SY0-701 Security Program Management and Oversight Practice Question
A records manager is told that some HR emails may be needed for an active investigation, while unrelated messages are still due for deletion under the retention schedule. Which two actions should the manager take? Select two.
⚠ Common exam trap
Many candidates confuse 'legal hold' with simply archiving or delaying deletion, but only a formal hold ensures compliance with legal preservation requirements and prevents spoliation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Place the affected emails on legal hold
A is correct because placing the affected emails on legal hold suspends the retention schedule for those specific records, ensuring they are preserved for the active investigation without altering the deletion policy for unrelated messages. This is a standard practice under eDiscovery and legal hold procedures, often implemented via Exchange Online or similar systems using litigation hold or in-place hold.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Place the affected emails on legal hold
Why this is correct
A legal hold is a formal preservation notice issued when litigation or an investigation is reasonably anticipated. It immediately suspends normal retention and deletion schedules for the affected emails, including any automated purge processes, to prevent spoliation and ensure that all relevant evidence remains intact and searchable for the legal matter. This is the required first step before any other records action is taken.
- ✗
Delete all related records immediately to reduce storage costs
Why it's wrong here
Immediately deleting related emails to reduce storage costs constitutes spoliation of evidence, which can trigger adverse inference instructions, severe monetary sanctions, and even criminal penalties for obstruction of justice. The duty to preserve arises as soon as litigation is reasonably anticipated, and cost concerns never justify destroying discoverable data. A lawful deletion would require that no preservation duty exists and that retention policies are followed.
- ✓
Keep the records until the legal team releases the hold
Why this is correct
The legal hold remains in force until the responsible legal team formally determines that the matter is concluded and all preservation obligations, including any appeals or related investigations, have been satisfied. Only after counsel issues a release can the records resume their normal life cycle under the approved retention schedule. Premature release could expose the organization to liability for destroying evidence still needed in ongoing proceedings.
- ✗
Move them into a personal archive folder
Why it's wrong here
Moving emails into a personal archive folder removes them from the authoritative records repository, stripping them of controlled metadata, version history, and audit trails that prove their authenticity and chain of custody. This ad hoc approach fails to enforce legal hold protections and may be viewed as concealment or unauthorized removal, raising spoliation concerns and harming the organization's ability to demonstrate compliance with discovery obligations.
- ✗
Rewrite the retention schedule without approval
Why it's wrong here
Rewriting the retention schedule without going through the governance approval process violates the organization's formal records management policy and can break regulatory and contractual compliance requirements. A retention schedule is a legal instrument that codifies obligations; unilateral changes by a single manager have no legal force and do not satisfy the need for a litigation hold, which is a separate, case-specific preservation action.
Go deeper
Related to this question
Learn chapter
Security Policies and Procedures
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
Standard
A standard is an agreed-upon set of rules, guidelines, or specifications that ensure consistency, compatibility, and quality across IT products, services, and processes.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.