712-50 exam dumps

712-50 practice question 382 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 382

Single answerDesign investigation processes such as evidence collection, imaging, data acquisition, and analysis

A global manufacturing company suspects that a senior engineer exfiltrated proprietary CAD files from a company-issued laptop before resigning. The legal department has indicated that civil litigation is likely, and the CEO wants the investigation to preserve evidence for potential court use while minimizing disruption to operations. The SOC has already isolated the laptop from the network, and the employee is no longer on site. As the CISO designing the investigation process, which action should be performed FIRST to best preserve evidentiary integrity and support later forensic analysis?

  1. A

    Have IT log in to the laptop using an administrator account and search for the CAD files, then copy suspicious folders to a shared drive for review

  2. B

    Create a documented forensic image of the laptop's storage using validated tools, verify it with cryptographic hashes, and maintain chain-of-custody records before conducting analysis

  3. C

    Power on the laptop, connect it to a forensic workstation, and run antivirus and EDR scans to identify malicious tools that may have been used for exfiltration

  4. D

    Ask HR to interview the engineer's manager and teammates immediately so the investigation can determine whether imaging the device is necessary

Show answer and explanation

Correct answer: B

Explanation

When designing an investigation process for potential legal action, the CISO should prioritize preservation, integrity, and repeatability. Best practice is to acquire forensic evidence as early as possible using a documented, validated process: secure the device, document its condition, create a forensic image, calculate and record cryptographic hashes, preserve the original media, and perform analysis on the acquired image. Chain-of-custody records should identify who collected, transferred, stored, and analyzed the evidence. This approach is consistent with widely accepted forensic principles reflected in guidance such as NIST SP 800-86 (Guide to Integrating Forensic Techniques into Incident Response) and NIST SP 800-101 for digital evidence handling, as well as general evidentiary handling practices used in legal and HR-sensitive investigations. The key leadership decision is to distinguish between incident response actions aimed at recovery and forensic actions aimed at preserving evidence for disciplinary, civil, or criminal proceedings.

  • A. Incorrect.

    This is incorrect because logging in and browsing the system changes file access times, user artifacts, logs, and other metadata. Copying selected folders is not a forensically sound substitute for full acquisition and may omit deleted files, slack space, unallocated space, browser artifacts, USB history, and other evidence relevant to exfiltration. A common misconception is that quickly collecting obvious files is sufficient, but in litigation-oriented investigations, preserving the original evidence and its integrity is essential.

  • B. Correct.

    This is correct because the first priority is to preserve the evidence in a defensible manner. A forensic image captures the storage media bit-for-bit, enabling later examination without altering the original device. Hash verification demonstrates integrity of the acquired image, and chain-of-custody documentation supports admissibility and credibility in legal proceedings. Using validated forensic tools and analyzing the image rather than the original system aligns with standard digital forensics practice and minimizes claims that evidence was contaminated.

  • C. Incorrect.

    This is incorrect because powering on and scanning the system risks altering evidence, including logs, timestamps, temporary files, and malware behavior. Although malware or insider tools might be relevant, scanning should not precede preservation of the device state when litigation is anticipated. This option reflects the operational-security mindset of remediation before preservation, which is inappropriate when evidentiary integrity is the primary objective.

  • D. Incorrect.

    This is incorrect because witness interviews may be useful, but they should not delay evidence preservation on the device. Human recollections can help scope the inquiry, yet they do not preserve volatile or persistent digital evidence. In this scenario, the laptop is already isolated and under organizational control, so acquisition should occur promptly before any unnecessary handling or environmental changes affect the data.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam