nerdexam
CompTIA

CAS-002 · Question #178

A data breach has occurred at Company A and as a result, the Chief Information Officer (CIO) has resigned. The CIO's laptop, cell phone and PC were all wiped of data per company policy. A month…

The correct answer is D. Restore the CIO's email from an email server backup and provide whatever is available up. When a legal subpoena is issued, the organization is obligated to comply and must provide whatever email data can be restored from backups, regardless of the corporate retention policy recommendation.

Research and Analysis

Question

A data breach has occurred at Company A and as a result, the Chief Information Officer (CIO) has resigned. The CIO's laptop, cell phone and PC were all wiped of data per company policy. A month later, prosecutors in litigation with Company A suspect the CIO knew about the data breach long before it was discovered and have issued a subpoena requesting all the CIO's email from the last 12 months. The corporate retention policy recommends keeping data for no longer than 90 days. Which of the following should occur?

Options

  • ARestore the CIO's email from an email server backup and provide the last 90 days from the
  • BInform the litigators that the CIOs information has been deleted as per corporate policy.
  • CRestore the CIO's email from an email server backup and provide the last 90 days from the
  • DRestore the CIO's email from an email server backup and provide whatever is available up

How the community answered

(30 responses)
  • A
    7% (2)
  • B
    23% (7)
  • C
    10% (3)
  • D
    60% (18)

Why each option

When a legal subpoena is issued, the organization is obligated to comply and must provide whatever email data can be restored from backups, regardless of the corporate retention policy recommendation.

ARestore the CIO's email from an email server backup and provide the last 90 days from the

Providing only the last 90 days in alignment with the retention recommendation does not satisfy a legal subpoena requesting 12 months of records when more data may be recoverable from backups.

BInform the litigators that the CIOs information has been deleted as per corporate policy.

Informing litigators that data was deleted per policy ignores the legal obligation imposed by the subpoena and potentially constitutes spoliation if data is still recoverable from backup systems.

CRestore the CIO's email from an email server backup and provide the last 90 days from the

Like choice A, providing only 90 days when more data may be restorable from backups does not fulfill the full scope of the legal subpoena and could result in legal sanctions against the organization.

DRestore the CIO's email from an email server backup and provide whatever is available upCorrect

A legal subpoena is a court order that supersedes internal corporate data retention policy recommendations, obligating the organization to produce all available evidence within the scope of the request. The organization must restore email data from any available backups and provide whatever records exist for the requested 12-month period, even if the retention policy only recommends 90 days of retention. Providing only 90 days or failing to disclose recoverable data after receiving a subpoena could constitute spoliation of evidence and expose the company to additional legal liability.

Concept tested: Legal hold and e-discovery obligations overriding retention policy

Source: https://www.justice.gov/archives/jm/civil-resource-manual-26-electronic-discovery

Topics

#legal hold#data retention#e-discovery#litigation response

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice