SY0-701 exam dumps

SY0-701 practice question 293 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 293

Single answerData retention

A healthcare company is reviewing its log management process after an incident response exercise revealed that investigators could only access 14 days of firewall and authentication logs. The company must support future forensic investigations, meet regulatory obligations to retain certain records for longer periods, and avoid excessive storage costs. Which action should the security administrator take FIRST to address this issue?

  1. A

    Create and implement a formal data retention policy that defines log types, required retention periods, legal and business requirements, and secure disposal procedures

  2. B

    Configure all systems to keep logs indefinitely so investigators always have historical data available

  3. C

    Increase SIEM alert thresholds so fewer events are stored and the existing 14-day retention window is preserved

  4. D

    Delete low-priority logs weekly and rely on endpoint antivirus telemetry for future investigations

Show answer and explanation

Correct answer: A

Explanation

Data retention is a governance and compliance issue before it is a storage issue. In this scenario, the organization needs logs for incident investigations and must also satisfy regulatory and operational requirements. The most appropriate first action is to define a formal retention policy that classifies data, assigns retention periods, and specifies secure handling and disposal. After that, the organization can implement technical measures such as hot/warm/cold log storage, archival systems, or SIEM capacity planning.

This aligns with common security and records-management best practices: retain data based on legal, regulatory, contractual, and business needs; ensure logs are available for investigations; and dispose of records securely when retention periods expire. Security frameworks and guidance such as NIST SP 800-61 (Computer Security Incident Handling Guide), NIST SP 800-92 (Guide to Computer Security Log Management), and general records-retention practices support establishing requirements and procedures before selecting tooling or adjusting logging volume.

  • A. Correct.

    Correct. The first step is to establish a formal data retention policy that aligns security logging needs with legal, regulatory, and business requirements. In a healthcare environment, retention requirements may be influenced by HIPAA-related documentation practices, internal audit needs, and incident response objectives. A policy should define what data must be retained, for how long, where it is stored, who can access it, and how it is securely disposed of when no longer needed. Once the policy exists, technical controls such as SIEM storage expansion, log tiering, archiving, or immutable storage can be implemented appropriately.

  • B. Incorrect.

    Incorrect. Retaining all logs indefinitely is usually not the best answer because it increases storage cost, operational complexity, privacy risk, and legal exposure. Good retention practice is based on defined requirements, not unlimited accumulation. Many candidates choose this because more data seems safer for forensics, but Security+ expects balancing availability, compliance, and cost through policy-driven retention rather than endless storage.

  • C. Incorrect.

    Incorrect. Raising SIEM alert thresholds affects detection logic, not retention requirements. It may reduce the number of stored events if logging is filtered, but this can also remove useful evidence and reduce visibility during incidents. The problem described is inadequate retention planning, not excessive alerting. This option reflects the misconception that reducing alerts is the same as managing records retention.

  • D. Incorrect.

    Incorrect. Weekly deletion of logs without a documented retention requirement can violate compliance needs and significantly hinder investigations. Antivirus telemetry is not a substitute for centralized firewall and authentication logs, which are essential for tracing access, lateral movement, and timelines. This option is plausible because organizations often try to save space, but it fails to meet forensic and regulatory goals.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam