A security technician has been given the task of preserving emails that are potentially involved in a dispute between a company and a contractor. Which of the following BEST describes this forensic concept?
Legal Hold
Legal hold refers to the fact that information that may be relevant to a court case must be preserved. Information subject to legal hold might be defined by regulators or industry best practice, or there may be a litigation notice from law enforcement or lawyers pursuing a civil action. This means that computer systems may be taken as evidence, with all the obvious disruption to a network that entails.
Chain of Custody
Chain of custody documentation reinforces the integrity and proper handling of evidence from collection, to analysis, to storage, and finally to presentation. When security breaches go to trial, the chain of custody protects an organization against accusations that evidence has either been tampered with or is different than it was when it was collected. Every person in the chain who handles evidence must log the methods and tools they used.
__
So, the answer is Legal hold
from Daryl Gibson's book: A chain of custody provides assurances that evidence has been
controlled and handled properly after collection. It documents who
handled the evidence and when they handled it. A legal hold is a court
order to preserve data as evidence.
I would go with chain of custody.
Correct . Key words "preserving emails that are potentially involved "
upvoted 2 times
...
This section is not available anymore. Please use the main Exam Page.SY0-501 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
MagicianRecon
Highly Voted 5 years agoEluis007
Most Recent 3 years, 7 months agosimo123456
4 years, 1 month agoFigekioki
4 years agohlwo
4 years, 9 months ago