A member of a digital forensics team, Joe arrives at a crime scene and is preparing to collect system data.
Before powering the system off, Joe knows that he must collect the most volatile date first. Which of the
following is the correct order in which Joe should collect the data?
CPU cache, paging/swap files, RAM, remote logging data
RAM, CPU cache. Remote logging data, paging/swap files
Paging/swap files, CPU cache, RAM, remote logging data
CPU cache, RAM, paging/swap files, remote logging data
One Comment on “which Joe should collect the data?”
Answer is D. This is text from Darril’s book:
“The order of volatility for data from most volatile to least volatile is
cache memory, regular RAM, swap or paging file, hard drive data,
logs stored on remote systems, and archived media.”