ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 387 - SY0-601 discussion

Report
Export

Which of the following is the correct order of evidence from most to least volatile in forensic analysis?

A.
Memory, disk, temporary filesystems, CPU cache
Answers
A.
Memory, disk, temporary filesystems, CPU cache
B.
CPU cache, memory, disk, temporary filesystems
Answers
B.
CPU cache, memory, disk, temporary filesystems
C.
CPU cache, memory, temporary filesystems, disk
Answers
C.
CPU cache, memory, temporary filesystems, disk
D.
CPU cache, temporary filesystems, memory, disk
Answers
D.
CPU cache, temporary filesystems, memory, disk
Suggested answer: C

Explanation:

The correct order of evidence from most to least volatile in forensic analysis is based on how quickly the evidence can be lost or altered if not collected or preserved properly. CPU cache is the most volatile type of evidence because it is stored in a small amount of memory on the processor and can be overwritten or erased very quickly. Memory is the next most volatile type of evidence because it is stored in RAM and can be lost when the system is powered off or rebooted. Temporary filesystems are less volatile than memory because they are stored on disk, but they can still be deleted or overwritten by other processes or users. Disk is the least volatile type of evidence because it is stored on permanent storage devices and can be recovered even after deletion or formatting, unless overwritten by new data. Reference: https://www.comptia.org/blog/what-is-volatility-in-digitalforensics

asked 02/10/2024
Oscar Luis Garza Ruiz
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first