CAS-001 · Question #428
A court order has ruled that your company must surrender all the email sent and received by a certain employee for the past five years. After reviewing the backup systems, the IT administrator…
The correct answer is C. Data retention policies. Data retention policies define how long specific categories of data must be preserved; without an adequate policy, organizations cannot comply with legal holds or court orders requiring historical records.
Question
A court order has ruled that your company must surrender all the email sent and received by a certain employee for the past five years. After reviewing the backup systems, the IT administrator concludes that email backups are not kept that long. Which of the following policies MUST be reviewed to address future compliance?
Options
- ATape backup policies
- BOffsite backup policies
- CData retention policies
- DData loss prevention policies
How the community answered
(30 responses)- A3% (1)
- B3% (1)
- C87% (26)
- D7% (2)
Why each option
Data retention policies define how long specific categories of data must be preserved; without an adequate policy, organizations cannot comply with legal holds or court orders requiring historical records.
Tape backup policies govern the mechanics of how backups are performed and rotated, but the root problem is that no requirement existed to retain the email data long enough - a storage medium policy does not establish retention duration requirements.
Offsite backup policies address where backup media is stored for disaster recovery purposes but do not define how long any category of data must legally be preserved.
A data retention policy specifies the minimum and maximum periods for which different data types - including email - must be stored and in what format. If the organization has no policy requiring email to be kept for five years, it has no compliance mechanism to produce those records when legally required. Reviewing and updating the data retention policy to align with legal and regulatory requirements directly addresses this gap.
Data Loss Prevention policies focus on preventing unauthorized disclosure or exfiltration of sensitive data in transit or at rest; they do not govern archival duration or legal hold requirements.
Concept tested: Data retention policy for legal hold compliance
Source: https://learn.microsoft.com/en-us/compliance/regulatory/retention-policies-and-hold-types
Topics
Community Discussion
No community discussion yet for this question.