SY0-701 exam dumps

SY0-701 practice question 393 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 393

Single answerDigital forensics: Legal hold , Chain of custody , Acquisition , Reporting , Preservation , E-discovery

A company discovers that a departing employee may have exfiltrated proprietary design files before leaving. Corporate counsel anticipates litigation and instructs IT and security staff to preserve relevant evidence from the employee's laptop, email, and cloud storage. The security analyst wants to ensure the evidence is admissible and that the organization can later identify responsive data during discovery. Which action should the analyst take FIRST?

  1. A

    Place the employee's data and systems under a legal hold, document chain of custody, and create forensic acquisitions using validated tools before analysis

  2. B

    Begin reviewing the employee's email and cloud files immediately so the team can quickly identify incriminating evidence before the data changes

  3. C

    Export only the files that appear relevant to the case and provide them directly to legal to reduce storage and processing time

  4. D

    Shut down the laptop, reimage it for the next user, and rely on SIEM logs and manager statements as sufficient evidence

Show answer and explanation

Correct answer: A

Explanation

The best first step is to preserve potentially relevant electronically stored information in a legally defensible way. In practice, that means implementing a legal hold, preserving data sources, documenting chain of custody, and performing forensic acquisition before analysis. This sequence aligns with common digital forensics and e-discovery best practices: preserve first, collect defensibly, then analyze and report. Chain of custody documentation helps demonstrate who handled the evidence, when, and how, which supports admissibility and credibility. Forensic acquisition should use validated tools and methods, typically capturing hashes to verify integrity. After preservation and collection, the organization can proceed with review, reporting, and e-discovery workflows to identify responsive data. These practices are consistent with widely recognized guidance such as NIST SP 800-86 on integrating forensic techniques into incident response and general e-discovery principles concerning legal hold and preservation of electronically stored information.

  • A. Correct.

    Correct. When litigation is reasonably anticipated, the organization should issue and implement a legal hold to suspend normal deletion and preservation processes for potentially relevant data. The analyst should also maintain a documented chain of custody and perform forensic acquisition using validated methods and tools so the evidence can be preserved in a defensible manner before any review or analysis occurs. This supports preservation, acquisition, reporting, and later e-discovery activities.

  • B. Incorrect.

    Incorrect. Jumping directly into review risks altering metadata, changing access times, and undermining evidentiary integrity if preservation steps have not yet been taken. While rapid triage may sometimes be operationally necessary, the scenario specifically asks about ensuring admissibility and future discovery readiness. Preservation and documented acquisition come before substantive review.

  • C. Incorrect.

    Incorrect. Collecting only files that appear relevant too early is a common mistake because it can miss hidden, deleted, or not-yet-obvious evidence and may be challenged as selective collection. Best practice is to preserve a defensible forensic copy of relevant sources first, then perform analysis and culling for e-discovery in a controlled manner.

  • D. Incorrect.

    Incorrect. Reimaging the laptop would destroy potentially relevant evidence and could be considered spoliation once litigation is anticipated. SIEM logs and witness statements may be useful, but they do not replace preserved original evidence from the endpoint and related repositories.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam