When would you pull the power on a compromised host instead of shutting it down cleanly?
answer
- both options end memory
- shutdown is code that gets to run
- the price lands on the filesystem
- sleep and hibernate are not a third option
basics
~20 sWhen you believe the host is still under an intruder's control. A clean shutdown runs shutdown handlers and cleanup tasks - an execution opportunity for destructive code. A hard power cut freezes the stored state, at the cost of an unclean filesystem.
solid answer
~50 sBoth options end memory, so this only arises once any live collection is finished or ruled out. A graceful shutdown asks the operating system to run code on the way down: logoff and shutdown scripts, service stop handlers, temporary-file cleanup, log rotation, and the dismount of any mounted container. On a machine you believe an adversary controls, that is a hook they can use to wipe or tidy. A hard power cut denies them that and freezes the stored state as it stands. The cost is cleanliness: the volume comes back dirty, NTFS replays its `$LogFile` and ext4 its journal on the next mount, writes in flight are lost, and a database needs crash recovery. On a laptop that is a fine trade; on a production server it may not be, and you say so rather than reciting a rule. Sleep and hibernate are not a third option.
go deeper
Know that a hard power cut and a clean shutdown both end memory, and that on a machine you believe an intruder controls the default is the hard cut.
Explain the mechanism on each side: a shutdown runs handlers and cleanup tasks, while a power cut leaves a dirty volume, journal replay and lost writes in flight.
Weigh it for the specific host — evidence lost to a shutdown hook against recovery cost on a live system — and rule sleep and hibernate out explicitly rather than leaving them open.
Own a pre-agreed default per class of asset, so that nobody is inventing the policy on a phone bridge at three in the morning with an adversary still logged in.
## The question only exists after the live decision A hard power cut and a clean shutdown both end memory. Neither preserves keys, processes or network state. So this is not a choice about volatile evidence — it is a choice about the *stored* state and about what code gets to run before the machine stops. If there is anything you wanted from the running system, it must already be collected before either option is on the table. ## What a graceful shutdown actually does 'Shut down cleanly' means asking the operating system to run its shutdown path. That path is code: - logoff and shutdown scripts configured on the machine or pushed by policy - service and application stop handlers, which flush caches and write final state - temporary-file cleanup, log rotation, and on some configurations clearing of the page file - unmounting of mounted volumes and containers, which discards their keys - scheduled tasks that fire on shutdown On a healthy machine all of that is desirable. On a machine you believe an adversary still controls, it is an execution opportunity handed over on request. Destructive tooling that reacts to shutdown is not exotic, and even without it, the ordinary cleanup path deletes things you might have wanted. A clean shutdown is the machine's chance to tidy itself up, and tidying up is the opposite of what you want. ## What a power cut actually costs Cutting power freezes the storage device exactly as it was at that instant, at the price of an unclean volume: - NTFS replays its `$LogFile` when the volume is next mounted; ext4 and similar filesystems replay their journals - writes in flight are lost, and a file being written may be truncated or partially written - databases and other stateful services come back in crash recovery, which can take time and can lose recent transactions - caches never flushed simply vanish For a forensic examination this is usually acceptable and bounded: you examine a copy, and journal replay affects the mounting system rather than the copy you took. For the business, on a machine doing real work, it may not be acceptable at all. That is the trade you are being asked to weigh. ## How the answer differs by host On a **laptop or workstation** you believe is compromised, the hard cut is the usual default: little is lost, and you deny the shutdown hook. Note that 'pull the plug' on a laptop means holding the power button until it dies — the battery is generally not removable, and unplugging the charger achieves nothing. On a **server** carrying production data, the calculation shifts. If the service owner can quiesce the workload and the host can be cut off from the network first, a controlled stop may well be the better call. A candidate who answers 'always pull the plug' without naming this exception is reciting rather than reasoning. On a **virtual machine**, the equivalent of a power cut is a hard stop from the hypervisor, and the hypervisor may also be able to snapshot memory and state — a materially better option that exists only in that environment. ## Sleep, hibernate and closing the lid are not a middle path The tempting third option — 'just close the lid and deal with it later' — is the worst choice available, because it is a state change you did not choose: - suspend or hibernate can cause a mounted container to dismount and keys to be re-protected - hibernation writes the contents of memory onto the disk, altering the exact volume you were about to acquire - a machine that resumes may resume with the adversary's session still live Decide the power state deliberately. Never let the lid switch decide it for you. ## What a good answer sounds like 'Both kill memory, so this comes after live collection. On a host I believe is owned I take the hard cut, because a clean shutdown runs shutdown handlers I do not control and cleanup tasks that delete evidence. The cost is a dirty volume and journal replay, which I can live with on an endpoint. On a production database I would want the service owner in the conversation and would consider a controlled stop after isolating the host. And I would rule out sleep and hibernate explicitly, because hibernation writes memory onto the disk I am about to image.'
- What does the hard power cut cost you on the disk itself?An unclean volume. NTFS replays its `$LogFile` and ext4 its journal on the next mount, writes in flight are lost or half-written, and stateful services come back in crash recovery. For an examination of a copy that is usually a bounded, acceptable cost; on a busy production host it can mean data loss the business actually feels.
- Why is closing the lid the worst of the three options?Because it is a state change you did not choose. Suspend or hibernate can dismount a mounted container and re-protect keys, hibernation writes memory onto the disk you were about to acquire, and a machine that resumes may resume with the intruder's session intact. Pick a power state deliberately instead of letting the hardware pick one.
- The host is a production database server rather than a laptop. Does the answer change?Yes. The reason to cut power is to deny an adversary's code a shutdown hook, and that has to be weighed against crash-recovering a live database. If the service owner can stop the workload and the host is already cut off from the network, a controlled stop is defensible. State the trade rather than reciting a universal rule.
saying these in an interview costs you the question
- Says always pull the plug, with no reasoning
- Thinks a graceful shutdown preserves memory
- Ignores that shutdown handlers are code that runs
- Treats suspend or hibernate as a safe pause
- Believes an unclean filesystem makes the image worthless