712-50 exam dumps

712-50 practice question 385 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 385

Single answerIdentify the best practices to acquire, store and process digital evidence

A global company suspects that a senior engineer exfiltrated proprietary source code before resigning. The CISO wants to preserve the option of civil litigation and possible criminal referral while minimizing disruption to business operations. The engineer's laptop is powered on and connected to the corporate network, and the SOC has already isolated the device from the network. Which action should the incident response team take FIRST to align with digital evidence best practices?

  1. A

    Have HR collect the laptop, power it off immediately, and store it in a locked cabinet until legal counsel decides whether to investigate

  2. B

    Create a forensically sound acquisition using trained personnel, document chain of custody from the moment of seizure, and capture volatile data before shutting the system down if justified by the case

  3. C

    Ask the engineer's manager to review recent files on the laptop to identify likely evidence, then copy relevant folders to a shared drive for analysis

  4. D

    Allow IT operations to reimage the laptop after exporting Windows event logs and browser history so the employee's replacement can use the device

Show answer and explanation

Correct answer: B

Explanation

The best answer is to perform a forensically sound acquisition with proper chain of custody and, where appropriate, capture volatile data before shutdown. In digital forensics, evidence should be acquired, stored, and processed in a manner that preserves integrity, authenticity, and admissibility. Key best practices include using trained personnel, minimizing handling, documenting every transfer and action, using validated forensic tools and repeatable procedures, calculating and verifying cryptographic hashes for acquired images, and storing original evidence securely with controlled access while conducting analysis on verified copies. For live systems, volatile data collection may be necessary because memory-resident artifacts can be lost on shutdown. This must be balanced against the risk of changing system state, which is why established incident response and forensic procedures are essential. These practices are consistent with widely recognized guidance such as NIST SP 800-86, Guide to Integrating Forensic Techniques into Incident Response, and principles reflected in ISO/IEC 27037 on identification, collection, acquisition, and preservation of digital evidence.

  • A. Incorrect.

    Incorrect. While securing the device in a locked cabinet helps protect physical access, immediately powering off the laptop without a forensic plan can destroy volatile evidence such as RAM contents, running processes, network connections, encryption keys, and unsaved artifacts. Having HR collect the device is also problematic because evidence handling should be performed by trained personnel under established procedures. Waiting to decide whether to investigate after altering the evidence state weakens admissibility and undermines preservation.

  • B. Correct.

    Correct. Best practice is to use trained responders to perform a forensically sound acquisition, preserve integrity, and maintain a documented chain of custody from seizure through analysis and storage. Because the system is still powered on, volatile data may be highly valuable in an exfiltration case, especially if encryption, remote access tools, cloud sync utilities, or transient sessions are involved. Capturing volatile data first, when justified and within approved procedures, followed by controlled shutdown and imaging, best preserves evidentiary value while supporting legal defensibility.

  • C. Incorrect.

    Incorrect. Letting a manager inspect files and selectively copy folders is not a forensically sound process and risks altering metadata such as access times, missing deleted artifacts, and creating questions about evidence completeness and integrity. This option reflects the common misconception that collecting only obviously relevant files is sufficient. In legal or disciplinary matters, investigators should preserve the full evidence source in a defensible manner before reviewing content.

  • D. Incorrect.

    Incorrect. Reimaging the laptop destroys potentially critical evidence, including deleted files, registry artifacts, application traces, and other forensic data not captured in exported logs. Exporting only event logs and browser history is incomplete and may omit the very indicators needed to prove exfiltration or user intent. Business continuity matters, but it should be addressed by providing alternate equipment rather than altering the original evidence source before proper acquisition.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam