During an incident response, you have identified data that is potentially relevant to an ongoing legal case. What is the most appropriate next step to ensure compliance with legal hold requirements?
Allow the normal data lifecycle policies to manage the retention of the data since it is part of an ongoing incident.
Continue to analyze the data but ensure it is deleted after the analysis to prevent unauthorized access.
Immediately place the data on legal hold to prevent any alteration or deletion.
Create backups of the data periodically and continue using the original data for business operations.
Placing the data on legal hold ensures that it cannot be modified or deleted. This means that the integrity and availability of the evidence are preserved for legal analysis and proceedings. This step is an integral part of the legal hold process, which secures data relevant to litigation or investigation. The other options would either potentially alter the evidence (making backups and continuing to use the data) or fail to preserve the integrity of evidence (deleting the data after analysis).
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a legal hold in incident response?
Open an interactive chat with Bash
How is data integrity maintained during legal hold?
Open an interactive chat with Bash
Why is deleting data after analysis not appropriate in this situation?