During a forensic investigation, you are asked to acquire the contents of RAM from a live Windows 10 system without causing system instability. Which tool would be most appropriate for this task?
Trap 1: LiME
LiME is for Linux memory acquisition, not Windows.
Trap 2: DumpIt
DumpIt is a command-line tool that can cause system instability.
Trap 3: FTK Imager
FTK Imager can acquire RAM but may not be as stable on live systems.
- A
LiME
Why wrong: LiME is for Linux memory acquisition, not Windows.
- B
DumpIt
Why wrong: DumpIt is a command-line tool that can cause system instability.
- C
FTK Imager
Why wrong: FTK Imager can acquire RAM but may not be as stable on live systems.
- D
Belkasoft RAM Capturer
Belkasoft RAM Capturer is designed for Windows live RAM acquisition and is stable.