A first responder needs to collect digital evidence from a compromised headless virtual host. Which of the following should the first responder collect FIRST?
https://docs.vmware.com/en/VMware-vSphere/6.5/com.vmware.vsphere.vm_admin.doc/GUID-38F4D574-ADE7-4B80-AEAB-7EC502A379F4.html
When you take a snapshot, you capture the state of the virtual machine settings and the virtual disk. If you are taking a memory snapshot, you also capture the memory state of the virtual machine. These states are saved to files that reside with the virtual machine's base files.
Watch out
The question is asking you which type of digital device is the most perishable in case of investigating a computer crime taking in to consideration of power outage or some type of disaster that could damage or cause data loss. The the first data that is perishable is data on memory , caches, ruter table. Second less volatile is data in virtual memory so the ANSWER IS D
RAM
Order of Volatility Summary
First responders need to understand the order of volatility, to ensure they protect any potential evidence. The most volatile data includes data in CPU registers, caches, and memory. It is lost if the computer is rebooted. Virtual memory (a swap file) is stored on a disk drive, but is rebuilt when the computer is rebooted. For the CFR exam, Network cache is on about the same level of volatility as a virtual memory. Data on disk drives will stay there, often even after a user attempts to delete it. Backups on tapes and optical discs are have a very low level of volatility. Similarly, remote logs have a very low level of volatility.
Headless virtualization host is a bare metal hypervisor (https://wiki.msp.exchange/faq/create_headless_virutalbox_vhost). Capturing volatile memory is frought with problems (http://www.syssec-project.eu/m/page-media/3/raid13_graziano.pdf). Since capturing volatile memory is an issue within virtualization, the correct answer is capture a snapshot. Virtual memory and RAM, while sound good for order of volatility, don't work for us on a virtual host.
Headless mode means that the virtual machine is running in the background without any foreground elements visible (like the Vmware Fusion application)
You would have no screen to see running the front end; i.e. the screen/console would not be visible, even though the operating system is running, and would typically have to access the machine via SSH.
From stackoverflow......
The given answer is correct.....
With the snapshots, the responder can save the state of the virtual machine for later use and thus this will have all the information even when the system is not running. The snapshots which are taken backup will have the detailed operation of the virtual host.
You cannot snapshot the virtual host, you snapshot the virtual clients. The Virtual Host is the system that HOSTS the Virtual CLIENTS. I think the correct answer is D. RAM, and C. Snapshop is there to trip you up.
"There are different kinds of hypervisors. The hypervisor that we’ve seen so far is a type 2 hypervisor. This is one that runs on top of an existing host operating system. So this is a hypervisor that would run in Windows, in Mac OS, or on the Linux desktop."
https://www.professormesser.com/security-plus/sy0-501/virtualization-overview/
You can snapshot a virtual host. Virtual host here means a host like any other host but this time it doesnt have a physical hardware characteristics, so it is virtual. Meaning, it is a host that is virtual not physical and this is simply a VM
ibeastalot7 is probably right on this specific scenario.
upvoted 1 times
...
...
...
This section is not available anymore. Please use the main Exam Page.SY0-501 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
babati
Highly Voted 4 years, 10 months agocaps
Highly Voted 4 years, 11 months agofonka
Most Recent 3 years, 12 months agofonka
3 years, 12 months agoFreddie26
4 years, 2 months agoNLT
4 years, 5 months agocarlo479
4 years, 10 months agoJacobCrane
4 years, 11 months agoTeza
4 years, 10 months agoHeymannicerouter
4 years, 2 months agobcarr789
5 years agoDante_Dan
4 years, 12 months agoibeastalot7
4 years, 12 months agoAerials
4 years, 11 months ago