200-201 exam dumps

200-201 practice question 363 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 363

Select 3

A security analyst is responding to a suspected malware infection on a critical production server. The analyst has been instructed to collect volatile data before shutting down the server for further forensic analysis. Which of the following types of volatile data should the analyst prioritize collecting before powering down the system?

  1. A

    Active network connections

  2. B

    Running processes

  3. C

    Installed software packages

  4. D

    System memory (RAM) contents

  5. E

    Event logs from the local disk

Show answer and explanation

Correct answers: A, B, D

Explanation

Volatile data refers to information that is lost when a system is powered down, such as active network connections, running processes, and the contents of system memory (RAM). These types of data are critical for understanding the state of a system during an incident and should be prioritized for collection before shutting down the machine. Non-volatile data, such as installed software packages and event logs stored on disk, can be collected later as they persist after the system is powered down.

  • A. Correct.

    Active network connections are volatile and may reveal ongoing malicious activities or connections to command-and-control servers. This data will be lost if the system is powered down.

  • B. Correct.

    Running processes are volatile and can help identify malicious processes or unauthorized activity on the system. This data is crucial for understanding the current state of the system.

  • C. Incorrect.

    Installed software packages are typically stored on disk and are not considered volatile. This data does not need to be prioritized for collection in this scenario.

  • D. Correct.

    System memory (RAM) contents are highly volatile and can contain critical information such as malware code, encryption keys, and other transient data. This should be prioritized for collection.

  • E. Incorrect.

    Event logs from the local disk are not volatile, as they are stored persistently on the disk. These can be collected later during the forensic analysis.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam