Order of Volatility: Collecting Evidence in Correct Sequence
A forensic investigator is collecting evidence from a compromised Windows server. According to the order of volatility, which THREE pieces of evidence should be collected FIRST? (Select THREE)
Quick Answer
Running processes belong near the front of the collection order because they exist only in memory and volatile system state. The moment the system is powered down, rebooted, or even left running long enough for the process to exit, that evidence is gone permanently, unlike data written to disk which persists until it's actively overwritten. The order of volatility principle that governs forensic collection ranks evidence by how quickly it changes or disappears: the most fragile, transient artifacts have to be captured first, before less volatile sources like log files or the hard disk itself, precisely because those more durable sources will still be there later if collection has to be sequenced. Running processes sit alongside other memory-resident and connection-state data, such as active network connections, as some of the most time-sensitive evidence in an investigation, because an attacker's malicious process or an active command-and-control session can terminate or disconnect at any moment, either on its own or because the attacker notices they've been detected. Investigators use live-response tools to capture this kind of evidence with minimal disruption to the running system, rather than jumping straight to actions like powering off the machine, which would destroy exactly the evidence they're trying to preserve. Whenever a question invokes order of volatility, think in terms of what disappears fastest, meaning memory, processes, and active connections, and prioritize collecting those before anything durably stored on disk.
⚠ Common exam trap
ISC2 SSCP often tests the misconception that event logs are volatile because they are 'system state' data, but logs are written to disk and persist; the trap is confusing 'important' with 'volatile'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Network connections and open ports
According to the order of volatility, the most perishable data must be captured first because it disappears when the system is powered off or changes rapidly. Option C (Network connections and open ports) is correct because active TCP/UDP sessions, listening sockets, and ARP/routing state exist only in memory and vanish immediately on shutdown, so tools like netstat, ss, or Get-NetTCPConnection must run first. Option D (Contents of RAM (memory dump)) is correct because physical memory holds encryption keys, injected code, and uncommitted data that is irretrievably lost once power is removed, making it the highest-priority acquisition. Option E (List of running processes) is correct because the process table, PIDs, parent-child relationships, and loaded modules are volatile kernel structures that change second by second and cannot be recovered from a later disk image. Option A (System event logs) is not among the first tier because, although logs are valuable, they are typically persisted to disk (.evtx files) and survive until overwritten, so they are collected after memory-resident artifacts. Option B (Hard drive image) is not among the first tier because disk contents are the least volatile and remain intact while live memory and network state are captured beforehand.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
System event logs
Why it's wrong here
Event logs are stored on disk and are less volatile; they can be collected later.
- ✗
Hard drive image
Why it's wrong here
Hard drive is less volatile; should be collected after memory and network state.
- ✓
Network connections and open ports
Why this is correct
Network connections and open ports reside in memory and change or disappear within seconds, placing them near the top of the order of volatility. Collecting them first satisfies the stem's requirement to gather the most perishable evidence before it is lost.
- ✓
Contents of RAM (memory dump)
Why this is correct
RAM contents are highly volatile, holding running processes, network state and encryption keys that are lost on shutdown or reboot. Capturing memory first satisfies the order of volatility, preserving the most perishable evidence before collection proceeds to disk.
- ✓
List of running processes
Why this is correct
The list of running processes exists only in volatile memory and changes constantly, so it must be captured before shutdown or reboot. Collecting it first satisfies the order of volatility, preserving evidence that would otherwise be irretrievably lost.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
4 more ways this is tested on SSCP
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. During a forensic investigation, a responder must collect evidence from a live Windows system. Which of the following represents the correct order for collecting volatile data?
hard- A.Disk image, memory dump, process list, network connections
- ✓ B.Memory dump, network connections, process list, disk image
- C.Process list, memory dump, disk image, network connections
- D.Network connections, memory dump, process list, disk image
Why B: Volatile data must be collected in order of decreasing volatility to avoid losing critical evidence. Memory (RAM) is the most volatile, followed by network connections and process lists (which change rapidly), and finally disk images (persistent storage). This order ensures that transient data is captured before it disappears.
Variation 2. An incident responder is collecting volatile evidence from a compromised Linux server. Which TWO of the following should be collected first? (Select two.)
medium- A.Disk image of the system drive
- B.System log files from /var/log
- C.Hardware configuration inventory
- ✓ D.List of active network connections using netstat
- ✓ E.Contents of RAM using LiME
Why D: Option E (Contents of RAM using LiME) is correct because RAM is the most volatile evidence on a running Linux system and is lost on shutdown or reboot; LiME (Linux Memory Extractor) is a kernel module that captures physical memory to a file for later forensic analysis, preserving running processes, encryption keys, and network state. Option D (List of active network connections using netstat) is correct because active connections, listening sockets, and associated PIDs are highly volatile and change within seconds, so capturing them early preserves evidence of command-and-control channels and lateral movement; netstat (or its modern replacement ss) reads this state directly from the kernel. Option A (Disk image of the system drive) is not first because disk contents are persistent and can be acquired later without loss, and imaging a live disk is slower and less volatile than memory or network state. Option B (System log files from /var/log) is not first because logs are stored on disk and persist across reboots, so they are less volatile than RAM or active connections. Option C (Hardware configuration inventory) is not first because hardware configuration is static and remains available after the incident, making it the least volatile category of evidence.
Variation 3. An incident responder is collecting evidence from a compromised server. Which of the following is the correct order for collecting volatile data?
medium- ✓ A.Network connections, memory dump, disk image
- B.Disk image, network connections, memory dump
- C.Memory dump, network connections, disk image
- D.Disk image, memory dump, network connections
Why A: Volatile data must be collected in order of decreasing volatility. Network connections (active sessions, ARP cache, routing tables) are more volatile than RAM and can change or disappear within seconds, so they are captured first. Memory (RAM) is collected next because it is lost on power loss but persists slightly longer than network state. The disk image is collected last because it is persistent storage and the least volatile. This order preserves ephemeral evidence such as active sessions, running processes, and encryption keys before it disappears.
Variation 4. Which of the following is the FIRST step in the volatile evidence collection order when responding to an incident on a live system?
easy- ✓ A.Capture a RAM dump using a tool like Magnet RAM Capture or WinPmem
- B.Disconnect the system from the network
- C.Run antivirus scans to identify malware
- D.Create a forensic image of the hard drive
Why A: The first step in volatile evidence collection is to capture the most volatile data, which is typically RAM (memory). RAM contains running processes, network connections, and encryption keys that are lost when the system is powered off. Therefore, capturing a RAM dump using tools like Magnet RAM Capture or WinPmem is the first step. Disconnecting from the network is a containment step that may be done before or after, but it can alter volatile data; running antivirus scans modifies the system; creating a forensic image of the hard drive is less volatile and done later.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.