Question 1 of 30
Consider a scenario where investigators are responding to a live system suspected of containing critical digital evidence. The system is powered on and actively running applications. Which of the following actions, if prioritized first, would best adhere to the principles of digital evidence handling as defined by ISO/IEC 27037:2012 to preserve the integrity of potentially volatile information?
Conduct a forensically sound acquisition of the system's Random Access Memory (RAM).
Initiate a full disk image of the system's primary storage device.
Power down the system in a controlled manner to prevent data corruption.
Document the physical state of the computer hardware and peripherals.

Preparing for ISO/IEC 27037:2012 - Digital Evidence Handling Professional? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free