712-50 exam dumps

712-50 practice question 372 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 372

Single answerIdentify the volatile and persistent system information

A CCISO is reviewing the organization’s incident response playbook after a suspected compromise of a critical Linux application server. The security team is concerned that rebooting the server to restore service may destroy evidence needed to determine attacker actions and possible lateral movement. Which action should the CCISO direct the team to prioritize FIRST to preserve the most time-sensitive evidence while maintaining forensic soundness?

  1. A

    Capture volatile system information such as RAM contents, running processes, active network connections, logged-in sessions, and system time before powering down or rebooting the server

  2. B

    Create a full forensic image of the server’s disks first, because disk artifacts are more complete and easier to analyze than memory artifacts

  3. C

    Apply operating system patches and reboot immediately to prevent the attacker from maintaining persistence in memory

  4. D

    Collect configuration files, scheduled tasks/cron entries, installed services, and local log files first because they are the primary source of persistent evidence

Show answer and explanation

Correct answer: A

Explanation

The scenario tests understanding of volatile versus persistent system information and the practical application of the order of volatility in incident response. Volatile information includes RAM contents, process state, network connections, logged-in sessions, routing tables, ARP cache, and current system time. Persistent information includes disk contents such as logs, configuration files, scheduled jobs, installed binaries, and service definitions. Best practice in live response is to collect the most ephemeral evidence first because rebooting or powering down destroys it. This principle is reflected in common digital forensics guidance, including the IETF RFC 3227 guidance on evidence collection and handling, as well as NIST incident response and forensic process guidance. From a CCISO perspective, the key decision is directing responders to preserve volatile evidence first while maintaining chain of custody and documented forensic procedures, then proceed to disk imaging and analysis of persistent artifacts.

  • A. Correct.

    Correct. Volatile data is lost when a system is powered off or rebooted, so it should generally be collected first when incident response objectives include preserving evidence. Examples include memory contents, active processes, network connections, ARP cache, kernel modules, logged-in users, and current system time. This aligns with the widely accepted order of volatility used in digital forensics and incident handling guidance.

  • B. Incorrect.

    Incorrect. A disk image is important, but disk data is persistent and usually survives shutdown, unlike volatile data in RAM and live system state. Prioritizing disk imaging before memory and live-state collection risks losing crucial evidence such as malware injected only in memory, encryption keys, command history in memory, and active attacker sessions.

  • C. Incorrect.

    Incorrect. While containment and recovery are important business goals, patching and rebooting immediately can destroy volatile evidence and undermine the investigation. A CCISO should balance operational urgency with evidentiary preservation, especially on a critical system where understanding attacker behavior, scope, and lateral movement is necessary.

  • D. Incorrect.

    Incorrect. Configuration files, cron jobs, services, and log files are examples of persistent or semi-persistent artifacts that are often still available after shutdown. They are valuable for identifying persistence mechanisms, but they should not be prioritized ahead of volatile evidence when the system is still running.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam