Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Proofpoint PPAN01 Exam - Topic 1 Question 13 Discussion

Evidence of an attack is no longer present due to a scheduled data purge. What would be the appropriate recommendation?
D) Re-evaluate the data retention policy to ensure evidence is adequately preserved.
A) Report the incident to the appropriate authorities for further investigation.
B) Ignore the deletion of evidence as it cannot be recovered or used for any legal actions.
C) Maintain the current data retention policy because it has been adequate until now.

Proofpoint PPAN01 Exam - Topic 1 Question 13 Discussion

Actual exam question for Proofpoint's PPAN01 exam
Question #: 13
Topic #: 1
[All PPAN01 Questions]

Evidence of an attack is no longer present due to a scheduled data purge. What would be the appropriate recommendation?

Show Suggested Answer Hide Answer
Suggested Answer: D

If evidence disappears due to routine purge, the correct recommendation is to re-evaluate retention to preserve artifacts needed for investigations, legal review, and lessons learned (D). In Proofpoint-focused IR, key evidence often includes message traces (Smart Search), TAP threat metadata (campaign association, URL/attachment verdicts), click telemetry, quarantine/pull actions (TRAP), and raw message artifacts (.eml with full headers). If these are purged too quickly, responders lose the ability to reconstruct timelines, confirm scope (who received/clicked), and prove containment effectiveness. NIST-aligned preparation requires retention policies that match realistic detection and reporting windows---especially for low-and-slow campaigns, supplier compromise, and credential abuse that may be discovered days or weeks later. The recommendation is not to ignore the gap or assume ''it was fine before''; it is to adjust retention to support IR requirements, including longer log retention, mailbox audit log duration, and secure storage for forensic artifacts. In practice, teams define retention based on regulatory obligations, business risk, and mean-time-to-detect, then implement controls to prevent premature deletion of high-value evidence during active incidents.


Contribute your Thoughts:

0/2000 characters
Ryan
2 hours ago
I practiced a similar question where we had to evaluate data policies. I think D is the best choice, but I wonder if there's a legal aspect we should consider too.
upvoted 0 times
...
Arlette
5 days ago
I feel like option B is definitely wrong, but I can't recall why exactly. We can't just ignore evidence, right?
upvoted 0 times
...
Edda
10 days ago
I'm not entirely sure, but I remember something about the importance of data retention policies in class. Maybe we should consider option A too?
upvoted 0 times
...
Charolette
16 days ago
I think option D makes the most sense. We need to ensure that evidence is preserved for future incidents.
upvoted 0 times
...

Save Cancel