Skip to content

CS Professional · Internal and Forensic Audit · Cyber Forensics

In a fraud inquiry, an auditor must collect digital evidence from a running desktop and from the same machine's hard disk. According to the order of volatility, which should be collected first?

RAM and running process data should be collected first. Under the order of volatility, the most short-lived evidence is captured before more persistent sources like disks, backups and printouts, because memory contents vanish when the system is powered down.

  1. AArchived backup tapes stored offsite
  2. BContents of RAM and running processesCorrect
  3. CFiles stored on the hard disk
  4. DPrinted documents in the office

Explanation

Evidence is gathered from the most volatile source to the least volatile. RAM and running processes are lost when the machine is powered off, whereas disk files and backups persist. Hence memory is captured first. Collecting disk data first risks losing the volatile data.

Did you get it right without looking?

One question tells you little. A timed set on Cyber Forensics shows your real accuracy, how long you take and where you lose marks.

More Cyber Forensics questions