SSCP Incident Response and Recovery Practice Question
An incident responder is investigating a compromised Linux server and needs to collect volatile data. The responder has root access and wants to ensure that the data collected is admissible in a court of law. Which of the following commands should be used FIRST to capture the contents of physical memory?
⚠ Common exam trap
The trap here is assuming that traditional tools like dd on /dev/mem or process-level dumps are sufficient for full physical memory acquisition, when they are not forensically reliable on modern systems.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
LiME (Linux Memory Extractor) to dump memory to a file
LiME is specifically designed for Linux memory forensics, allowing a responder to capture physical memory in a forensically sound manner. It loads as a kernel module and writes the memory image to a file or network destination, preserving the integrity of the evidence. This method is accepted in legal proceedings because it does not alter the system state unnecessarily and captures a comprehensive image.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
LiME (Linux Memory Extractor) to dump memory to a file
Why this is correct
LiME is a loadable kernel module designed for volatile memory acquisition on Linux. It allows the responder to dump physical memory to a file or over the network without altering the system state significantly. It is widely accepted in forensics because it preserves the integrity of the memory image and is less likely to crash the system, making the evidence more defensible in court.
- ✗
gcore to dump the memory of all running processes
Why it's wrong here
gcore dumps the memory of individual processes, not the entire physical memory. It is useful for analyzing specific applications but does not capture kernel memory, network buffers, or other volatile data that may contain evidence. It also requires the process to be running and may not work for kernel threads, making it incomplete for a full memory capture.
- ✗
The 'free' command to display memory usage statistics
Why it's wrong here
The 'free' command only shows a summary of memory usage, such as total, used, and free memory. It does not capture the actual contents of memory, which is necessary for forensic analysis. It is a monitoring tool, not an acquisition tool, and provides no evidentiary value for identifying malicious activity or recovering data.
- ✗
dd if=/dev/mem of=/evidence/memory.dd
Why it's wrong here
Using dd on /dev/mem is unreliable on modern Linux systems because the kernel restricts access to physical memory for security reasons, and it may not capture all memory regions. Additionally, it can cause system instability or crashes, potentially destroying evidence. It is not a recommended method for forensic memory acquisition.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.