List of questions
Related questions
Question 630 - 312-49v10 discussion
Derrick, a forensic specialist, was investigating an active computer that was executing various processes. Derrick wanted to check whether this system was used In an Incident that occurred earlier. He started Inspecting and gathering the contents of RAM, cache, and DLLs to Identify Incident signatures. Identify the data acquisition method employed by Derrick in the above scenario.
A.
Dead data acquisition
B.
Static data acquisition
C.
Non-volatile data acquisition
D.
Live data acquisition
Your answer:
0 comments
Sorted by
Leave a comment first