712-50 Question 376
Single answerUnderstand various digital media devices, e-discovery principles and practices and different file systemsA multinational company receives a litigation hold after allegations that engineers exfiltrated design documents to external media before resigning. The CISO must direct a response that supports legal discovery while preserving potentially relevant evidence from company-issued Windows laptops, macOS laptops, and removable storage devices collected during offboarding. Which action should the CISO prioritize FIRST to best align with sound e-discovery and digital evidence handling practices?
- A
Instruct IT to copy user documents from each device into a shared folder so Legal can immediately search the files
- B
Implement a documented preservation process that suspends routine deletion, captures forensic images of relevant devices where appropriate, and maintains chain of custody for collected media
- C
Reformat all removable drives after confirming the files have been transferred to the enterprise DLP repository
- D
Limit collection to active files in user home directories because deleted files and file system metadata are generally outside normal e-discovery scope
Show answer and explanation
Correct answer: B
Explanation
The best answer is to prioritize defensible preservation with legal hold, forensic collection where appropriate, and chain-of-custody controls. In real-world e-discovery, the CISO should coordinate with Legal, HR, and forensic specialists to identify custodians, data sources, and the appropriate scope of preservation. This is especially important when multiple digital media types and file systems are involved. Windows laptops may use NTFS, macOS systems commonly use APFS, and removable devices may use exFAT or FAT32; each file system stores metadata differently, and that metadata may be material to proving or disproving exfiltration. Best practice is to preserve originals, avoid altering evidence, and collect in a forensically sound manner when facts suggest misconduct. This aligns with common e-discovery and digital forensics principles reflected in defensible preservation practice, chain-of-custody standards, and guidance from sources such as the Federal Rules of Civil Procedure on preservation obligations, the EDRM framework for e-discovery workflow, and NIST guidance on forensic collection and handling.
- A. Incorrect.
This is incorrect because simply copying user documents into a shared folder can alter metadata such as timestamps, omit deleted data and file system artifacts, and break defensibility. In an investigation involving possible exfiltration to external media, relevant evidence may include metadata, link files, USB usage artifacts, deleted content, and file system records. A basic copy also weakens chain-of-custody controls and may be challenged by opposing counsel.
- B. Correct.
This is correct because the first priority is defensible preservation. A documented legal hold and preservation workflow should stop routine deletion and modification, identify relevant custodians and devices, and preserve evidence in a manner suitable for downstream forensic and legal review. Forensic imaging is often appropriate when there is a credible need to preserve file system metadata, deleted files, slack or unallocated space, and usage artifacts across file systems such as NTFS, APFS, exFAT, or FAT32. Maintaining chain of custody supports evidentiary integrity and admissibility.
- C. Incorrect.
This is incorrect because reformatting removable drives destroys potentially relevant evidence, including deleted files, volume metadata, directory structures, and timestamps. Even if files were copied elsewhere, the original media may contain evidence of transfer activity and remnants needed for forensic reconstruction. Reformatting after notice of litigation can constitute spoliation.
- D. Incorrect.
This is incorrect because e-discovery and investigations often extend beyond active user files when proportional and relevant. Deleted files, metadata, and file system artifacts can be highly relevant in an exfiltration matter. On NTFS, for example, artifacts in the Master File Table and other metadata may be useful; on APFS, snapshots and metadata may matter; removable media formatted with exFAT or FAT32 may retain directory and allocation evidence. Restricting collection only to active files risks missing key evidence.