ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 90 - CS0-003 discussion

Report
Export

During an incident, a security analyst discovers a large amount of Pll has been emailed externally from an employee to a public email address. The analyst finds that the external email is the employee's personal email. Which of the following should the analyst recommend be done first?

A.
Place a legal hold on the employee's mailbox.
Answers
A.
Place a legal hold on the employee's mailbox.
B.
Enable filtering on the web proxy.
Answers
B.
Enable filtering on the web proxy.
C.
Disable the public email access with CASB.
Answers
C.
Disable the public email access with CASB.
D.
Configure a deny rule on the firewall.
Answers
D.
Configure a deny rule on the firewall.
Suggested answer: A

Explanation:

Placing a legal hold on the employee's mailbox is the best action to perform first, as it preserves all mailbox content, including deleted items and original versions of modified items, for potential legal or forensic purposes. A legal hold is a feature that allows an administrator to retain mailbox data for a user indefinitely or for a specified period, regardless of the user's actions or retention policies. A legal hold can be applied to a mailbox using Litigation Hold or In-Place Hold in Exchange Server or Exchange Online. A legal hold can help to ensure that evidence of data exfiltration or other malicious activities is not lost or tampered with, and that the organization can comply with any legal or regulatory obligations. The other actions are not as urgent or effective as placing a legal hold on the employee's mailbox, as they do not address the immediate threat of data loss or compromise. Enabling filtering on the web proxy may help to prevent some types of data exfiltration or malicious traffic, but it does not help to recover or preserve the data that has already been emailed externally. Disabling the public email access with CASB (Cloud Access Security Broker) may help to block or monitor the use of public email services by employees, but it does not help to recover or preserve the data that has already been emailed externally. Configuring a deny rule on the firewall may help to block or monitor the network traffic from the employee's laptop, but it does not help to recover or preserve the data that has already been emailed externally.

asked 02/10/2024
Maurice Nicholson
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first