Cyber Monday 2024! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

GIAC Exam GCED Topic 5 Question 5 Discussion

Actual exam question for GIAC's GCED exam
Question #: 5
Topic #: 5
[All GCED Questions]

Of the following pieces of digital evidence, which would be collected FIRST from a live system involved in an incident?

Show Suggested Answer Hide Answer
Suggested Answer: D

Best practices suggest that live response should follow the order of volatility, which means that you want to collect data which is changing the most rapidly. The order of volatility is:

Memory

Swap or page file

Network status and current / recent network connections

Running processes

Open files


Contribute your Thoughts:

Currently there are no comments in this discussion, be the first to comment!


Save Cancel