nerdexam
CompTIA

CS0-003 · Question #247

During an incident, a security analyst discovers a large amount of Pll has been emailed externally from an employee to a public email address. The analyst finds that the external email is the employee

The correct answer is A. Place a legal hold on the employee's mailbox.. Placing a legal hold on the employee's mailbox is the best action to perform first, as it preserves all mailbox content, including deleted items and original versions of modified items, for potential legal or forensic purposes. A legal hold is a feature that allows an administrat

Submitted by krish.m· Mar 6, 2026Incident Response and Management

Question

During an incident, a security analyst discovers a large amount of Pll has been emailed externally from an employee to a public email address. The analyst finds that the external email is the employee's personal email. Which of the following should the analyst recommend be done first?

Options

  • APlace a legal hold on the employee's mailbox.
  • BEnable filtering on the web proxy.
  • CDisable the public email access with CASB.
  • DConfigure a deny rule on the firewall.

How the community answered

(63 responses)
  • A
    73% (46)
  • B
    16% (10)
  • C
    8% (5)
  • D
    3% (2)

Explanation

Placing a legal hold on the employee's mailbox is the best action to perform first, as it preserves all mailbox content, including deleted items and original versions of modified items, for potential legal or forensic purposes. A legal hold is a feature that allows an administrator to retain mailbox data for a user indefinitely or for a specified period, regardless of the user's actions or retention policies. A legal hold can be applied to a mailbox using Litigation Hold or In-Place Hold in Exchange Server or Exchange Online. A legal hold can help to ensure that evidence of data exfiltration or other malicious activities is not lost or tampered with, and that the organization can comply with any legal or regulatory obligations.

Topics

#Incident response#Data exfiltration#Legal hold#PII protection

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice