What is the “Best Evidence Rule”?
A.
It states that the court only allows the original evidence of a document, photograph, or
recording at the trial rather than a copy
B.
It contains system time, logged-on user(s), open files, network information, process information,
process-to-port mapping, process memory, clipboard contents, service/driver information, and
command history
C.
It contains hidden files, slack space, swap file, index.dat files, unallocated clusters, unused
partitions, hidden partitions, registry settings, and event logs
D.
It contains information such as open network connection, user logout, programs that reside in
memory, and cache data