Your SOC suspects an insider exfiltrated customer data from a file server that is also causing production outages. The team wants to reimage the server and clear old logs. What must happen before those logs are deleted?
Select an answer to reveal the explanation.
Short Explanation
Think of a legal hold like putting a museum piece in a case before anyone cleans the room. If logs could prove insider theft, preservation comes before reimaging or log cleanup. You don't fix the outage first and erase the evidence.
Full Explanation
Legal hold is a preservation order that suspends normal log retention and deletion so evidence remains available for a suspected incident, investigation, or litigation. In an insider-data case, file-server logs, EDR events, and SIEM records may become evidence, so the analyst must preserve them before any remediation such as reimaging, log rotation, or clearing storage. Preservation protects chain of custody and supports later forensic timeline analysis, legal review, and disciplinary action. Reimaging the server to stop outages is remediation, not preservation; it can destroy the very logs needed to prove what the insider accessed or exfiltrated. Notifying affected customers may be a legal or privacy requirement, but it does not justify deleting logs and is not the first step when evidence preservation is unresolved. Escalating to HR, isolating the host, and preserving volatile memory can be valid incident-response actions, yet they do not address the immediate risk of destroying historical logs under a hold. Exam caveat: when logs are tied to a suspected insider incident, choose legal hold or evidence preservation before cleanup. Operational check: have legal or privacy confirm the hold scope, suspend deletion for the relevant log sources, and record the custodian, time, and systems placed under hold.