An incident responder is tasked with collecting forensic evidence from a Programmable Logic Controller (PLC) that is actively controlling a critical industrial process. The highest priority is to preserve evidence of a potential memory-resident attack without halting the physical process. Which of the following is the MOST appropriate initial action?
-
A
Perform a live memory acquisition of the PLC over the network.
-
B
Immediately power down the PLC to prevent evidence tampering and create a disk image.
-
C
Isolate the PLC from the network and connect it to a forensic workstation.
-
D
Request the engineering project files from the workstation to compare with the running logic.