exam questions

Exam SY0-501 All Questions

View all questions & answers for the SY0-501 exam

Exam SY0-501 topic 1 question 801 discussion

Actual exam question from CompTIA's SY0-501
Question #: 801
Topic #: 1
[All SY0-501 Questions]

A first responder needs to collect digital evidence from a compromised headless virtual host. Which of the following should the first responder collect FIRST?

  • A. Virtual memory
  • B. BIOS configuration
  • C. Snapshot
  • D. RAM
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
babati
Highly Voted 4 years, 10 months ago
https://docs.vmware.com/en/VMware-vSphere/6.5/com.vmware.vsphere.vm_admin.doc/GUID-38F4D574-ADE7-4B80-AEAB-7EC502A379F4.html When you take a snapshot, you capture the state of the virtual machine settings and the virtual disk. If you are taking a memory snapshot, you also capture the memory state of the virtual machine. These states are saved to files that reside with the virtual machine's base files.
upvoted 9 times
...
caps
Highly Voted 4 years, 11 months ago
If a headless virtual host is COMPROMISED, Snapshot allows to create a copy quickly and obtain the digital info.
upvoted 6 times
...
fonka
Most Recent 3 years, 12 months ago
This link will tell you why ram is the answer not snapshot
upvoted 1 times
...
fonka
3 years, 12 months ago
Watch out The question is asking you which type of digital device is the most perishable in case of investigating a computer crime taking in to consideration of power outage or some type of disaster that could damage or cause data loss. The the first data that is perishable is data on memory , caches, ruter table. Second less volatile is data in virtual memory so the ANSWER IS D RAM Order of Volatility Summary First responders need to understand the order of volatility, to ensure they protect any potential evidence. The most volatile data includes data in CPU registers, caches, and memory. It is lost if the computer is rebooted. Virtual memory (a swap file) is stored on a disk drive, but is rebuilt when the computer is rebooted. For the CFR exam, Network cache is on about the same level of volatility as a virtual memory. Data on disk drives will stay there, often even after a user attempts to delete it. Backups on tapes and optical discs are have a very low level of volatility. Similarly, remote logs have a very low level of volatility.
upvoted 2 times
...
Freddie26
4 years, 2 months ago
Headless virtualization host is a bare metal hypervisor (https://wiki.msp.exchange/faq/create_headless_virutalbox_vhost). Capturing volatile memory is frought with problems (http://www.syssec-project.eu/m/page-media/3/raid13_graziano.pdf). Since capturing volatile memory is an issue within virtualization, the correct answer is capture a snapshot. Virtual memory and RAM, while sound good for order of volatility, don't work for us on a virtual host.
upvoted 5 times
...
NLT
4 years, 5 months ago
Headless mode means that the virtual machine is running in the background without any foreground elements visible (like the Vmware Fusion application) You would have no screen to see running the front end; i.e. the screen/console would not be visible, even though the operating system is running, and would typically have to access the machine via SSH. From stackoverflow......
upvoted 1 times
...
carlo479
4 years, 10 months ago
The given answer is correct..... With the snapshots, the responder can save the state of the virtual machine for later use and thus this will have all the information even when the system is not running. The snapshots which are taken backup will have the detailed operation of the virtual host.
upvoted 2 times
...
JacobCrane
4 years, 11 months ago
You cannot snapshot the virtual host, you snapshot the virtual clients. The Virtual Host is the system that HOSTS the Virtual CLIENTS. I think the correct answer is D. RAM, and C. Snapshop is there to trip you up. "There are different kinds of hypervisors. The hypervisor that we’ve seen so far is a type 2 hypervisor. This is one that runs on top of an existing host operating system. So this is a hypervisor that would run in Windows, in Mac OS, or on the Linux desktop." https://www.professormesser.com/security-plus/sy0-501/virtualization-overview/
upvoted 1 times
Teza
4 years, 10 months ago
You can snapshot a virtual host. Virtual host here means a host like any other host but this time it doesnt have a physical hardware characteristics, so it is virtual. Meaning, it is a host that is virtual not physical and this is simply a VM
upvoted 1 times
Heymannicerouter
4 years, 2 months ago
I think what they mean by "headless virtual host" is basically a bare metal hypervisor like VMware ESXi, at least that's how I interpret it.
upvoted 1 times
...
...
...
bcarr789
5 years ago
I thought the data should be collected according to the order of volatility. Wouldn't (D) RAM be correct?
upvoted 3 times
Dante_Dan
4 years, 12 months ago
I think you are correct. Should be RAM. Answer D
upvoted 1 times
...
ibeastalot7
4 years, 12 months ago
I think because is states virtual host that means the snapshot is like cache correct?
upvoted 12 times
Aerials
4 years, 11 months ago
ibeastalot7 is probably right on this specific scenario.
upvoted 1 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...