Triage BoardGet the app

Concept · Response techniques

Order of volatility: what to collect first

The order of volatility means collecting evidence from the most short-lived source to the most durable: CPU registers and cache, then memory and live network state, then temporary files, disk, remote logs and finally archival media. That sequence comes from RFC 3227, and it decides the “collect first” evidence questions under objective 3.3 of the CS0-004 exam.

  • Exam code CS0-004
  • Tickets here 8

An evening spent on the wrong sources

A Linux build server at a fictional software company is running a process nobody recognizes, started from a script in /tmp. The responder begins with the sources that feel authoritative: an export of the server's logs from the SIEM (security information and event management system), then last week's backup to compare files against. Both take most of the evening.

At 02:00 the server's scheduled patch reboot runs. On this host /tmp is a tmpfs, held in RAM, so the script disappears with the reboot, along with the process, its command line and whatever it had decoded in memory. The SIEM export and the backup are intact, and they show that something ran without showing what it did. Copying /tmp and capturing memory would have taken minutes at the start.

The rule that would have saved them is simple to state: collect what will disappear soonest first. Volatility is about each source's lifetime, so the SIEM copy and the backup, which will still exist next month, wait until the fast-changing sources are safe.

RFC 3227, top to bottom

Registers, cache1stMemory, tables, processes2ndTemporary file systems3rdDisk4thRemote logs, monitoring5thPhysical config, topology6thArchival media7th
Top layer goes first. Each layer down survives longer, so it can wait.

What erases each layer

Where each kind of evidence lives and what destroys it
EvidenceLives inErased by
Registers, cacheThe CPUThe next instructions it runs
Routing and ARP tables, process table, kernel statisticsKernel memoryNormal churn, processes exiting, reboot
Memory contentsRAMPower loss, reboot, reuse by other processes
Temporary file systems/tmp, tmpfsReboot, cleanup jobs
DiskLocal drivesOverwrites, wiping, re-imaging
Remote logs and monitoring dataSIEM or log serverRetention limits, rotation
Physical configuration, network topologyThe site itselfChanges made during response
Archival mediaBackups, tapeRetention policy, media aging

When the order bends

RFC 3227 is guidance, and two situations change the plan. The first is a remote source that is about to roll over: a proxy or firewall that keeps only a few hours of logs. A second responder can export that window in parallel; the order of volatility governs each host, and nothing stops two people collecting from different sources at once.

The second is your own tooling. Every command you run on a live system changes it a little. RFC 3227 warns against trusting the compromised system's programs, so run collection tools from trusted external media and record what you ran. Whenever you depart from the standard order, write down what you did and why, because someone will ask.

Each artifact also gets a hash and a custody record the moment it is collected. And when the host has to come off the network before you finish, isolate it at the network level and keep the power on, which is a containment step that leaves memory intact. The rest of the evidence techniques are on the incident response techniques page.

“First” asks about volatility, not valueTrap

A full disk image usually holds the most evidence, which is why it tempts. A stem that asks what to collect first wants the source that will be gone soonest. Value decides whether you collect something at all; volatility decides when.

Collect in the right order

The systems in these stems are live, and the clock keeps running while you choose.

Ticket 1 / 8

0 right

INC-001

Which type of information should be collected FIRST when responding to a potential data breach incident?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AConfiguration files live on disk and survive a reboot, so they can be collected after the volatile data.
  2. BCorrect: RAM contents and running processes disappear when the system is powered off or changes state, so the order of volatility puts them first.
  3. CBackup restoration procedures are recovery documentation, not evidence, and belong to a later phase.
  4. DUser account lists are stored on disk or in a directory service, so they are less volatile than memory.

INC-002

A multi-component architecture comprising a hypervisor, container workloads, and a Storage Area Network is currently under active attack. Based on generalized order of volatility principles, which operational state should be collected first?

Exhibit

System ComponentCurrent Operational State
Container HostCPU registers and L1/L2 cache executing workloads
HypervisorVolatile memory (RAM) allocated to active guests
SAN ControllerSystem logs continuously writing to persistent disk
Network SwitchRunning processes maintaining active ARP connections

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. AGuest RAM is highly volatile, but it changes more slowly than CPU registers and cache, so it comes after them.
  2. BLogs being written to persistent disk are among the least volatile items here and can be collected later.
  3. CCorrect: CPU registers and cache change constantly and sit at the top of the order of volatility (RFC 3227), so they are collected first.
  4. DProcess and ARP state is volatile, but it still lasts longer than register and cache contents.

