CompTIA Security+ (SY0-701)Security OperationsMedium

An organization anticipates litigation related to a data breach and must ensure that relevant emails and logs are not deleted or altered, even by automated retention policies. Which action should be taken?

  1. AApply a legal hold on the affected data
  2. BRun a full vulnerability scan
  3. CInitiate a SOAR playbook for containment
  4. DEnable data loss prevention rules
Show answer & explanation

Correct answer: A. Apply a legal hold on the affected data

A legal hold suspends normal data destruction and retention policies to preserve potentially relevant evidence for anticipated or ongoing litigation.

Why the other options are wrong

  • B. A vulnerability scan identifies weaknesses and does not preserve data.
  • C. A SOAR playbook automates incident response actions, not evidence preservation for litigation.
  • D. DLP rules prevent data exfiltration, not automated deletion under retention policy.

Legal Hold

A directive that suspends normal data deletion and retention schedules to preserve information relevant to anticipated or ongoing legal proceedings.

  • Overrides automated retention/deletion policies
  • Failure to comply can result in spoliation sanctions
  • Typically issued by legal counsel

Memory trick: Hold the data hostage until the case is closed.

More Security Operations questions