Volatile data (RAM content) = 只存在 while computer running。Power off = 永久失去。取證時要先 capture volatile data。
「power off immediately」→ 會 destroy volatile evidence。先 capture volatile,才 power off。
Q1002
Forensic team was commissioned to analyze processes. Why NOT disconnect power first?
ATo prevent disk corruption
BTo avoid loss of data stored in volatile memory
CTo conduct a hot-swap of the main disk drive
DTo prevent overwriting
廣東話拆解Volatile memory (RAM) = lost when power off。取證前先 capture volatile data(processes, network connections, encryption keys)。