INC-003

Based on the artifact location matrix below, which artifact must be collected first according to the standard order of volatility?

Exhibit

Artifact TypeStorage MediumServer Role
Temporary application filesLocal SSDApplication Server
Active network sessionsSystem RAMGateway Router
Forwarded event log recordsSIEM StorageLog Collector
Archived database backup setsExternal NASStorage Server

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AForwarded logs already sit in SIEM storage, which is persistent and off the host, so they are among the last items to collect.
  2. BCorrect: Active network sessions live in RAM and vanish when connections close or the router restarts, so they are the most volatile artifact listed.
  3. CTemporary files on a local SSD are more volatile than archives but still persist on disk, so they come after memory-resident data.
  4. DArchived backups on external storage are the least volatile item and can be collected last.

INC-004

A compromised Windows host must stay online. Which evidence must be collected first to preserve maximum forensic value?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. ADisk images and event logs are the least volatile data listed and should be taken after memory.
  2. BCorrect: CPU registers and RAM are the most volatile evidence, so they come first even when the host stays online.
  3. CLogged-in users and open files are volatile state, but they rank below registers and memory, and a memory capture preserves much of this information anyway.
  4. DNetwork connections are short-lived, but registers and cache still come first in RFC 3227, and a memory capture also records active sockets.

INC-005

An analyst suspects active data exfiltration on a server. Which action best balances immediate evidence preservation with operational incident response procedures?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. APulling the cable first ends the live sessions that show where the data is going; recording them takes a minute, and isolation follows right after.
  2. BA full disk image of a running server takes hours while the exfiltration continues, and the disk is less volatile than the live connections.
  3. CRebooting wipes memory and every active connection, and safe mode does nothing about data that has already left.
  4. DCorrect: Active network sessions are among the most volatile evidence, so a quick capture of them comes first and the host is isolated immediately afterward.

INC-006

An analyst powers off a ransomware-infected server to prevent further lateral movement. What is the primary forensic consequence of this containment action?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: Ransomware often holds encryption keys and its running state in memory, and powering off destroys them, which can remove the chance to recover keys or analyze the live malware.
  2. BPowering off does not clear event logs; they remain on disk.
  3. CShutting down does not trigger propagation; it stops running processes, including the malware.
  4. DA normal power-off does not overwrite the master boot record; only specific malware does that.

INC-007

During a suspected breach on a cloud instance, an analyst proposes immediately stopping the instance before taking a disk image. Why is this approach detrimental to the forensic investigation?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. ACloud control-plane logs, such as API audit logs, are kept by the provider and are not deleted when an instance stops.
  2. BCorrect: Stopping an instance wipes its memory and any ephemeral (instance-store) disks, so that evidence is lost before the disk snapshot is taken.
  3. CStopping an instance does not encrypt its root volume; the volume stays attached and can still be snapshotted.
  4. DStopping an instance does not trigger any hypervisor-level lockdown of the subnet.

INC-008

A security analyst discovers a workstation exhibiting anomalous network behavior. The workstation is encrypted using Full Disk Encryption (FDE). To preserve evidence effectively without losing critical data, which action must the analyst avoid performing first?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. ACapturing RAM is what the analyst should do first, because it preserves volatile data and may contain the disk encryption key.
  2. BRouting tables are volatile network state worth collecting early, not an action to avoid.
  3. CCorrect: Powering off a machine with full disk encryption locks the disk again and wipes memory, so the drive may become unreadable without the key and all volatile evidence is lost.
  4. DPhotographing the screen and setup records the system state without changing it, so it is a sound early step.

Shift tally

0 / 0

Collecting on a live host

Will I find the order of volatility in the CompTIA objectives?

No. Objective 3.3 of the CS0-004 objectives names chain of custody, data integrity validation, preservation and legal hold under evidence gathering; the ordering is RFC 3227, Guidelines for Evidence Collection and Archiving, and NIST SP 800-86 gives similar advice.

Can I leave logs that already sit in the SIEM until later?

Not for long. A copy off the host is why remote logs rank low, but retention still runs out. Check the retention window early in the incident and export the period you need, with a hash, before it ages out.

Keep the queue going on your phone

Our practice app carries CySA+ questions to your phone, on iPhone and Android.