SSCP Incident Response and Recovery Practice Question
An incident responder is preparing to acquire volatile data from a compromised Linux server that is still powered on. The server hosts a critical database and cannot be shut down yet. According to order of volatility, which data source should the responder collect FIRST?
⚠ Common exam trap
The trap here is assuming that network connections or logs are the most volatile because they change frequently, when actually RAM contents are lost first upon shutdown or reboot.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Contents of physical memory (RAM) using a tool such as LiME
The order of volatility prioritizes data that is most likely to be lost first. RAM is highly volatile and contains running processes, network connections, encryption keys, and malware that may not exist on disk. Network state and disk logs are less volatile and can be collected afterward. Capturing memory with a tool like LiME before other sources ensures the most perishable evidence is preserved for forensic analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Output of the netstat -antp command showing active network connections
Why it's wrong here
Network connections are volatile and important, but they are not the most volatile. Order of volatility places CPU registers, cache, and RAM above network state. Network connections can change rapidly, but memory contains running processes, encryption keys, and injected code that may be lost if not captured first. Therefore, netstat output is not the top priority.
- ✗
Contents of the /var/log/auth.log file
Why it's wrong here
Log files on disk are less volatile than memory or network state. While auth.log may contain valuable evidence, it persists across reboots and can be collected later. Order of volatility prioritizes data that will be lost first, such as CPU registers, cache, and RAM. Collecting disk logs before memory would risk losing critical volatile evidence, making this an incorrect first choice.
- ✗
Temporary files in the /tmp directory
Why it's wrong here
Temporary files are stored on disk and are less volatile than RAM. They may persist until reboot or cleanup, but they are not lost as quickly as memory contents. Order of volatility prioritizes CPU registers, cache, and RAM before disk-based data like /tmp. Collecting temporary files first would ignore more volatile evidence, so this is incorrect.
- ✓
Contents of physical memory (RAM) using a tool such as LiME
Why this is correct
Order of volatility dictates that memory (RAM) is more volatile than network state, disk logs, or temporary files. RAM holds running processes, open network connections, encryption keys, and malware artifacts that disappear on shutdown or reboot. Capturing RAM first preserves the most perishable evidence. Tools like LiME allow memory acquisition on Linux, making this the correct first step.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.