nerdexam
EC-Council

312-49V11 · Question #77

During a digital forensics investigation, an investigator is tasked with collecting data from servers and shared drives within an organization's infrastructure. The investigator accesses and…

The correct answer is A. The investigator uses network collection to gather data directly from internal repositories and. Under the CHFI v11 objectives related to the eDiscovery process, investigators must understand and correctly apply various eDiscovery collection methodologies based on where data resides and how it is accessed. In this scenario, the investigator is collecting evidence from…

Electronic Discovery (eDiscovery)

Question

During a digital forensics investigation, an investigator is tasked with collecting data from servers and shared drives within an organization's infrastructure. The investigator accesses and retrieves relevant electronic evidence from these central storage locations to assist in the investigation. This data collection includes files, user logs, and other system artifacts necessary for understanding the scope of the incident. Which eDiscovery collection methodology is the investigator employing in this scenario?

Options

  • AThe investigator uses network collection to gather data directly from internal repositories and
  • BThe investigator uses cloud-based collection to retrieve data from cloud storage and platforms.
  • CThe investigator uses email collection to extract relevant communications and attachments from
  • DThe investigator uses mobile device collection to retrieve data from smartphones, tablets, or other

How the community answered

(31 responses)
  • A
    77% (24)
  • B
    13% (4)
  • C
    6% (2)
  • D
    3% (1)

Explanation

Under the CHFI v11 objectives related to the eDiscovery process, investigators must understand and correctly apply various eDiscovery collection methodologies based on where data resides and how it is accessed. In this scenario, the investigator is collecting evidence from internal servers and shared drives that are part of the organization's on-premises infrastructure. These repositories typically store centralized data such as user files, audit logs, access records, and application artifacts. This approach directly aligns with network collection, an eDiscovery methodology in which data is acquired remotely over the organizational network from file servers, database servers, shared storage, and internal repositories. Network collection is commonly used in enterprise investigations because it allows investigators to gather large volumes of data efficiently without physically seizing individual endpoint devices. Cloud-based collection (Option B) applies only when data is hosted on third-party cloud platforms such as AWS, Azure, or Google Cloud. Email collection (Option C) is limited to mail servers and messaging systems, while mobile device collection (Option D) focuses on smartphones and tablets. None of these accurately describe the centralized, internal infrastructure outlined in the The CHFI v11 Exam Blueprint emphasizes eDiscovery collection methodologies as part of forensic readiness and investigation workflows, highlighting network collection as the appropriate technique for acquiring evidence from organizational servers and shared drives while maintaining integrity and chain of custody

Topics

#eDiscovery#network collection#digital evidence#internal repositories

Community Discussion

No community discussion yet for this question.

Full 312-49V11 Practice