CS0-003 · Question #341
During an incident, a security analyst discovers a large amount of PII has been emailed externally from an employee to a public email address. The analyst finds that the external email is the employee
The correct answer is A. Place a legal hold on the employee's mailbox.. In the event of a PII data breach involving an employee's mailbox, the most immediate and critical priority is to place a legal hold to preserve all evidence.
Question
During an incident, a security analyst discovers a large amount of PII has been emailed externally from an employee to a public email address. The analyst finds that the external email is the employee's personal email. Which of the following should the analyst recommend be done first?
Options
- APlace a legal hold on the employee's mailbox.
- BEnable filtering on the web proxy.
- CDisable the public email access with CASB.
- DConfigure a deny rule on the firewall.
How the community answered
(22 responses)- A73% (16)
- B9% (2)
- C14% (3)
- D5% (1)
Why each option
In the event of a PII data breach involving an employee's mailbox, the most immediate and critical priority is to place a legal hold to preserve all evidence.
When a significant data breach, especially involving PII, occurs through an employee's mailbox, placing a legal hold is the most critical first step. This action ensures that all relevant data in the mailbox is preserved immediately, preventing accidental or intentional deletion, which is crucial for forensic investigation, compliance, and potential legal proceedings.
Enabling filtering on the web proxy addresses future outgoing traffic, but it does not address the already occurred data exfiltration or preserve the existing evidence related to the incident.
Disabling public email access with a Cloud Access Security Broker (CASB) would prevent future similar incidents but does not address the immediate need to preserve evidence of the breach that already happened.
Configuring a deny rule on the firewall focuses on network-level prevention of future outbound connections, which is too broad or too late for the immediate concern of preserving evidence from a specific internal data exfiltration event.
Concept tested: Incident response - data breach evidence preservation
Source: https://learn.microsoft.com/en-us/purview/create-an-in-place-hold
Topics
Community Discussion
No community discussion yet for this question.