712-50 exam dumps

712-50 practice question 384 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 384

Select 2Identify the best practices to acquire, store and process digital evidence

A global company discovers that a senior administrator may have exfiltrated sensitive design files before resigning. The CISO expects both internal disciplinary action and possible criminal referral. The incident response team has identified the suspect's laptop, a file server, and relevant cloud storage logs. Because the company must preserve evidence that will withstand legal scrutiny, the security leadership team needs to choose the most defensible approach for acquiring, storing, and processing the digital evidence. Which TWO actions are the best choices?

  1. A

    Create forensic bit-stream images of the laptop and relevant server media using validated tools, calculate cryptographic hashes before and after acquisition, and document chain of custody for each evidence item.

  2. B

    Allow system administrators to continue normal access to the laptop and server so business operations are not interrupted, then export only the files believed to be relevant once HR confirms the allegation.

  3. C

    Store the original evidence in a secured, access-controlled evidence repository, perform analysis only on verified copies, and maintain detailed logs of every transfer, access, and processing step.

  4. D

    Power on the suspect's laptop and search it manually for suspicious files so investigators can quickly confirm whether formal evidence handling is necessary.

  5. E

    Have the cloud provider send screenshots of relevant log entries by email to the legal team, since screenshots are easier to review than raw logs.

Show answer and explanation

Correct answers: A, C

Explanation

The most defensible evidence handling approach combines proper forensic acquisition with rigorous preservation and controlled analysis. For endpoints and storage media, investigators should acquire forensic images using validated tools and verify integrity with cryptographic hashes. For all evidence types, including cloud logs, they should preserve originals, maintain documented chain of custody, and analyze only verified copies. These practices align with widely recognized digital forensics and evidence-handling guidance, including principles reflected in NIST publications such as NIST SP 800-86 and NIST SP 800-101, as well as general forensic standards emphasizing integrity, repeatability, and accountability. From a CCISO perspective, the key leadership decision is ensuring that processes, tooling, access controls, and documentation are sufficient not just for investigation, but also for HR, regulatory, civil, or criminal proceedings.

  • A. Correct.

    This is correct because forensic best practice is to acquire a complete bit-stream image when possible, preserve metadata and deleted artifacts, and validate integrity with cryptographic hashes such as SHA-256. Using validated forensic tools and documenting the chain of custody strengthens admissibility and defensibility by showing that the evidence was collected in a repeatable manner and was not altered during acquisition.

  • B. Incorrect.

    This is incorrect because allowing routine administrative access increases the risk of evidence alteration, intentional or accidental spoliation, and breaks defensibility. Exporting only files thought to be relevant too early can miss deleted data, timestamps, system artifacts, and context that later become important. This option reflects the common misconception that business convenience should take priority over evidence preservation when legal action is anticipated.

  • C. Correct.

    This is correct because original evidence should be preserved in a secure evidence repository with strict access control, environmental protection as applicable, and full audit logging. Analysis should be conducted on verified working copies so the original remains unmodified. Detailed records of transfers, access, and processing support chain of custody and help demonstrate integrity throughout the evidence lifecycle.

  • D. Incorrect.

    This is incorrect because powering on and manually examining a device can modify timestamps, logs, temporary files, and other artifacts. If the laptop is already powered on when first encountered, live response decisions must be made carefully by trained personnel based on volatility and legal guidance; however, casually turning it on to look around is not a best practice. This option represents a common but improper shortcut.

  • E. Incorrect.

    This is incorrect because screenshots are typically insufficient as a primary form of digital evidence when original log data or provider-generated exports are available. Screenshots lack full context, metadata, and verifiable integrity. Best practice is to obtain logs through formal provider processes, preserve them in original or native export format where possible, and hash and document them upon receipt.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam