SY0-701 exam dumps

SY0-701 practice question 216 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 216

Single answerData types: Regulated , Trade secret , Intellectual property , Legal information , Financial information , Human and non-human-readable

A software company is preparing a litigation hold and data protection plan after discovering that an engineer copied sensitive files to a personal cloud account. The security team must classify the affected data so the legal, compliance, and incident response teams can apply the correct handling requirements. During the review, they identify the following files: customer payment card transaction logs, source code for an unreleased product, a signed merger agreement draft from outside counsel, and a binary application log generated by a manufacturing robot. Which file should be classified primarily as LEGAL information?

  1. A

    Customer payment card transaction logs

  2. B

    Source code for an unreleased product

  3. C

    Signed merger agreement draft from outside counsel

  4. D

    Binary application log generated by a manufacturing robot

Show answer and explanation

Correct answer: C

Explanation

This question tests the ability to distinguish among Security+ data types in a realistic incident-response and governance scenario. Legal information includes contracts, court documents, legal correspondence, evidence related to disputes, and materials subject to attorney-client privilege or litigation hold. By contrast, payment card transaction logs are financial information and may also fall under regulated data handling requirements such as PCI DSS. Unreleased source code is intellectual property and can also qualify as a trade secret when secrecy provides business value. Robot-generated binary logs are an example of non-human-readable data, which affects storage, monitoring, and forensic tooling but does not make them legal information by default. Security professionals should classify data according to its primary business and compliance context so the organization can apply appropriate controls such as least privilege, encryption, retention, DLP policies, and legal hold procedures. Relevant guidance commonly referenced in practice includes PCI DSS for payment card data, NIST data governance and incident handling guidance, and organizational records-retention and eDiscovery policies maintained by legal and compliance teams.

  • A. Incorrect.

    Incorrect. Customer payment card transaction logs are primarily financial information and may also be regulated because payment card data is subject to PCI DSS requirements. While such records can become relevant in legal matters, their primary classification is not legal information.

  • B. Incorrect.

    Incorrect. Source code for an unreleased product is primarily intellectual property and may also be considered a trade secret if the company derives economic value from keeping it confidential. It is sensitive and valuable, but it is not primarily legal information.

  • C. Correct.

    Correct. A signed merger agreement draft from outside counsel is legal information because it relates directly to legal proceedings, contracts, attorney-client communications, and corporate legal matters. This type of information often requires strict access control, retention handling, and coordination with legal counsel, especially during litigation hold or eDiscovery activities.

  • D. Incorrect.

    Incorrect. A binary application log generated by a manufacturing robot is best identified as non-human-readable data. It may still be important for operations or forensics, but its primary classification is based on format and system use rather than being legal information.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam