200-201 Question 357
Single answerA cybersecurity analyst is responding to a ransomware attack on a company network. The attack has encrypted certain files, and the attacker has demanded payment for decryption keys. The analyst needs to prioritize evidence collection to ensure proper incident handling. According to the order of volatility, which type of evidence should the analyst collect first?
- A
RAM data and active processes from affected endpoints
- B
Archived system logs stored on a remote server
- C
Backup files stored in a cloud storage service
- D
Hard drive images from affected systems
Show answer and explanation
Correct answer: A
Explanation
The order of volatility prioritizes evidence that is most likely to change or be lost first. RAM and active processes are volatile and can disappear when a system is powered off or rebooted, making them the highest priority for collection. Other evidence types, such as logs, backups, and hard drives, are less volatile and can be collected later in the investigation.
- A. Correct.
RAM data and active processes are highly volatile and can be lost if not collected immediately. This type of evidence should be prioritized in the evidence collection process.
- B. Incorrect.
Archived system logs are less volatile and remain available for a longer period. They do not need to be collected immediately compared to more volatile evidence.
- C. Incorrect.
Backup files stored in the cloud are persistent and not part of immediate volatile evidence. They can be collected later in the investigation process.
- D. Incorrect.
Hard drive images are relatively non-volatile compared to RAM and active processes. They can be collected after more volatile evidence is secured.