nerdexam
CompTIA

CAS-002 · Question #224

An administrator receives a notification from legal that an investigation is being performed on members of the finance department. As a precaution, legal has advised a legal hold on all documents…

The correct answer is A. Data Storage Policy B. Data Retention Policy. A legal hold requires indefinite preservation of data, which directly conflicts with normal data storage limits and scheduled data retention deletion policies.

Integration of Computing, Communications and Business Disciplines

Question

An administrator receives a notification from legal that an investigation is being performed on members of the finance department. As a precaution, legal has advised a legal hold on all documents for an unspecified period of time. Which of the following policies will MOST likely be violated? (Select TWO).

Options

  • AData Storage Policy
  • BData Retention Policy
  • CCorporate Confidentiality Policy
  • DData Breach Mitigation Policy
  • ECorporate Privacy Policy

How the community answered

(53 responses)
  • A
    87% (46)
  • C
    8% (4)
  • D
    4% (2)
  • E
    2% (1)

Why each option

A legal hold requires indefinite preservation of data, which directly conflicts with normal data storage limits and scheduled data retention deletion policies.

AData Storage PolicyCorrect

A legal hold forces the organization to retain data beyond its normal lifecycle, potentially violating Data Storage Policy by exceeding defined storage quotas, retention tiers, or deletion schedules that govern how much data may be kept.

BData Retention PolicyCorrect

Data Retention Policy defines how long specific data categories are kept before deletion or archival - a legal hold of unspecified duration directly overrides this schedule, placing the organization in violation of its own policy.

CCorporate Confidentiality Policy

Corporate Confidentiality Policy governs who may access sensitive data and how it is protected, not how long it must be preserved - a legal hold does not inherently expose confidential data.

DData Breach Mitigation Policy

Data Breach Mitigation Policy addresses incident response when data is compromised by unauthorized access, which is unrelated to a preservation requirement issued by legal counsel.

ECorporate Privacy Policy

Corporate Privacy Policy governs the collection, use, and sharing of personal information with external parties, not the internal duration of data retention mandated by a legal hold.

Concept tested: Legal hold conflict with data retention and storage policies

Source: https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final

Topics

#legal hold#data retention policy#data storage policy#e-discovery

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice