Chain of Custody, Drive Copies, and Order of Volatility for A+
Short answer
A technician encountering a suspected security incident should avoid making changes to original media. Best practice: if you must collect data, capture volatile state first (e.g., RAM, running processes, network connections), then create a bit-for-bit copy (forensic image) of storage media and calculate cryptographic hashes (MD5/SHA1/SHA256 as available) to show integrity. Record each transfer, who handled the device, times, and storage locations to maintain chain of custody.
Why it appears on the exam
- Given a short scenario, choose the correct sequence for data capture (order of volatility) for a live workstation. - Identify which actions preserve evidence and which risk altering or destroying volatile evidence. - Recognize when to escalate to a forensic specialist versus performing an operational preservation copy.
Key concepts
Concept 1
Required terms
chain of custody: A documented, auditable record that tracks who had possession of evidence, when, and under what conditions to preserve integrity for later review or legal use. order of volatility: A prioritized sequence for capturing data from a running system, starting with the most transient (like RAM) and ending with the least volatile (like archived files on disk). chain of custody: documented audit of evidence possession and handling. order of volatility: prioritized sequence for capturing data (RAM, running processes, network, disk).
Example
Example 1: Laptop with suspected malware. Technician documents device state, takes photos, captures screenshots of running processes, collects network logs if possible, then performs a forensic image of the drive to a secured storage device and records hashes and custody transfers.
Concept 2
How Chain of Custody, Drive Copies, and Order of Volatility works
A technician encountering a suspected security incident should avoid making changes to original media. Best practice: if you must collect data, capture volatile state first (e.g., RAM, running processes, network connections), then create a bit-for-bit copy (forensic image) of storage media and calculate cryptographic hashes (MD5/SHA1/SHA256 as available) to show integrity. Record each transfer, who handled the device, times, and storage locations to maintain chain of custody.
Example
Example 2: Server under active attack. Team captures memory and network state first (order of volatility), then isolates the server from the network and images disks for preservation.
Concept 3
Common confusion
- "Imaging the drive is enough": Imaging is important but capturing volatile memory and network state first may preserve evidence that disappears on shutdown. - "A ticket note counts as chain of custody": Casual ticket notes lack the structured fields (who, when, where, handover signatures) required for admissible chain-of-custody records.
Example
Example 1: Laptop with suspected malware. Technician documents device state, takes photos, captures screenshots of running processes, collects network logs if possible, then performs a forensic image of the drive to a secured storage device and records hashes and custody transfers.
Concept 4
Core 2 (220-1202) question cues
Given a short scenario, choose the correct sequence for data capture (order of volatility) for a live workstation; Identify which actions preserve evidence and which risk altering or destroying volatile evidence; Recognize when to escalate to a forensic specialist versus performing an operational preservation copy.
Example
Example 2: Server under active attack. Team captures memory and network state first (order of volatility), then isolates the server from the network and images disks for preservation.
Sample questions
Select an answer to reveal the explanation. For tracked practice and weak-area review, use the Cultiv8 app.
Q1.An A+ support scenario describes this situation: Example 1: Laptop with suspected malware. Technician documents device state, takes photos, captures screenshots of running processes, collects network logs if possible, then performs a forensic image of the dri... Which answer fits best?
Q2.A support ticket includes this clue: Example 2: Server under active attack. Team captures memory and network state first (order of volatility), then isolates the server from the network and images disks for preservation. Which concept is being tested?
Q3.Read this A+ scenario: Example 2: Server under active attack. Team captures memory and network state first (order of volatility), then isolates the server from the network and images disks for preservation. Which term or action matches it?
Practice this lesson in Cultiv8
The app adds tracked practice, targeted remediation, saved session history, and future readiness scoring.
Continue in Cultiv8