ExamRange

CND (312-38) Network Defense Simulation

Understanding hardware architecture is critical for network defenders. Learn how volatile memory dictates the order of volatility during live network incident response.

Network Scenario

You are a network security analyst responding to a suspected compromise on a critical edge firewall. IDS alerts indicate beaconing activity originating from the firewall itself, suggesting a potential in-memory rootkit or advanced persistent threat (APT) residing in the device's RAM. A junior analyst suggests immediately pulling the power plug to stop the beaconing and "clean" the device. You must intervene and explain the properties of the firewall's memory architecture to ensure crucial network forensic evidence—such as active state tables, running processes, and the routing cache—is not permanently destroyed.

Traffic & Logs

[EDGE-FW-01] # show connection active details Total active connections: 1024 ... Protocol: TCP Source IP: 10.0.5.50:49211 Destination IP: 198.51.100.88:443 State: ESTABLISHED Bytes: 45000 / 1200 Flags: U (Up), I (In-memory payload suspect) Age: 04:12:00 [ALERT] The active state table shown above resides entirely in system RAM.

Question

Which of the following statements are true about volatile memory? Each correct answer represents a complete solution. Choose all that apply.

Select multiple options, then click Submit.