SSCP Incident Response and Recovery Practice Question
A security analyst is responding to a malware incident on a Windows server. Which TWO actions should be taken to properly collect volatile evidence?
⚠ Common exam trap
Watch out — candidates often confuse 'volatile evidence' with 'non-volatile evidence' and choose disk imaging (Option C) instead of memory capture, or mistakenly think rebooting (Option A) is a safe containment step.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Capture a memory dump using WinPmem
Option D is correct because capturing a memory dump with WinPmem preserves the contents of RAM, which is the most volatile evidence and is lost the moment the system is powered off or rebooted. Option E is correct because recording active network connections (e.g., via netstat or similar tools) documents volatile state such as established sessions, listening ports, and remote endpoints that would otherwise disappear. Options A and B are wrong because rebooting or deleting files destroys volatile evidence and alters the system state, violating order-of-volatility principles. Option C is incorrect here because a full disk image with a write blocker captures non-volatile storage, not volatile evidence such as memory or live network connections.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reboot the system to clear malware from memory
Why it's wrong here
Rebooting destroys memory-resident artefacts such as running processes, network connections and encryption keys before they are captured. It is tempting as a quick malware-removal step, and would suit restoring a production server, but volatile evidence must be collected first, not erased.
- ✗
Delete suspicious files to prevent further infection
Why it's wrong here
Deleting files alters the disk and can trigger malware routines that wipe logs or memory artefacts, corrupting the evidence set. It is tempting as containment to stop further infection, and would be reasonable after evidence capture, but here it precedes collection and destroys recoverable data.
- ✗
Perform a full disk image using a write blocker
Why it's wrong here
A write-blocked disk image captures non-volatile storage only; it preserves nothing from RAM, which the question targets. Imaging is tempting because it is the standard forensic first step for disks, and would be correct for file-system evidence, but volatile memory requires live acquisition tools instead.
- ✓
Capture a memory dump using WinPmem
Why this is correct
WinPmem captures physical memory, preserving running processes, injected code and encryption keys that vanish on shutdown or reboot. This satisfies the volatile-evidence requirement, since RAM is lost first and must be acquired before any disk imaging or power-off.
- ✓
Record active network connections
Why this is correct
Recording active network connections captures established sessions, remote addresses and listening ports that disappear once the malware is contained or the host reboots. This satisfies the volatile-evidence requirement, as connection state exists only in memory and changes continuously.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.