Order of volatility is a procedure that a computer forensics examiner must follow during evidence collection. It refers to the order in which digital evidence is collected, starting with the most volatile and moving to the least volatile. Volatile data is data that is not permanent and is easily lost, such as data in memory when you turn off a computer. The security analyst should have followed the order of volatility to preserve the most fragile evidence first, such as the malicious script running as a background process, before turning off the infected machine. Verified Reference: https://www.computer-forensics-recruiter.com/order-of-volatility/ https://www.sans.org/blog/best-practices-in-digital-evidence-collection/ https://blogs.getcertifiedgetahead.com/order-of-volatility/