Courseiva

SY0-701 Security Program Management and Oversight Practice Question

A security manager is reviewing the organization's incident response plan and notices that it lacks a defined process for handling evidence that may be used in legal proceedings. Which concept should the manager ensure is addressed to maintain the integrity of evidence?

⚠ Common exam trap

Watch out — candidates often confuse chain of custody with general data retention or incident documentation, missing that chain of custody specifically tracks evidence handling for legal admissibility.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Chain of custody

Chain of custody is essential for ensuring that evidence collected during an incident remains admissible in legal proceedings. It documents who handled the evidence, when, and why, preventing tampering or contamination. The other options address different areas: retention schedules, user policies, and business continuity. The incident response plan must include chain of custody procedures to support potential prosecutions or lawsuits.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Chain of custody

    Why this is correct

    Chain of custody is the documented process that tracks the seizure, custody, control, transfer, analysis, and disposition of evidence. It ensures that evidence is admissible in court by showing that it has not been tampered with. In an incident response plan, defining chain of custody procedures is critical for any investigation that may lead to legal action. This directly addresses the manager's concern about evidence integrity.

  • ✗

    Data retention policy

    Why it's wrong here

    A data retention policy specifies how long data should be kept and when it should be destroyed, but it does not address the handling of evidence during an incident. While retention is important for legal holds, it does not ensure that evidence remains unaltered from collection to presentation. The scenario specifically asks about maintaining evidence integrity for legal proceedings, which is the domain of chain of custody.

  • ✗

    Business impact analysis

    Why it's wrong here

    A business impact analysis identifies critical business functions and the effects of disruptions, helping prioritize recovery efforts. It is a component of business continuity planning, not incident evidence handling. While it may inform incident severity, it does not address the legal integrity of evidence. The scenario is about legal proceedings, so a BIA would not fill the identified gap.

  • ✗

    Acceptable use policy

    Why it's wrong here

    An acceptable use policy defines how employees may use organizational assets and is primarily a preventive control. It does not provide procedures for preserving evidence after an incident. The manager's focus is on legal admissibility of evidence, which requires a forensic chain of custody, not user behavior rules. Therefore, this policy is not relevant to the stated gap in the incident response plan.

Go deeper

Related to this question

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,030 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.