What is the primary purpose of acquiring volatile memory (RAM) during a digital forensics investigation?
-
A
To preserve encryption keys, passwords, and running process data that would be lost on shutdown
-
B
To create a forensic backup of the hard drive contents
-
C
To analyze stored network traffic logs from the past 30 days
-
D
To recover deleted files from unallocated filesystem clusters