インシデント発生中、アナリストは後の調査のために証拠を入手する必要があります。揮発性レベルに関連して、コンピュータ システムで最初に収集する必要があるものは次のうちどれですか?
正解:D
The most volatile type of evidence that must be collected first in a computer system is running processes.
Running processes are programs or applications that are currently executing on a computer system and using its resources, such as memory, CPU, disk space, or network bandwidth. Running processes are very volatile because they can change rapidly or disappear completely when the system is shut down, rebooted, logged off, or crashed. Running processes can also be affected by other processes or users that may modify or terminate them. Therefore, running processes must be collected first before any other type of evidence in a computer system