712-50 exam dumps

712-50 practice question 373 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 373

Single answerIdentify the volatile and persistent system information

A multinational company suspects a targeted compromise on a finance manager's workstation that is still powered on and connected to the network. The CISO is coordinating the initial response and must ensure that investigators preserve the most critical evidence before containment actions such as shutdown or reimaging occur. Which of the following should be collected first because it is primarily volatile system information that would likely be lost if the system state changes?

  1. A

    The contents of RAM, active network connections, running processes, and logged-on user sessions

  2. B

    The system's installed applications list, disk image of the hard drive, and local security policy files

  3. C

    Archived event logs stored on disk, browser history databases, and scheduled task definitions

  4. D

    The workstation asset inventory record, CMDB ownership details, and the approved software baseline

Show answer and explanation

Correct answer: A

Explanation

The key distinction is between volatile information, which exists mainly in the system's current operational state, and persistent information, which is stored on non-volatile media and typically survives power loss. Standard incident response and forensic best practice follows the order of volatility: collect the most ephemeral data first, such as RAM, active connections, running processes, logged-in users, ARP tables, and other live system state. Persistent data such as disk contents, configuration files, registry hives, scheduled tasks, and stored logs can usually be acquired afterward. This approach is consistent with widely recognized digital forensic guidance, including NIST SP 800-61 Computer Security Incident Handling Guide and NIST SP 800-86 Guide to Integrating Forensic Techniques into Incident Response, both of which emphasize preserving volatile evidence before taking actions that may alter or destroy it.

  • A. Correct.

    Correct. These are classic examples of volatile data: memory contents, live network sessions, active processes, and current user sessions can change within seconds and are often lost entirely if the system is shut down, rebooted, or isolated improperly. In incident response and digital forensics, order of volatility principles prioritize collecting this live state information before moving to more persistent artifacts.

  • B. Incorrect.

    Incorrect. Although a disk image is highly important, the hard drive and configuration files are persistent sources of evidence and generally remain available after shutdown. Installed applications lists and local policy files are also persistent artifacts. This option reflects a common mistake of treating all useful evidence as equally time-sensitive.

  • C. Incorrect.

    Incorrect. These artifacts are usually persistent because they are stored on disk. While they may later be altered by system activity or attacker actions, they do not normally disappear immediately when power is lost. This option is plausible because event logs and browser history are valuable, but they do not outrank RAM and live connections under the order of volatility.

  • D. Incorrect.

    Incorrect. Asset inventory and CMDB records may help with scoping and ownership, but they are not system-resident volatile evidence from the potentially compromised endpoint. They are administrative records and can be retrieved later without risking immediate evidence loss.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam