nerdexam
CompTIA

CAS-001 · Question #428

A court order has ruled that your company must surrender all the email sent and received by a certain employee for the past five years. After reviewing the backup systems, the IT administrator…

The correct answer is C. Data retention policies. Data retention policies define how long specific categories of data must be preserved; without an adequate policy, organizations cannot comply with legal holds or court orders requiring historical records.

Integration of Computing, Communications and Business Disciplines

Question

A court order has ruled that your company must surrender all the email sent and received by a certain employee for the past five years. After reviewing the backup systems, the IT administrator concludes that email backups are not kept that long. Which of the following policies MUST be reviewed to address future compliance?

Options

  • ATape backup policies
  • BOffsite backup policies
  • CData retention policies
  • DData loss prevention policies

How the community answered

(30 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    87% (26)
  • D
    7% (2)

Why each option

Data retention policies define how long specific categories of data must be preserved; without an adequate policy, organizations cannot comply with legal holds or court orders requiring historical records.

ATape backup policies

Tape backup policies govern the mechanics of how backups are performed and rotated, but the root problem is that no requirement existed to retain the email data long enough - a storage medium policy does not establish retention duration requirements.

BOffsite backup policies

Offsite backup policies address where backup media is stored for disaster recovery purposes but do not define how long any category of data must legally be preserved.

CData retention policiesCorrect

A data retention policy specifies the minimum and maximum periods for which different data types - including email - must be stored and in what format. If the organization has no policy requiring email to be kept for five years, it has no compliance mechanism to produce those records when legally required. Reviewing and updating the data retention policy to align with legal and regulatory requirements directly addresses this gap.

DData loss prevention policies

Data Loss Prevention policies focus on preventing unauthorized disclosure or exfiltration of sensitive data in transit or at rest; they do not govern archival duration or legal hold requirements.

Concept tested: Data retention policy for legal hold compliance

Source: https://learn.microsoft.com/en-us/compliance/regulatory/retention-policies-and-hold-types

Topics

#data retention#eDiscovery#legal compliance#backup policy

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice