nerdexam
CompTIA

CAS-003 · Question #195

A company has implemented data retention policies and storage quotas in response to their legal department's requests and the SAN administrator's recommendation. The retention policy states all…

The correct answer is C. Provide the 1Tb of files on the network and the 300Mb of email files regardless of age. Once an e-discovery request is issued by opposing legal counsel, a legal hold is triggered. Legal holds supersede all internal data retention and storage quota policies-deleting or altering any potentially relevant data after receiving such a request could constitute spoliation…

Risk Management

Question

A company has implemented data retention policies and storage quotas in response to their legal department's requests and the SAN administrator's recommendation. The retention policy states all email data older than 90 days should be eliminated. As there are no technical controls in place, users have been instructed to stick to a storage quota of 500Mb of network storage and 200Mb of email storage. After being presented with an e-discovery request from an opposing legal council, the security administrator discovers that the user in the suit has 1Tb of files and 300Mb of email spanning over two years. Which of the following should the security administrator provide to opposing council?

Options

  • ADelete files and email exceeding policy thresholds and turn over the remaining files and
  • BDelete email over the policy threshold and hand over the remaining emails and all of the
  • CProvide the 1Tb of files on the network and the 300Mb of email files regardless of age.
  • DProvide the first 200Mb of e-mail and the first 500Mb of files as per policy.

How the community answered

(56 responses)
  • A
    18% (10)
  • B
    7% (4)
  • C
    50% (28)
  • D
    25% (14)

Explanation

Once an e-discovery request is issued by opposing legal counsel, a legal hold is triggered. Legal holds supersede all internal data retention and storage quota policies-deleting or altering any potentially relevant data after receiving such a request could constitute spoliation of evidence, which carries severe legal consequences (sanctions, adverse inference instructions, or criminal charges). The security administrator must preserve and hand over all relevant data in its entirety, regardless of whether it exceeds policy thresholds. Options A, B, and D all involve deleting data to comply with internal policy, which is legally impermissible once litigation is underway.

Topics

#e-discovery#legal hold#data retention#compliance conflict

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice