712-50 exam dumps

712-50 practice question 379 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 379

Single answerDevelop and manage an organizational digital forensic program

A newly appointed CISO is formalizing an enterprise digital forensic program after several investigations were challenged by internal audit for inconsistent evidence handling and poor admissibility preparation. The organization operates across multiple countries, relies heavily on cloud services, and uses both internal responders and external forensic specialists during major incidents. Which action should the CISO prioritize FIRST to establish a defensible and scalable forensic capability?

  1. A

    Purchase a single enterprise forensic toolkit and require all investigators to use it for every case

  2. B

    Establish standardized forensic governance, including evidence handling procedures, chain-of-custody requirements, legal/regulatory coordination, and role-based escalation criteria

  3. C

    Outsource all digital forensic activities to an external specialist firm to improve neutrality and reduce internal overhead

  4. D

    Increase log retention across all systems to the maximum period allowed by storage budgets

Show answer and explanation

Correct answer: B

Explanation

The best first step in developing and managing an organizational digital forensic program is to establish governance and standardized procedures. In practice, forensic readiness depends on clearly documented processes for evidence collection and preservation, chain of custody, investigator authorization, interaction with HR/legal/privacy functions, use of external specialists, and criteria for escalating matters that may lead to litigation or regulatory reporting. This is especially important in multinational and cloud-based environments where data location, privacy law, contractual access rights, and provider responsibilities can affect what evidence can be collected and how. Best practices reflected in common forensic and incident handling guidance, such as NIST guidance on incident response and evidence handling and ISO/IEC 27037 guidance on identification, collection, acquisition, and preservation of digital evidence, emphasize process integrity, documentation, and legal defensibility before tool selection. Tool standardization, outsourcing, and retention improvements can all be valuable, but they should follow a governance model rather than replace it.

  • A. Incorrect.

    This is incorrect because tooling alone does not solve the core program weaknesses identified in the scenario: inconsistent evidence handling and poor preparation for admissibility. A forensic program must be built on governance, documented procedures, trained personnel, and legal alignment. Standardizing on one tool may improve consistency in some cases, but it does not by itself establish chain of custody, authority, jurisdictional handling, or escalation requirements. It also may be impractical in a multinational, cloud-heavy environment where different evidence sources require different collection methods.

  • B. Correct.

    This is correct because the most urgent gap is program governance. A defensible forensic capability begins with standardized policies and procedures for identification, collection, preservation, analysis, documentation, transport, storage, and presentation of evidence. Chain-of-custody controls, legal/regulatory review, jurisdiction-specific requirements, and defined roles for internal versus external investigators directly address the audit findings and support scalability across countries and cloud environments. Once governance is in place, tooling, retention, and sourcing decisions can be aligned to those standards.

  • C. Incorrect.

    This is incorrect because outsourcing can provide expertise, but it does not remove the organization's responsibility to define evidence handling standards, legal requirements, decision rights, or oversight. External specialists still need clear engagement criteria, custody transfer procedures, reporting expectations, and integration with incident response and legal teams. Without internal governance, outsourcing can simply shift inconsistency to a third party and create additional custody and accountability risks.

  • D. Incorrect.

    This is incorrect because longer log retention may improve future investigative visibility, but it does not directly remediate the primary problem of inconsistent handling and admissibility. Retention should be based on legal, regulatory, investigative, privacy, and business requirements, not only storage capacity. In addition, logs are only one source of evidence; forensic readiness requires governance for many forms of digital evidence, including endpoints, cloud artifacts, mobile devices, and third-party data.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam