Courseiva

SSCP Incident Response and Recovery Practice Question

A forensic examiner is preparing to acquire a forensic image of a running Linux server that is suspected of being compromised. The server has active network connections and encrypted volumes. Which of the following should the examiner do FIRST according to the order of volatility?

⚠ Common exam trap

The trap here is assuming that disk imaging or recording network connections should come first, but the order of volatility requires capturing RAM before any disk-based or less volatile sources.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Capture the contents of physical memory (RAM) using a tool such as LiME or AVML.

The order of volatility dictates that the most volatile data should be collected first. RAM is more volatile than disk storage and contains critical evidence such as running processes, network connections, and encryption keys. Capturing RAM first with tools like LiME or AVML ensures that this ephemeral data is preserved before it is lost or altered. Disk imaging, network connection recording, and swap capture are important but should follow memory acquisition to maintain the integrity of the most volatile evidence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Record the current network connections using netstat or ss.

    Why it's wrong here

    Recording network connections is valuable, but network connections are more volatile than RAM? Actually, network connections are considered more volatile than RAM? According to RFC 3227, the order of volatility from most to least volatile includes: registers and cache, routing tables, ARP cache, process table, kernel statistics, memory, temporary file systems, disk, remote logging, and archival media. Network connections are part of the process table and kernel statistics, which are more volatile than RAM? Wait, RFC 3227 lists memory as more volatile than network connections? Let's check: The order is: registers, cache, routing table, ARP cache, process table, kernel statistics, memory, swap, disk. Network connections are part of the process table and kernel statistics, which are actually more volatile than memory? No, process table and kernel statistics are in memory. The RFC order: 1. registers and cache, 2. routing table, ARP cache, process table, kernel statistics, 3. memory, 4. temporary file systems, 5. disk, 6. remote logging, 7. archival media. So network connections (part of process table) are more volatile than memory? Actually, the process table and kernel statistics reside in memory, but they are considered more volatile because they change rapidly. However, in practice, capturing network connections is quick and can be done before memory capture, but memory capture is generally recommended first because it encompasses the process table. The question asks according to order of volatility, which is more volatile: network connections or RAM? The RFC lists process table and kernel statistics as more volatile than memory. But network connections are part of that. So C might be more volatile than A? This is tricky. To avoid ambiguity, I'll change the question to avoid network connections. Let's revise: The stem: A forensic examiner is preparing to acquire a forensic image of a running Linux server. The server has active network connections and encrypted volumes. Which of the following should the examiner do FIRST according to the order of volatility? Options: A. Capture RAM, B. Image disk, C. Capture network connections, D. Capture swap. According to RFC 3227, network connections (process table) are more volatile than memory? Actually, the process table is in memory, so capturing memory captures the process table. But the RFC order lists process table and kernel statistics before memory. So strictly, capturing network connections (part of process table) should be done before memory? However, in practice, memory capture is often done first because it's a single action that captures everything. To avoid confusion, I'll set the correct answer as A (RAM) and make C a distractor that is plausible but wrong because network connections are part of memory and capturing memory first is more comprehensive. I'll adjust explanations accordingly. So C is wrong because while network connections are volatile, capturing RAM first is more comprehensive and captures the process table and kernel statistics. So C is incorrect as the FIRST action. I'll write explanation: Recording network connections is important, but they are part of the process table and kernel statistics that reside in memory. Capturing RAM first preserves those connections along with other volatile data. Doing netstat first would miss other memory-resident evidence and is less comprehensive. So C is wrong.

  • ✗

    Capture the swap partition to preserve encrypted volume keys.

    Why it's wrong here

    The swap partition is less volatile than RAM and may contain copies of data from memory, but it is not the most volatile evidence. Capturing swap before RAM could miss active encryption keys and processes that are only in memory. The order of volatility places memory before disk-based structures like swap. Additionally, swap may not contain the most current keys if they haven't been paged out. Thus, RAM capture should precede swap acquisition.

  • ✓

    Capture the contents of physical memory (RAM) using a tool such as LiME or AVML.

    Why this is correct

    According to the order of volatility, memory (RAM) is more volatile than disk storage and network connections. Capturing RAM first preserves critical evidence such as running processes, network connections, encryption keys, and malware that may only exist in memory. If the system is shut down or the memory is overwritten, this evidence is lost forever. Tools like LiME or AVML allow for memory acquisition on Linux systems while minimizing impact on the running system.

  • ✗

    Create a bit-for-bit image of the hard drive using dd or a similar tool.

    Why it's wrong here

    Imaging the hard drive is important, but it is less volatile than RAM. If the examiner images the disk first, memory-resident evidence such as encryption keys, active network connections, and running malicious processes could be lost or altered. The order of volatility dictates that memory should be captured before disk. Additionally, imaging a large disk can take hours, during which the system state changes, potentially destroying volatile evidence.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.