712-50 exam dumps

712-50 practice question 375 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 375

Single answerSet up and manage forensic labs and programs

A newly appointed CISO is establishing an internal digital forensics lab after several regulatory investigations exposed weaknesses in the organization’s evidence handling. The board wants the program to support HR, legal, and incident response investigations while minimizing the risk that evidence will be challenged in court. Budget is available for tooling, but the organization operates in multiple jurisdictions and expects outside experts to assist during major cases. Which action should the CISO prioritize FIRST to build a defensible and scalable forensic lab program?

  1. A

    Acquire a broad set of commercial forensic tools so investigators can process any media type without delay

  2. B

    Define formal governance for the forensic program, including evidence handling procedures, chain-of-custody requirements, lab access controls, and criteria for when to use external specialists

  3. C

    Build a dedicated isolated lab network and prohibit all connections to production systems to eliminate contamination risk

  4. D

    Train all incident responders to perform full forensic imaging so the organization can avoid relying on third parties

Show answer and explanation

Correct answer: B

Explanation

The most defensible first step in setting up and managing a forensic lab and program is establishing governance and operating procedures before buying tools or expanding staff duties. In practice, forensic programs should define scope, authority, case intake, evidence acquisition standards, chain of custody, storage and retention, quality assurance, access control, reporting, jurisdictional/legal review, and escalation to external specialists. This aligns with widely accepted forensic and incident handling principles reflected in guidance such as NIST SP 800-86 (Guide to Integrating Forensic Techniques into Incident Response), NIST SP 800-61 (Computer Security Incident Handling Guide), and ISO/IEC 27037 guidance on identification, collection, acquisition, and preservation of digital evidence. A CISO must ensure the program is repeatable, auditable, and legally supportable across business units and jurisdictions. Once governance is in place, the organization can select validated tools, design an appropriate lab environment, and define training and outsourcing models consistent with risk, legal requirements, and expected case volume.

  • A. Incorrect.

    This is not the best first step. Commercial tools can improve capability, but tools alone do not make a forensic program legally defensible. Without documented processes for acquisition, preservation, handling, validation, storage, access control, and escalation, evidence may be challenged regardless of the tools used. A common misconception is that buying leading tools is the main determinant of forensic quality, when governance and repeatable procedure are more foundational.

  • B. Correct.

    This is the best answer. A defensible forensic lab program begins with governance: documented standard operating procedures, chain-of-custody practices, evidence preservation requirements, role separation, access control, jurisdictional considerations, and engagement criteria for internal versus external experts. These controls create consistency across cases and help demonstrate integrity and admissibility of evidence. From a CCISO perspective, this is the strategic foundation that enables tooling, staffing, and facility design to support business, legal, and regulatory needs.

  • C. Incorrect.

    This is a useful technical control, but it should not be the first priority. Isolation can reduce contamination risk and protect evidence systems, yet a lab design decision must be driven by policy, case requirements, and operating procedures. Also, forensic work sometimes requires tightly controlled methods for interacting with enterprise systems, evidence repositories, or update services. The misconception here is treating infrastructure design as the starting point rather than an implementation detail derived from governance requirements.

  • D. Incorrect.

    This is not the best first action. Training incident responders can improve readiness, but broadening imaging responsibilities without defined procedures and competency standards can increase evidence handling risk. In many organizations, first responders should perform limited preservation steps while qualified forensic personnel or vetted external experts handle full acquisition and analysis, depending on legal sensitivity, jurisdiction, and case complexity. The distractor reflects the common but risky assumption that insourcing all activity is automatically better than using specialists.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam