Data Collection Procedures Flashcards
1
Q
After an attack, before you restore your servers into operational status, what must you do to preserve evidence?
A
Create a forensic disk image of the data for evidence
2
Q
What is the order of volatility?
A
- CPU registers and cache memory
- Routing tables, ARP cache, process table, kernel statistics, memory (RAM)
- Temporary files
- Disk (HDD/SDD/flash drive)
- Remote logging and monitoring data
- Physical configuration and network topology
- Archival media
Exam Tip: You have to remember this in order