that disk imaging is the first step, but volatile memory is more perishable and must be captured first.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Capture the contents of RAM using a memory acquisition tool.
The order of volatility in digital forensics dictates that the most perishable evidence, such as RAM and running processes, must be collected first. NIST SP 800-86 emphasizes capturing volatile memory before disk imaging or shutting down the system. This ensures that critical evidence like encryption keys, network connections, and malware artifacts are preserved for analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Capture the contents of RAM using a memory acquisition tool.
Why this is correct
According to NIST SP 800-86 and the order of volatility, volatile data such as RAM contents should be collected first because it is lost when the system is powered off. Capturing RAM preserves critical evidence like running processes, network connections, and encryption keys. This step must precede disk imaging to ensure that the most perishable evidence is not lost.
- ✗
Document the system's physical configuration and cable connections.
Why it's wrong here
Documentation is important but not the first priority when volatile evidence is at risk. While documenting the scene is part of the process, the immediate concern is to capture RAM before it is lost. NIST guidelines emphasize that volatile data collection should precede other steps to avoid losing critical evidence.
- ✗
Create a bit-for-bit image of the hard drive.
Why it's wrong here
While disk imaging is important, it should not be done first because volatile memory contains evidence that will be lost if the system is shut down or rebooted. The order of volatility dictates that RAM is more volatile than disk storage. Therefore, capturing RAM first is necessary to preserve all relevant evidence.
- ✗
Shut down the server to preserve the disk state.
Why it's wrong here
Shutting down the server would destroy volatile memory contents, which are crucial for understanding the incident. The order of volatility requires collecting the most volatile data first. Shutting down also might trigger anti-forensic mechanisms or lose temporary files. Thus, this action is incorrect as a first step.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.