Cold-boot attack
Recovering data such as disk encryption keys from a computer's RAM shortly after power is cut, exploiting the fact that memory contents fade over seconds or minutes rather than at once.
A cold-boot attack reads the contents of dynamic RAM after a machine has been powered off or restarted. DRAM does not lose its contents instantly: the charge decays over seconds to minutes, and cooling the chips slows it further. An attacker with physical access restarts the machine from a small boot tool or moves the memory modules to another computer, then dumps the memory and searches it for key material. Halderman and colleagues demonstrated the technique in 2008, recovering full-disk encryption keys from laptops.
The attack matters because it targets data in use. A laptop that is running, locked or asleep keeps its disk encryption key in memory, so full-disk encryption gives it much weaker protection than a machine that is fully shut down. It is a memory form of data remanence, not a side-channel attack, which infers secrets from timing, power or emissions. Countermeasures include shutting down fully rather than sleeping, pre-boot authentication, firmware that clears memory at start-up, hardware memory encryption, and physical protection of the device.
Exam relevance: a scenario is likely to describe a laptop stolen while asleep rather than switched off, with full-disk encryption enabled. Candidates are expected to see that encryption at rest does not protect a key held in memory, and that a full shutdown is a simple mitigation.