CAS-002 · Question #698
On Monday, the Chief Information Officer (CIO) of a state agency received an e-discovery request for the release of all emails sent and received by the agency board of directors for the past five…
The correct answer is A. Data retention policy. This question identifies which factor most directly determines whether five years of emails can be produced in response to an e-discovery request.
Question
On Monday, the Chief Information Officer (CIO) of a state agency received an e-discovery request for the release of all emails sent and received by the agency board of directors for the past five years. The CIO has contacted the email administrator and asked the administrator to provide the requested information by end of day on Friday. Which of the following has the GREATEST impact on the ability to fulfill the e-discovery request?
Options
- AData retention policy
- BBackup software and hardware
- CEmail encryption software
- DData recovery procedures
How the community answered
(30 responses)- A93% (28)
- B3% (1)
- C3% (1)
Why each option
This question identifies which factor most directly determines whether five years of emails can be produced in response to an e-discovery request.
A data retention policy defines how long data such as emails is stored before being deleted, making it the foundational control that determines whether five-year-old emails still exist. If the policy only retains emails for two years, no backup software, recovery procedure, or decryption capability can restore data that was intentionally purged per policy. The retention policy is therefore the greatest single constraint on the ability to fulfill an e-discovery request spanning a multi-year period.
Backup software and hardware affect the ability to restore data that was retained, but they are irrelevant if the retention policy never preserved the emails in the first place.
Email encryption software may complicate retrieval if keys are unavailable, but emails that were retained can still be identified and potentially decrypted; retention policy is a more fundamental barrier.
Data recovery procedures describe the process of restoring retained or backed-up data and are only relevant after confirming the data was actually stored, making them secondary to the retention policy.
Concept tested: Data retention policy impact on e-discovery
Source: https://csrc.nist.gov/publications/detail/sp/800-34/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.