CISSP - Security Operations - Section 7.1

Understand and comply with investigations including evidence collection and handling, reporting, investigative techniques, and digital forensics.

Describe digital forensics principles including evidence collection, chain of custody, preservation of artefacts, and investigative techniques used in security incidents. Apply the correct sequence of evidence handling steps so that digital evidence remains admissible and tamper-evident throughout an investigation.

digital forensicsevidence collectionchain of custodyartifactsinvestigative techniques

Practice question for this objective

Free sampleSecurity Operationshard

During an internal investigation into suspected intellectual property theft, an examiner discovers that the suspect's mailbox is hosted in a cloud productivity suite and that retention policies will purge deleted items in seven days. The general counsel has placed the suspect on a legal hold. What is the MOST appropriate next step for the examiner?

  • AExport the suspect's mailbox to a PST file from the examiner's own administrative account and store it on the case share for later review.
  • BInstruct the suspect's manager to quietly disable the suspect's account so that no further deletions occur while the investigation proceeds.
  • CIssue a written preservation notice to the cloud provider asking them to freeze the tenant data while the legal team prepares a formal subpoena.
  • DApply an in-place hold or preservation policy through the tenant's eDiscovery tooling so that all mailbox content is retained in place pending collection. Correct
Use native cloud eDiscovery preservation to enforce a legal hold on mailbox data before any collection or export takes place. Cloud mailbox investigations require preservation before collection. Native in-place or litigation hold features keep deleted and edited items recoverable, override retention purges, and produce an audit trail that proves the hold was applied at a defensible time. Only after preservation is in force should the examiner scope and execute a collection through the same tooling, keeping metadata intact and the chain of custody documented end to end.

Why A is wrong: Ad hoc PST export from a personal admin account leaves no audit trail tying the action to the legal hold, breaks chain of custody, and risks altering message metadata such as read flags and folder paths during export.

Why B is wrong: Disabling the account does not stop tenant retention policies from purging already-deleted items, may tip off the suspect when access fails, and pulls the line manager into an investigation in a way that risks confidentiality and procedural fairness.

Why C is wrong: A unilateral preservation letter to a provider for a customer-controlled tenant is unnecessary and slow; the customer already controls the relevant retention levers and should use them rather than waiting on the provider.

Why D is correct: Using the tenant's native eDiscovery preservation invokes provider-side retention that survives user deletion and retention policy purges, is auditable, and preserves original metadata until a defensible collection can be scoped and exported.

See more CISSP practice questions, answers explained.

More in this domain

Back to all Security Operations objectives, or the CISSP cert hub.

Examworthy is not affiliated with or endorsed by (ISC)2. Original, blueprint-aligned practice material only.