Your individual project for this unit has you researching and applying your knowledge of digital evidence volatility, and the order of volatility.
With the identification and preservation of the physical and digital evidence completed the incident response team must now enter the data collection phase. During the data collection phase, the investigative team must collect volatile evidence first, and non-volatile second. For each of the four items in the list below (SSD, Virtual Memory, CPU Cache, and Printout), perform the following three actions:
Identify if they are volatile and non-volatile, and their correct order of volatility
Explain the importance of the order of volatility
Describe the methods to both collect and analyze at least two types of evidence from this list.
The postfirst appeared on .