Questions
Answer the following questions to test your knowledge of this chapter:
- When looking at the order of volatility, which of the following evidence categories should be acquired first?
- Random Access Memory
- Pagefile or Swap File
- Central Processing Unit, Registers
- Storage Drive
- It is a good practice to acquire the pagefile with RAM if using FTK Imager.
- True
- False
- When recreating the memory from a virtual system, responders should acquire both the VMSS and VMEM file.
- True
- False