Add to Chrome
✅ The verified answer to this question is available below. Our community-reviewed solutions help you understand the material better.
If the computer you have to examinate has been shutdown, what is your best way to analyze volatile data ?
Capture the RAM with a tool like FTK or WinPMEM
Download the Swapfile and the Pagefile : %SystemDrive%\pagefile.sys OR%SystemDrive%\swapfile.sys
Download the Swapfile and the Pagefile : %SystemDrive%\pagefile.sys OR
%SystemDrive%\swapfile.sys
Restart the computer in a forensics environment
Collect the Kernel-mode(crash) Dump files : %SystemRoot%\MEMORY.DMP
Collect the Kernel-mode
(crash) Dump files : %SystemRoot%\MEMORY.DMP
Get the Hibernation file : %SystemDrive%\hiberfil.sys
Get Unlimited Answers To Exam Questions - Install Crowdly Extension Now!