A compromised endpoint must be powered off for forensic imaging, but the analyst first captures RAM, active network connections, and running processes. Before shutdown, which documentation action best preserves the investigative value of this volatile data?
Select an answer to reveal the explanation.
Short Explanation
Think of volatile evidence like a melting snowflake: once the power is off, the shape is gone. You should note the collection order, timestamps, and custody details while you're still capturing it, because that record makes the evidence usable later. Skip it, and you've got raw data no one can trust.
Full Explanation
Volatile memory and process/network state change continuously, so the value of the collected artifact depends on contemporaneous documentation. Recording the sequence of commands or tools, the exact collection times with source timezone, and the person handling the data creates a chain of custody that lets another analyst correlate the artifact with system logs, EDR telemetry, and the incident timeline. Without that record, the artifact may be accurate but unusable for analysis, escalation, or legal review. A summary written after shutdown is too late because volatile data is lost at power-off and the collection steps cannot be reconstructed reliably. Identifying only the business owner and asset tag supports reporting and ownership, but it does not explain what was captured, how, or by whom. Relying on the SIEM alert ID and severity score may tie the activity to an event, yet automated correlation cannot replace human documentation of forensic collection actions. Exam caveat: volatile data preservation is an IR technique, but the question tests the reporting and communication value of the documentation, not the tool used to acquire the artifact. Operational check: before powering off the endpoint, record each acquisition step in the incident ticket with UTC timestamps, analyst name, tool/version, and hash of the saved output.