Practice Test Geeks home

CFE Incident Response and Reporting 2

During an incident response engagement, a forensic examiner discovers that volatile memory contains evidence of a running malware process.
What is the MOST appropriate first action?

Select your answer