An organization's security team detects a potential data breach. After confirming the incident, they classify it as P2 (high severity) and begin containment. Which action should be performed FIRST to preserve evidence for forensic analysis?
Trap 1: Disconnect the system from the network
Network isolation is a containment step, but evidence preservation should be prioritized.
Trap 2: Create a forensic image of the hard drive
Hard drive imaging is important but volatile data should be collected first.
Trap 3: Run an antivirus scan to remove malware
Running AV can modify evidence; it should be avoided during initial forensics.
- A
Disconnect the system from the network
Why it fails: Network isolation is a containment step, but evidence preservation should be prioritized.
- B
Capture a memory dump using a tool like Magnet RAM Capture
RAM holds volatile artefacts — running processes, network connections, encryption keys — that vanish on shutdown or reboot. Capturing memory first satisfies the order of volatility, preserving evidence that containment actions such as isolation or power-off would otherwise destroy.
- C
Create a forensic image of the hard drive
Why it fails: Hard drive imaging is important but volatile data should be collected first.
- D
Run an antivirus scan to remove malware
Why it fails: Running AV can modify evidence; it should be avoided during initial forensics.