nerdexam
CompTIA

CAS-002 · Question #122

The security administrator at a company has received a subpoena for the release of all the email received and sent by the company Chief Information Officer (CIO) for the past three years. The…

The correct answer is B. The company backup logs and archives. Before assuming non-compliance with a subpoena, the administrator should check backup logs and archives because the missing years of email may still exist outside the live mail server.

Integration of Computing, Communications and Business Disciplines

Question

The security administrator at a company has received a subpoena for the release of all the email received and sent by the company Chief Information Officer (CIO) for the past three years. The security administrator is only able to find one year's worth of email records on the server and is now concerned about the possible legal implications of not complying with the request. Which of the following should the security administrator check BEFORE responding to the request?

Options

  • AThe company data privacy policies
  • BThe company backup logs and archives
  • CThe company data retention policies and guidelines
  • DThe company data retention procedures

How the community answered

(28 responses)
  • A
    18% (5)
  • B
    71% (20)
  • C
    7% (2)
  • D
    4% (1)

Why each option

Before assuming non-compliance with a subpoena, the administrator should check backup logs and archives because the missing years of email may still exist outside the live mail server.

AThe company data privacy policies

Data privacy policies govern how information is handled and protected, but they do not reveal the physical or logical location of historical email backup copies.

BThe company backup logs and archivesCorrect

Email systems routinely back up and archive messages on a schedule that retains data well beyond the active server's retention window - the two missing years of email could exist in tape backups, email archiving appliances, or offline storage, and confirming their existence before responding to a legal request prevents a false declaration of non-compliance.

CThe company data retention policies and guidelines

Data retention policies define how long data should be kept, but consulting the policy does not confirm whether the archived email copies actually exist in a backup system.

DThe company data retention procedures

Data retention procedures describe the process for storing data, but like the policy itself, they cannot confirm whether specific backup copies of the missing emails are present.

Concept tested: Email backup and archive verification for legal hold compliance

Source: https://csrc.nist.gov/publications/detail/sp/800-34/rev-1/final

Topics

#data retention#legal compliance#email records#backup archives

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice