nerdexam
CompTIA

CAS-003 · Question #680

Confidential information related to ApplicationA. Application B and Project X appears to have been leaked to a competitor. After consulting with the legal team, the IR team is advised to take…

The correct answer is A. Remove all members from the distribution groups immediately. This answer is debatable in practice, but in the context of this exam question the FIRST priority is containment - stopping the ongoing breach before evidence is further altered or exfiltrated. Removing all members from the distribution groups immediately (A) cuts off access so…

Enterprise Security Operations

Question

Confidential information related to ApplicationA. Application B and Project X appears to have been leaked to a competitor. After consulting with the legal team, the IR team is advised to take immediate action to preserve evidence for possible litigation and criminal charges. While reviewing the rights and group ownership of the data involved in the breach, the IR team inspects the following distribution group access lists:

Which of the following actions should the IR team take FIRST?

Exhibit

CAS-003 question #680 exhibit

Options

  • ARemove all members from the distribution groups immediately
  • BPlace the mailbox for jsmith on legal hold
  • CImplement a proxy server on the network to inspect all outbound SMTP traffic for the DevOps
  • DInstall DLP software on all developer laptops to prevent data from leaving the network.

How the community answered

(38 responses)
  • A
    79% (30)
  • B
    3% (1)
  • C
    13% (5)
  • D
    5% (2)

Explanation

This answer is debatable in practice, but in the context of this exam question the FIRST priority is containment - stopping the ongoing breach before evidence is further altered or exfiltrated. Removing all members from the distribution groups immediately (A) cuts off access so the leak cannot continue and suspects cannot delete or tamper with additional evidence. Option B (legal hold on jsmith's mailbox) is a critical next step for preserving specific email evidence, but it only covers one user's mailbox and does not stop the active exfiltration. Options C and D are longer-term preventive measures (proxy inspection, DLP) that would not help immediately. The IR principle is: contain first, then preserve and investigate.

Topics

#legal hold#evidence preservation#incident response#data breach

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice