Question 1 of 157%
Computer Forensics Labmedium

During a forensic investigation, an analyst needs to acquire data from a live Windows system without altering the system's state. Which tool should the analyst use to capture the contents of RAM?

Select one: