exam questions

Exam CS0-002 All Questions

View all questions & answers for the CS0-002 exam

Exam CS0-002 topic 1 question 51 discussion

Actual exam question from CompTIA's CS0-002
Question #: 51
Topic #: 1
[All CS0-002 Questions]

An employee was found to have performed fraudulent activities. The employee was dismissed, and the employee's laptop was sent to the IT service desk to undergo a data sanitization procedure. However, the security analyst responsible for the investigation wants to avoid data sanitization. Which of the following can the security analyst use to justify the request?

  • A. GDPR
  • B. Data correlation procedure
  • C. Evidence retention
  • D. Data retention
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
EVE12
Highly Voted 2 years, 7 months ago
Selected Answer: C
Evidence Retention If the incident involved a security breach and the incident response process gathered evidence to prove an illegal act or a violation of policy, the evidence must be stored securely until it is presented in court or is used to confront the violating employee. Computer investigations require different procedures than regular investigations because the time frame for the computer investigator is compressed, and an expert might be required to assist in the investigation. Also, computer information is intangible and often requires extra care to ensure that the data is retained in its original format. Finally, the evidence in a computer crime is difficult to gather.
upvoted 9 times
...
fuzzyguzzy
Most Recent 5 months ago
Selected Answer: C
C: Makes sense given the context. "Evidence Retention" is in the exam objectives in the context of incident response.
upvoted 1 times
...
kiduuu
2 years, 1 month ago
Selected Answer: C
Evidence retention would be the most appropriate justification for the security analyst to request avoiding data sanitization
upvoted 2 times
...
2Fish
2 years, 1 month ago
Selected Answer: C
C. This is basically the same as putting data on Legal Hold.
upvoted 2 times
...
[Removed]
2 years, 2 months ago
Evidence Retention = Legal Hold
upvoted 4 times
...
MrRobotJ
2 years, 5 months ago
Selected Answer: C
most likely C
upvoted 1 times
...
TeyMe
2 years, 5 months ago
The option should be "Legal Hold" not Evidence retention..
upvoted 3 times
...
MortG7
2 years, 6 months ago
Selected Answer: D
I am leaning towards D. How do we know that the evidence came from the laptop which resulted in fraudulent activity. The evidence could have come from a DLP, Firewall, proxy server...IMHO it is D.
upvoted 1 times
TheStudiousPeepz
2 years, 6 months ago
"How do we know that the evidence came from the laptop which resulted in fraudulent activity" You would still want to check his computer for evidence of fraud regardless, no? He committed a crime and its likely that the org wants to pursue him legally. If they wipe the drive they have no evidence to provide to legal counsel. It's no longer just "data" it is now also evidence.
upvoted 1 times
MortG7
2 years, 6 months ago
evidence? "..An employee was found to have performed fraudulent activities.." he has been found guilty and dismissed. They already have proof, and there is evidence already..thus the dismissal.
upvoted 1 times
...
...
...
sh4dali
2 years, 7 months ago
Selected Answer: C
Evidence retention
upvoted 1 times
...
nonjabusiness
2 years, 7 months ago
Selected Answer: C
Evidence retention is the process of keeping any evidence of an incident for the entire duration of the legal process
upvoted 2 times
...
amateurguy
2 years, 8 months ago
Selected Answer: D
I would have to go with D because I dont think ive ever heard the term "evidence retention" being used in any courses. What do you guys think?
upvoted 4 times
sh4dali
2 years, 7 months ago
Exam objective 4.2 under post-incident activities has specially has "Evidence retention"
upvoted 2 times
...
ititititcomcocmcom
2 years, 7 months ago
evidence retention is in exam obj 4.2
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago