nerdexam
EC-Council

312-49V11 · Question #139

Following a cybersecurity incident at an organization, a forensic investigator is tasked with collecting Electronically Stored Information (ESI) as part of the investigation. To streamline the data…

The correct answer is D. Investigator employs a directed collection of definite data sets and system areas. As defined in the CHFI v11 Procedures and Methodology domain, directed collection is an eDiscovery methodology in which investigators deliberately limit evidence collection to specific data sets, file types, directories, custodians, or system areas that are known or highly…

Computer Forensics Investigation Process

Question

Following a cybersecurity incident at an organization, a forensic investigator is tasked with collecting Electronically Stored Information (ESI) as part of the investigation. To streamline the data collection process, the investigator restricts the range and size of ESI from custodians, limiting the collection to specific file types and directories on a computer. This approach ensures that only relevant information is collected while minimizing the impact on other devices. Which eDiscovery collection methodology is being used in this scenario?

Options

  • AInvestigator leverages custodian self-collection to gather sensitive evidence data.
  • BInvestigator uses incremental collection, focusing on newly created or modified data.
  • CInvestigator uses remote acquisition of data from custodians' systems via network connections.
  • DInvestigator employs a directed collection of definite data sets and system areas.

How the community answered

(42 responses)
  • A
    17% (7)
  • B
    7% (3)
  • C
    2% (1)
  • D
    74% (31)

Explanation

As defined in the CHFI v11 Procedures and Methodology domain, directed collection is an eDiscovery methodology in which investigators deliberately limit evidence collection to specific data sets, file types, directories, custodians, or system areas that are known or highly likely to contain relevant information. This approach is commonly used to reduce data volume, minimize business disruption, and lower legal and operational costs while maintaining forensic relevance. In the given scenario, the investigator intentionally restricts the scope of ESI by targeting specific directories and file types, rather than collecting full disk images or all user data. CHFI v11 explicitly describes this as directed (or targeted) collection, which is aligned with the Electronic Discovery Reference Model (EDRM) best practices. Directed collection helps investigators remain compliant with legal proportionality requirements and reduces exposure to irrelevant or private third-party data.

Topics

#eDiscovery#ESI collection#directed collection#forensic methodology

Community Discussion

No community discussion yet for this question.

Full 312-49V11 Practice