ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 68 - CS0-003 discussion

Report
Export

During an incident, an analyst needs to acquire evidence for later investigation. Which of the following must be collected first in a computer system, related to its volatility level?

A.
Disk contents
Answers
A.
Disk contents
B.
Backup data
Answers
B.
Backup data
C.
Temporary files
Answers
C.
Temporary files
D.
Running processes
Answers
D.
Running processes
Suggested answer: D

Explanation:

The most volatile type of evidence that must be collected first in a computer system is running processes. Running processes are programs or applications that are currently executing on a computer system and using its resources, such as memory, CPU, disk space, or network bandwidth. Running processes are very volatile because they can change rapidly or disappear completely when the system is shut down, rebooted, logged off, or crashed. Running processes can also be affected by other processes or users that may modify or terminate them. Therefore, running processes must be collected first before any other type of evidence in a computer system

asked 02/10/2024
Mark Lalangan
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first