SY0-701 exam dumps

SY0-701 practice question 292 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 292

Single answerData retention

A healthcare company is reviewing its security logging strategy after an incident investigation failed because firewall and authentication logs had been deleted after 30 days. The company must improve its ability to support future investigations while also controlling storage costs and limiting unnecessary retention of sensitive data. Which action BEST addresses these requirements?

  1. A

    Implement a data retention policy that classifies log types, defines required retention periods based on business and regulatory needs, and automatically archives and deletes logs according to policy

  2. B

    Configure all systems to retain every log indefinitely so investigators will always have historical data available

  3. C

    Shorten log retention to seven days and rely on real-time alerting instead of historical records for investigations

  4. D

    Allow each system administrator to choose retention periods for their own systems based on available disk space

Show answer and explanation

Correct answer: A

Explanation

The best answer is to implement a formal data retention policy with classification, defined retention schedules, and automated archival/deletion. In Security+, data retention is a governance and operational control issue: organizations should retain records long enough to meet business, legal, regulatory, and investigative needs, but not longer than necessary. For a healthcare organization, retention decisions may be influenced by compliance obligations, internal audit requirements, and the need to preserve security logs for incident response. Best practices from records management and security governance frameworks emphasize establishing documented retention schedules, applying them consistently, and enforcing them through technical controls where possible. This approach supports investigations, reduces storage costs, and aligns with the principle of minimizing unnecessary data retention.

  • A. Correct.

    Correct. A formal data retention policy is the best solution because it aligns retention with legal, regulatory, operational, and investigative requirements rather than using a one-size-fits-all approach. Classifying logs by type and value helps the organization retain critical records, such as security and audit logs, for an appropriate duration while deleting data that no longer has business or compliance value. Automating archival and deletion supports consistency, reduces human error, and helps control storage costs.

  • B. Incorrect.

    Incorrect. Retaining all logs indefinitely may seem helpful for investigations, but it increases storage costs, expands legal discovery scope, and keeps sensitive data longer than necessary. Good security governance balances availability for investigations with data minimization and retention limits. Indefinite retention is generally not the best practice unless a specific legal or regulatory requirement exists.

  • C. Incorrect.

    Incorrect. Real-time alerting is important, but it does not replace historical records needed for incident response, forensic analysis, trend analysis, and compliance audits. Reducing retention to seven days would likely make future investigations even more difficult and would not address the company’s requirement to improve investigation support.

  • D. Incorrect.

    Incorrect. Letting individual administrators decide retention periods creates inconsistent practices, gaps in compliance, and a higher chance that important logs will be deleted too soon. Data retention should be centrally governed by policy and based on organizational, legal, and regulatory requirements rather than ad hoc local decisions.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam