Which of the following actions provides the BEST evidence for forensic analysis of powered-off device?
Copy all potentially useful files from the system to a network drive.
Image the entire hard disk on an external drive.
Copy all system and application log files to an external drive.
Collect the memory, running processes, and temporary files.
Submit