712-50 exam dumps

712-50 practice question 381 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 381

Single answerEstablish, develop and manage forensic investigation teams

A global manufacturing company is creating a formal digital forensics capability after several incidents required external consultants. The CISO has been asked to establish and manage an internal forensic investigation team that can support HR, legal, and cyber incident response across multiple regions. During planning, the legal department warns that evidence from future investigations may be used in regulatory actions and civil litigation. Which action should the CISO prioritize FIRST to ensure the new forensic team can produce defensible investigative results?

  1. A

    Define investigation governance, including evidence handling standards, chain-of-custody procedures, role separation, and escalation paths aligned with legal and HR requirements

  2. B

    Purchase industry-leading forensic tools and provide advanced malware analysis training so the team can quickly examine endpoints without relying on third parties

  3. C

    Require the forensic team to report directly to IT operations so endpoint access, containment, and data collection can be performed more efficiently

  4. D

    Build a standing policy that all potential evidence should be collected in full from any employee device after a security alert to maximize investigative completeness

Show answer and explanation

Correct answer: A

Explanation

When establishing, developing, and managing forensic investigation teams, a CCISO should prioritize governance before technology acquisition or operational convenience. A defensible forensic capability requires documented procedures, trained personnel operating under those procedures, proper segregation of duties, legal oversight, and clear coordination with HR and incident response. Widely accepted forensic best practices emphasize preserving evidence integrity, maintaining a documented chain of custody, using repeatable methods, and ensuring investigations are properly authorized and scoped. Guidance from sources such as NIST SP 800-86 (Guide to Integrating Forensic Techniques into Incident Response) and general digital evidence handling principles used in legal and regulatory contexts support this approach. Once governance is established, the organization can then select tools, define team structure, train personnel, and create regional operating procedures that align with privacy and labor obligations.

  • A. Correct.

    This is correct because the defensibility of forensic results depends first on governance and process, not just technical capability. A forensic team must operate under documented procedures for evidence identification, preservation, collection, transfer, analysis, documentation, and presentation. Chain of custody, role clarity, legal review, escalation criteria, and coordination with HR are foundational to ensuring evidence is admissible, trustworthy, and collected in a way that respects employment, privacy, and jurisdictional constraints. Establishing these controls first enables tools, training, and staffing decisions to be implemented within a legally sound framework.

  • B. Incorrect.

    This is incorrect because tools and training are important, but they do not by themselves make results defensible. Without documented evidence handling procedures, analysts may unintentionally alter evidence, fail to preserve metadata, or create gaps in documentation. This option reflects a common misconception that technical sophistication alone is the primary success factor in forensics. In reality, mature governance must come first so technical operations are performed consistently and can withstand legal scrutiny.

  • C. Incorrect.

    This is incorrect because placing the forensic team under IT operations can create conflicts of interest and weaken investigative independence, especially if the investigation involves administrators, system owners, or failures in operational controls. While close operational coordination is necessary, reporting structure should preserve objectivity and support oversight by security leadership, legal, and other governance stakeholders. Efficiency in access is not the highest initial priority when the stated goal is defensible results for legal and regulatory use.

  • D. Incorrect.

    This is incorrect because broad collection from every employee device after any alert is disproportionate and can violate privacy, labor, and data minimization requirements, especially across jurisdictions. Forensic collection should be authorized, scoped, and relevant to the matter under investigation. Over-collection also increases legal exposure, costs, and review burden. This distractor targets the misconception that collecting more data automatically improves investigations; in practice, defensibility depends on relevance, necessity, and proper authorization.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam