During a forensic investigation, an analyst needs to preserve evidence from a compromised system. Which action should be performed FIRST?
-
A
Run antivirus to clean the system
-
B
Capture a memory dump before powering off
-
C
Reboot the system to apply patches
-
D
Delete suspicious processes immediately