How should a DLP administrator change a policy so that it retains the original file when an endpoint incident has detected a copy to USB device operation?

Prepare for the Symantec Data Loss Prevention Test with our comprehensive materials. Utilize flashcards and multiple-choice questions, complete with hints and explanations, to ensure your success!

Multiple Choice

How should a DLP administrator change a policy so that it retains the original file when an endpoint incident has detected a copy to USB device operation?

Explanation:
This question tests how DLP handles preserving evidence when an endpoint incident shows a copy to a USB device. To ensure the exact file stays available for investigation, you configure a Limit Incident Data Retention policy and choose to Retain Original Message. This setting tells the system to preserve the original file content that triggered the incident, rather than just storing a summary or additional related data. Keeping the original artifact is crucial for forensic review and confirms precisely what was copied. Other options don’t target preserving the original file itself: Retain All Data would keep more data than necessary and may include extraneous information; automatically quarantining changes the device’s handling of the file but doesn’t ensure the original content is retained in the incident store; disabling incident data retention would prevent preserving any evidence.

This question tests how DLP handles preserving evidence when an endpoint incident shows a copy to a USB device. To ensure the exact file stays available for investigation, you configure a Limit Incident Data Retention policy and choose to Retain Original Message. This setting tells the system to preserve the original file content that triggered the incident, rather than just storing a summary or additional related data. Keeping the original artifact is crucial for forensic review and confirms precisely what was copied.

Other options don’t target preserving the original file itself: Retain All Data would keep more data than necessary and may include extraneous information; automatically quarantining changes the device’s handling of the file but doesn’t ensure the original content is retained in the incident store; disabling incident data retention would prevent preserving any evidence.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy