nerdexam
CompTIA

CS0-003 · Question #341

During an incident, a security analyst discovers a large amount of PII has been emailed externally from an employee to a public email address. The analyst finds that the external email is the employee

The correct answer is A. Place a legal hold on the employee's mailbox.. In the event of a PII data breach involving an employee's mailbox, the most immediate and critical priority is to place a legal hold to preserve all evidence.

Submitted by saadiq_pk· Mar 6, 2026Incident Response and Management

Question

During an incident, a security analyst discovers a large amount of PII has been emailed externally from an employee to a public email address. The analyst finds that the external email is the employee's personal email. Which of the following should the analyst recommend be done first?

Options

  • APlace a legal hold on the employee's mailbox.
  • BEnable filtering on the web proxy.
  • CDisable the public email access with CASB.
  • DConfigure a deny rule on the firewall.

How the community answered

(22 responses)
  • A
    73% (16)
  • B
    9% (2)
  • C
    14% (3)
  • D
    5% (1)

Why each option

In the event of a PII data breach involving an employee's mailbox, the most immediate and critical priority is to place a legal hold to preserve all evidence.

APlace a legal hold on the employee's mailbox.Correct

When a significant data breach, especially involving PII, occurs through an employee's mailbox, placing a legal hold is the most critical first step. This action ensures that all relevant data in the mailbox is preserved immediately, preventing accidental or intentional deletion, which is crucial for forensic investigation, compliance, and potential legal proceedings.

BEnable filtering on the web proxy.

Enabling filtering on the web proxy addresses future outgoing traffic, but it does not address the already occurred data exfiltration or preserve the existing evidence related to the incident.

CDisable the public email access with CASB.

Disabling public email access with a Cloud Access Security Broker (CASB) would prevent future similar incidents but does not address the immediate need to preserve evidence of the breach that already happened.

DConfigure a deny rule on the firewall.

Configuring a deny rule on the firewall focuses on network-level prevention of future outbound connections, which is too broad or too late for the immediate concern of preserving evidence from a specific internal data exfiltration event.

Concept tested: Incident response - data breach evidence preservation

Source: https://learn.microsoft.com/en-us/purview/create-an-in-place-hold

Topics

#Data exfiltration#PII#Incident response#Legal hold

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice