CompTIA CySA+ (CS0-003) — Question 501

A security alert was triggered when an end user tried to access a website that is not allowed per organizational policy. Since the action is considered a terminable offense, the SOC analyst collects the authentication logs, web logs, and temporary files, reflecting the web searches from the user's workstation, to build the case for the investigation. Which of the following is the best way to ensure that the investigation complies with HR or privacy policies?

Answer options

Correct answer: B

Explanation

The correct answer is B because it emphasizes the need to protect user privacy by not including identifiable information and controlling access to sensitive evidence. Options A and D do not address privacy concerns adequately, while option C, although it attempts to obscure the investigation's nature, still does not ensure compliance with HR regulations effectively.