1. During live response, which order best follows the order of volatility?
Volatile data disappears first. Capture the most short-lived items early. That preserves evidence that would be gone by the time you power off or image the drive.
Quick set: mem dump → netstat → process list → selective disk grabs