SY0-701 Question 394
Single answerDigital forensics: Legal hold , Chain of custody , Acquisition , Reporting , Preservation , E-discoveryA company discovers that an employee may have exfiltrated sensitive design documents before resigning. Legal counsel anticipates litigation and instructs the security team to preserve relevant evidence from the employee's laptop, email, and cloud storage. The employee's laptop is still powered on at the employee's desk. Which action should the security team take FIRST to best support admissibility of evidence and compliance with e-discovery requirements?
- A
Immediately search the laptop for suspicious files and copy any relevant documents to a USB drive for review
- B
Issue a legal hold, document the chain of custody, and perform a forensically sound acquisition of the identified data sources
- C
Power off the laptop to prevent further tampering, then ask HR to collect the device for storage
- D
Delete the employee's cloud data access tokens and begin restoring any missing files from backup
Show answer and explanation
Correct answer: B
Explanation
The best answer is to issue a legal hold, preserve relevant electronically stored information, maintain chain-of-custody records, and conduct a forensically sound acquisition. In digital forensics and e-discovery, once litigation is reasonably anticipated, organizations should suspend normal data destruction practices for relevant information. A legal hold helps ensure that email, endpoint data, logs, and cloud content are preserved. Chain of custody documents who collected, transferred, stored, and analyzed the evidence, helping demonstrate integrity and admissibility. Forensic acquisition should be performed in a way that preserves metadata and supports later validation, commonly through hashing and detailed documentation. Searching systems informally, selectively copying files, or performing remediation before preservation are common mistakes because they can alter evidence and weaken legal defensibility. These practices align with common forensic best practices and legal preservation principles used in incident response, internal investigations, and civil litigation support.
- A. Incorrect.
This is incorrect because directly searching the laptop and selectively copying files to a USB drive alters the normal forensic process and can undermine evidence integrity. It also risks changing metadata such as access times and fails to preserve the full context of the evidence. In a legal matter, the team should avoid ad hoc collection and instead follow documented forensic acquisition procedures.
- B. Correct.
This is correct because when litigation is reasonably anticipated, a legal hold should be issued to prevent deletion or modification of potentially relevant data. At the same time, the organization should document chain of custody for devices and evidence handling, then perform a forensically sound acquisition of the relevant systems and accounts. This approach supports preservation, defensibility, and later e-discovery review and reporting.
- C. Incorrect.
This is incorrect because simply powering off the laptop may destroy volatile evidence such as running processes, network connections, encryption state, or data in memory. Although securing the device is important, the best first response in a legal and forensic context is coordinated preservation under legal hold with proper documentation and acquisition planning. HR custody alone does not satisfy forensic chain-of-custody requirements.
- D. Incorrect.
This is incorrect because revoking access and restoring files may be appropriate for containment or recovery, but those actions do not come first when the priority is preserving evidence for litigation. Premature remediation can alter, overwrite, or destroy relevant evidence in the laptop, email, or cloud environment. E-discovery obligations require preservation of relevant electronically stored information before routine changes or cleanup occur.