SY0-701 exam dumps

SY0-701 practice question 394 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 394

Single answerDigital forensics: Legal hold , Chain of custody , Acquisition , Reporting , Preservation , E-discovery

A company discovers that an employee may have exfiltrated sensitive design documents before resigning. Legal counsel anticipates litigation and instructs the security team to preserve relevant evidence from the employee's laptop, email, and cloud storage. The employee's laptop is still powered on at the employee's desk. Which action should the security team take FIRST to best support admissibility of evidence and compliance with e-discovery requirements?

  1. A

    Immediately search the laptop for suspicious files and copy any relevant documents to a USB drive for review

  2. B

    Issue a legal hold, document the chain of custody, and perform a forensically sound acquisition of the identified data sources

  3. C

    Power off the laptop to prevent further tampering, then ask HR to collect the device for storage

  4. D

    Delete the employee's cloud data access tokens and begin restoring any missing files from backup

Show answer and explanation

Correct answer: B

Explanation

The best answer is to issue a legal hold, preserve relevant electronically stored information, maintain chain-of-custody records, and conduct a forensically sound acquisition. In digital forensics and e-discovery, once litigation is reasonably anticipated, organizations should suspend normal data destruction practices for relevant information. A legal hold helps ensure that email, endpoint data, logs, and cloud content are preserved. Chain of custody documents who collected, transferred, stored, and analyzed the evidence, helping demonstrate integrity and admissibility. Forensic acquisition should be performed in a way that preserves metadata and supports later validation, commonly through hashing and detailed documentation. Searching systems informally, selectively copying files, or performing remediation before preservation are common mistakes because they can alter evidence and weaken legal defensibility. These practices align with common forensic best practices and legal preservation principles used in incident response, internal investigations, and civil litigation support.

  • A. Incorrect.

    This is incorrect because directly searching the laptop and selectively copying files to a USB drive alters the normal forensic process and can undermine evidence integrity. It also risks changing metadata such as access times and fails to preserve the full context of the evidence. In a legal matter, the team should avoid ad hoc collection and instead follow documented forensic acquisition procedures.

  • B. Correct.

    This is correct because when litigation is reasonably anticipated, a legal hold should be issued to prevent deletion or modification of potentially relevant data. At the same time, the organization should document chain of custody for devices and evidence handling, then perform a forensically sound acquisition of the relevant systems and accounts. This approach supports preservation, defensibility, and later e-discovery review and reporting.

  • C. Incorrect.

    This is incorrect because simply powering off the laptop may destroy volatile evidence such as running processes, network connections, encryption state, or data in memory. Although securing the device is important, the best first response in a legal and forensic context is coordinated preservation under legal hold with proper documentation and acquisition planning. HR custody alone does not satisfy forensic chain-of-custody requirements.

  • D. Incorrect.

    This is incorrect because revoking access and restoring files may be appropriate for containment or recovery, but those actions do not come first when the priority is preserving evidence for litigation. Premature remediation can alter, overwrite, or destroy relevant evidence in the laptop, email, or cloud environment. E-discovery obligations require preservation of relevant electronically stored information before routine changes or cleanup occur.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam