CompTIA Security+ (SY0-701)Security OperationsMedium
An organization anticipates litigation related to a data breach and must ensure that relevant emails and logs are not deleted or altered, even by automated retention policies. Which action should be taken?
- AApply a legal hold on the affected data
- BRun a full vulnerability scan
- CInitiate a SOAR playbook for containment
- DEnable data loss prevention rules
Show answer & explanationAnswer & explanation
Correct answer: A. Apply a legal hold on the affected data
A legal hold suspends normal data destruction and retention policies to preserve potentially relevant evidence for anticipated or ongoing litigation.
Why the other options are wrong
- B. A vulnerability scan identifies weaknesses and does not preserve data.
- C. A SOAR playbook automates incident response actions, not evidence preservation for litigation.
- D. DLP rules prevent data exfiltration, not automated deletion under retention policy.
Legal Hold
A directive that suspends normal data deletion and retention schedules to preserve information relevant to anticipated or ongoing legal proceedings.
- Overrides automated retention/deletion policies
- Failure to comply can result in spoliation sanctions
- Typically issued by legal counsel
Memory trick: Hold the data hostage until the case is closed.