A member of a digital forensics team, Joe arrives at a crime scene and is preparing to collect system data.
Before powering the system off, Joe knows that he must collect the most volatile date first.
Which of the following is the correct order in which Joe should collect the data?
Click on the arrows to vote for the correct answer
A. B. C. D.D.
The correct order in which Joe should collect the data is D. CPU cache, RAM, paging/swap files, remote logging data.
When it comes to digital forensics, volatile data refers to data that can be lost or modified easily when the system is powered off or rebooted. Therefore, it is crucial to collect this data first before shutting down or manipulating the system.
Let's examine each option and determine which one follows the correct order:
Option A:
Option B:
Option C:
Option D:
Therefore, the correct order in which Joe should collect the data is D. CPU cache, RAM, paging/swap files, remote logging data.