712-50 exam dumps

712-50 practice question 377 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 377

Single answerUnderstand various digital media devices, e-discovery principles and practices and different file systems

During a regulatory investigation, a multinational company receives a legal hold requiring preservation and collection of potentially relevant data from executive laptops, employee USB drives, and a file server used by the finance team. The CISO must ensure the collection approach is defensible, minimizes spoliation risk, and preserves metadata needed for later analysis. Which action is the BEST first step to direct the response team?

  1. A

    Immediately copy user-visible files from each device to a shared folder so counsel can review content quickly

  2. B

    Create forensically sound bit-level images of relevant media where appropriate, document chain of custody, and coordinate with counsel to scope custodians, data sources, and preservation requirements

  3. C

    Rely on endpoint backup agents to restore the latest versions of files because backup copies are sufficient for e-discovery purposes

  4. D

    Convert all collected files to PDF to normalize formats and reduce compatibility issues before preserving them

Show answer and explanation

Correct answer: B

Explanation

The best answer is to begin with a defensible preservation and collection strategy coordinated with legal counsel. In practice, e-discovery starts with identifying custodians and data sources, issuing and enforcing legal holds, preserving potentially relevant electronically stored information (ESI), and documenting chain of custody. For devices such as laptops and USB media, bit-level imaging is often appropriate when metadata, deleted artifacts, or file system evidence may matter. This is particularly relevant across file systems such as NTFS, exFAT, FAT32, APFS, or ext4, each of which stores metadata and artifacts differently. For example, NTFS can contain Master File Table entries and alternate data streams; removable media may use FAT32 or exFAT with different artifact availability; and server shares may require targeted collection methods depending on scope and proportionality. Best practices align with broadly accepted forensic principles such as preserving original evidence, using repeatable methods, hashing collected data, and maintaining chain of custody. Guidance from sources such as the Electronic Discovery Reference Model (EDRM), NIST digital evidence handling guidance, and legal-hold/e-discovery practice standards supports preserving data in a manner that is reasonable, documented, and defensible.

  • A. Incorrect.

    This is incorrect because simply copying user-visible files may omit deleted items, slack space, file system artifacts, timestamps, alternate data streams, and other metadata that can be relevant depending on the matter. It also weakens defensibility if the process is not documented and may alter access times or other metadata. A quick file copy may be useful in some targeted collections, but it is not the best first step for a legally sensitive investigation spanning multiple media types.

  • B. Correct.

    This is correct because a defensible e-discovery and digital forensics response begins with legal and investigative scoping, preservation, and documented handling. Coordinating with counsel helps define custodians, date ranges, proportionality, and jurisdictional constraints. Creating forensically sound bit-level images where appropriate preserves the underlying file system and metadata on devices such as laptops and removable media, while chain of custody documentation supports admissibility and integrity. This approach is especially important when different file systems may contain artifacts beyond active files, such as NTFS metadata, deleted entries, or timestamps relevant to the matter.

  • C. Incorrect.

    This is incorrect because backup systems are designed for recovery, not necessarily forensically defensible collection. Backups may not preserve the full context of the original media, may deduplicate or alter metadata, and often do not capture deleted data or device-level artifacts needed for investigation. While backups can be a supplemental source in e-discovery, relying on them alone is a common misconception.

  • D. Incorrect.

    This is incorrect because converting files to PDF before preservation changes the original format and can strip or alter metadata, embedded objects, formulas, comments, and other potentially relevant information. In e-discovery, original or natively preserved data is typically preferred when metadata matters. Normalization for review may happen later in the workflow, but preservation should protect originals first.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam