712-50 exam dumps

712-50 practice question 380 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 380

Single answerEstablish, develop and manage forensic investigation teams

A global manufacturing company is building a formal digital forensics capability after several cross-border insider data theft incidents. The CISO has been asked to establish and manage a forensic investigation team that can support internal investigations, HR actions, regulatory inquiries, and potential criminal referrals. The company has limited budget, operations in multiple jurisdictions, and a history of ad hoc evidence collection by local IT administrators. Which action should the CISO take FIRST to build a defensible and sustainable forensic investigation function?

  1. A

    Purchase advanced forensic tools for each regional IT team so evidence can be collected immediately at any site

  2. B

    Define governance for the forensic function, including investigation authority, evidence handling standards, legal/HR coordination, escalation criteria, and chain-of-custody requirements

  3. C

    Outsource all forensic investigations to a specialist firm to avoid internal bias and eliminate the need for internal procedures

  4. D

    Train system administrators in basic malware analysis so they can independently investigate incidents before notifying legal counsel

Show answer and explanation

Correct answer: B

Explanation

The strongest first step in establishing, developing, and managing a forensic investigation team is to create governance and operating procedures for the function. In practice, a defensible forensic capability requires clear authority, documented evidence handling procedures, defined roles and segregation of duties, legal and HR coordination, jurisdiction-aware processes, escalation thresholds, retention requirements, and chain-of-custody controls. These principles are consistent with widely accepted digital forensics and incident response practices, including maintaining evidence integrity and documenting handling from collection through analysis and disposition. Relevant best-practice sources include NIST guidance such as SP 800-61 on incident response and SP 800-86 on integrating forensic techniques into incident response, as well as general evidence handling principles reflected in ISO/IEC 27037. A CCISO-level leader should focus first on governance, cross-functional alignment, and defensibility before scaling tools, training, or outsourcing arrangements.

  • A. Incorrect.

    This is not the best first step. While tooling is important, buying tools before defining governance, roles, evidence handling procedures, and legal coordination often leads to inconsistent practices and inadmissible or unreliable evidence. In a distributed enterprise, regional teams using tools without standardized authority and process can worsen the existing problem of ad hoc evidence collection.

  • B. Correct.

    This is correct. A forensic capability should be established on a governance foundation first: who is authorized to initiate and lead investigations, how evidence is preserved and documented, when legal and HR must be involved, what jurisdictional constraints apply, and how chain of custody is maintained. These elements are essential for defensibility, consistency, and alignment with business, legal, and regulatory requirements. Once governance is in place, the organization can determine team structure, training, tooling, and use of external specialists.

  • C. Incorrect.

    This is plausible but incorrect as the first action. External forensic firms can be valuable for surge support, independence, or specialized expertise, but outsourcing everything does not remove the need for internal governance, escalation paths, legal review, evidence preservation requirements, and decision rights. The organization still needs a defined operating model to determine when and how third parties are engaged.

  • D. Incorrect.

    This is incorrect. System administrators may help identify operational indicators, but allowing them to independently investigate before legal or the formal forensic process is engaged can contaminate evidence, create conflicts of interest, and violate internal investigation protocols. Malware analysis training may be useful later, but it does not address the foundational need for a managed forensic function.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam