712-50 exam dumps

712-50 practice question 387 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 387

Single answerConfigure and use various forensic investigation tools

A global manufacturing company suspects that an engineer used a company-issued Windows laptop to stage sensitive design files before leaving the organization. The board expects legal action may follow, so the CISO has directed the incident response team to collect evidence in a way that preserves admissibility while allowing analysts to reconstruct user activity. The laptop is powered off and has been secured. Which action should the CISO MOST strongly require as the next step in the forensic process?

  1. A

    Create a bit-for-bit forensic image of the laptop drive using a hardware write blocker, calculate and record cryptographic hashes of the source and image, and conduct analysis on the image copy

  2. B

    Boot the laptop normally and use built-in Windows tools to review recent files, browser history, and USB activity before deciding whether a full image is necessary

  3. C

    Copy the user's profile folders and recent document locations to an external drive, because targeted collection is faster and reduces storage costs

  4. D

    Run an antivirus and endpoint detection scan directly on the original laptop to identify exfiltration tools before collecting any forensic evidence

Show answer and explanation

Correct answer: A

Explanation

The best answer is to create a forensic image using write-blocking controls, document chain of custody, and verify integrity with cryptographic hashes before any analysis. This is the most defensible approach when evidence may be used in court or HR proceedings. A bit-for-bit image captures not only active files but also deleted content, file-system metadata, and other low-level artifacts needed to reconstruct user actions. Best practices from NIST guidance on integrating forensic techniques into incident response and general digital evidence handling emphasize minimizing changes to original evidence, maintaining a documented chain of custody, using validated tools, and verifying acquired images with hashes. Industry-standard forensic suites such as EnCase, FTK, X-Ways Forensics, and open-source workflows using tools like dc3dd/Guymager with proper write blocking support this process. The key leadership decision for a CCISO is not merely selecting a tool, but enforcing a process that preserves evidentiary integrity, supports repeatable analysis, and withstands legal scrutiny.

  • A. Correct.

    Correct. For a powered-off system where legal action is anticipated, the defensible approach is to preserve the original media by acquiring a forensic bit-stream image through a write blocker and validating integrity with hashes such as SHA-256. Analysis should be performed on the forensic copy, not the original. This aligns with standard digital forensics practice for preserving chain of custody, repeatability, and evidentiary integrity.

  • B. Incorrect.

    Incorrect. Booting the system normally changes files, timestamps, logs, registry artifacts, and other metadata. Even if the intent is only triage, doing so on the original device can undermine evidentiary value and make later testimony more difficult. A candidate might choose this because built-in tools are convenient, but convenience is outweighed by evidence preservation requirements in a likely legal matter.

  • C. Incorrect.

    Incorrect. Targeted collection may be useful in some internal investigations, but it is not the best next step when the objective is admissible evidence and reconstruction of potentially concealed activity. Copying only profile folders risks missing deleted files, slack space, unallocated space, alternate data streams, link files, registry hives, browser databases, and other artifacts outside obvious user directories.

  • D. Incorrect.

    Incorrect. Scanning the original laptop with antivirus or EDR tools alters the system and may quarantine, delete, or modify artifacts that investigators need to examine. This is a common operational mistake when security teams prioritize rapid threat hunting over forensic soundness. Such tools may be appropriate later on copies or in parallel enterprise detection workflows, but not as the first action on original evidence intended for legal proceedings.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam