exam questions

Exam CS0-002 All Questions

View all questions & answers for the CS0-002 exam

Exam CS0-002 topic 1 question 259 discussion

Actual exam question from CompTIA's CS0-002
Question #: 259
Topic #: 1
[All CS0-002 Questions]

A digital forensics investigator works from duplicate images to preserve the integrity of the original evidence. Which of the following types of media are MOST volatile and should be preserved? (Choose two.)

  • A. Memory cache
  • B. Registry file
  • C. SSD storage
  • D. Temporary filesystems
  • E. Packet decoding
  • F. Swap volume
Show Suggested Answer Hide Answer
Suggested Answer: AF 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
gnnggnnggnng
Highly Voted 2 years, 2 months ago
Selected Answer: AD
Memory cache and temporary filesystems are considered the most volatile types of media because they contain information that can be easily overwritten or lost when the system is restarted or powered off. Memory cache, also known as RAM, is used to temporarily store data and commands that are frequently accessed by the computer's processor. This data is not permanently stored on the computer's hard drive, making it vulnerable to being lost or overwritten when the system is restarted. Temporary filesystems, also known as temp files, are used to store data that is temporarily needed for a specific process or task. These files are not meant to be permanent and are usually deleted when the task is completed. However, in some cases, these files may contain important information that is relevant to a digital forensics investigation. If not properly preserved, this data can be easily lost or overwritten, making it important for the digital forensics investigator to preserve these types of media.
upvoted 12 times
...
karpal
Highly Voted 1 year, 10 months ago
Selected Answer: AF
key word is : types of MEDIA (memory cache and swap files) are a type of media. Temp files are not a MEDIA
upvoted 7 times
...
Dree_Dogg
Most Recent 1 year, 7 months ago
terrible question
upvoted 6 times
...
Big_Dre
1 year, 7 months ago
Selected Answer: AD
watched J Dion and i think i will go with A and D though swap files are highly volatile too but i will go with what i know.
upvoted 2 times
...
Bubu3k
1 year, 8 months ago
Comptia....for an old Sec+ the answer for such a question had the option for Swap/Temp files...wonder if they actually have an engineer look over their questions or just bureaucrats...
upvoted 2 times
Nixon333
1 year, 8 months ago
I watched Jason Dion's videos today and he also mentioned temporary swap files. Im confused.
upvoted 1 times
...
...
Sleezyglizzy
1 year, 9 months ago
AD sec+ question almost
upvoted 2 times
...
nomad421
1 year, 9 months ago
Selected Answer: AF
Memory cache and Swap are considered volatile memory Temp files live in C:\Users\AppData\Local\Temp (not volatile)
upvoted 4 times
...
kiduuu
1 year, 11 months ago
Selected Answer: AD
Temporary filesystems are another type of volatile storage that are used to store temporary data and files. They are typically used by applications during runtime and may contain important data that can be lost when the system is shut down or restarted.
upvoted 1 times
...
khrid4
2 years ago
Selected Answer: AD
The main reference as seen from the book for order of volatility can be seen here: The ISOC best practice guide to evidence collection and archiving, published as tools.ietf.org/html/rfc3227
upvoted 2 times
...
Nuke2020
2 years ago
Selected Answer: AF
Based on the order of volatility, memory cache is first and then swap volume (i.e. paging file for windows), because both can be erased when rebooting. https://blogs.getcertifiedgetahead.com/cfr-and-order-of-volatility/
upvoted 6 times
...
2Fish
2 years, 1 month ago
Selected Answer: AD
I am torn on this one, we know Memory Cache is a given. so we are left with Swap volume (swap space) or Temp files. I would lean to Temp files since most of what you would need besides that is Cache.
upvoted 1 times
...
IanRogerStewart
2 years, 2 months ago
Selected Answer: AF
The swap file is considered to be a extension of RAM and is lost on reboot. It's thus higher on the volatility hierarchy than the temp files.
upvoted 5 times
...
gnnggnnggnng
2 years, 2 months ago
Selected Answer: AD
References: NIST SP 800-86, Guide to Integrating Forensic Techniques into Incident Response SANS Institute, Digital Forensics and Incident Response (DFIR) Fundamentals Course.
upvoted 2 times
...
IanRogerStewart
2 years, 2 months ago
This is a tricky one - both the swap file and the temporary files are highly volatile - I don't know which would be be put above the other and I can't find any reference that specifies this.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago