CAS-003 · Question #49
An agency has implemented a data retention policy that requires tagging data according to type before storing it in the data repository. The policy requires all business emails be automatically…
The correct answer is D. The employee saved a file on the computer's hard drive that contained archives of emails, which. The most likely cause is that the employee saved a local archive file (e.g., a .pst or .zip file containing old emails) directly on their workstation's hard drive. The data retention policy and automated deletion apply to the email server and data repository, not to local…
Question
An agency has implemented a data retention policy that requires tagging data according to type before storing it in the data repository. The policy requires all business emails be automatically deleted after two years. During an open records investigation, information was found on an employee's work computer concerning a conversation that occurred three years prior and proved damaging to the agency's reputation. Which of the following MOST likely caused the data leak?
Options
- AThe employee manually changed the email client retention settings to prevent deletion of emails
- BThe file that contained the damaging information was mistagged and retained on the server for
- CThe email was encrypted and an exception was put in place via the data classification application
- DThe employee saved a file on the computer's hard drive that contained archives of emails, which
How the community answered
(24 responses)- A17% (4)
- B8% (2)
- C29% (7)
- D46% (11)
Explanation
The most likely cause is that the employee saved a local archive file (e.g., a .pst or .zip file containing old emails) directly on their workstation's hard drive. The data retention policy and automated deletion apply to the email server and data repository, not to local copies stored outside those systems. A file saved locally bypasses the server-side deletion mechanism entirely, allowing data that should have been purged to persist. Option A is possible but less likely than a simple local save. Option B (mistagging) could allow server retention but wouldn't explain data found specifically on the employee's local computer. Option C (encryption exception) is speculative and not a standard behavior.
Topics
Community Discussion
No community discussion yet for this question.