CS Professional · Internal and Forensic Audit · Cyber Forensics
In a fraud inquiry, an auditor must collect digital evidence from a running desktop and from the same machine's hard disk. According to the order of volatility, which should be collected first?
RAM and running process data should be collected first. Under the order of volatility, the most short-lived evidence is captured before more persistent sources like disks, backups and printouts, because memory contents vanish when the system is powered down.
- AArchived backup tapes stored offsite
- BContents of RAM and running processesCorrect
- CFiles stored on the hard disk
- DPrinted documents in the office
Explanation
Evidence is gathered from the most volatile source to the least volatile. RAM and running processes are lost when the machine is powered off, whereas disk files and backups persist. Hence memory is captured first. Collecting disk data first risks losing the volatile data.
Did you get it right without looking?
One question tells you little. A timed set on Cyber Forensics shows your real accuracy, how long you take and where you lose marks.
More Cyber Forensics questions
- A forensic auditor at Verma Steels Pvt Ltd finds that the accounts ledger was kept in an electronic file and the same record was saved simul…
- After a ransomware incident, a company's forensic team wants the national agency to coordinate incident response and issue advisories. Under…
- A forensic auditor at Nair Pharma Ltd finds that the original electronic file was lost in a fire, through no default or neglect of the compa…
- A forensic examiner at a Mumbai company finds that the hash value of the working image of a server disk differs from the hash recorded at ac…
- A company produces in court an email archive taken from the server where the company's law requires such records to be kept, and the server …
- An internal auditor lists the national functions of the Indian Computer Emergency Response Team under Section 70B of the IT Act, 2000 to ben…