Which FTK Imager option should be used to create a forensically sound image of a live system's network share without powering it down?
-
A
Create Disk Image from physical drive
-
B
Add Evidence Item using a logical evidence file
-
C
Capture Memory only
-
D
Decrypt Files option