During an incident response engagement, a forensic examiner discovers that volatile memory contains evidence of a running malware process. What is the MOST appropriate first action?
-
A
Immediately power off the system to preserve the hard drive
-
B
Capture a memory dump before taking any other action
-
C
Run antivirus software to identify and remove the malware
-
D
Disconnect the system from the network and reboot