Which Data Type Should Have Reduced Retention for Investigations?

Given a scenario, use appropriate data sources to support investigation.
Answer Correct answer: A — Reduce retention of packet capture data first because it is the largest and costliest investigative data type with limited long-term value.

A security team at a large, global company needs to reduce the cost of storing data used for performing investigations. Which of the following types of data should have its retention length reduced?

  1. Packet capture Correct Answer
  2. Endpoint logs
  3. OS security logs
  4. Vulnerability scan

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests whether you can balance investigative value against storage cost, and the trap is choosing a smaller structured data type like vulnerability scans instead of the voluminous packet capture.

A global security team can cut investigation data storage costs most effectively by reducing packet capture retention, because full traffic captures are the largest and fastest-growing forensic data set. This SY0-701 guide explains why packet capture is the best choice over endpoint logs, OS security logs, and vulnerability scan data.

Many learners pick vulnerability scan data because it seems less important for investigations, but scans are structured and relatively small, while packet capture consumes enormous storage and has limited long-term forensic value.

Community Discussion (3 comments)

e2ba0ff 👍 5 Selected: A
This is the most detailed type of network data, capturing all traffic on a network segment. It can quickly accumulate large volumes of data, making it the most expensive to store, especially when considering long retention periods
ProudFather 👍 2 Selected: A
Packet capture data (also known as network traffic captures) is typically very large and can quickly consume significant storage space. Why reduce retention: Limited investigative value: While valuable for immediate incident response, the long-term value of most packet captures diminishes rapidly. High storage costs: Storing large volumes of packet capture data can be expensive.
Fourgehan 👍 1 Selected: D
This is because vulnerability scans are less critical for ongoing investigations compared to the other types of data, and their relevance decreases over time as vulnerabilities are remediated

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Packet capture is full packet-level network traffic, often terabytes per day in a large global company, making it the most expensive investigation data to store. Its forensic value is highest immediately after an incident, but long retention often has diminishing returns compared with the storage cost. Reducing packet capture retention directly cuts storage expense while still preserving short-term incident response capability. Endpoint logs and OS security logs are much smaller and remain valuable for host-based and authentication investigations. Therefore A is the correct data type to reduce first.

Why the Other Options Are Wrong

B endpoint logs are compact, endpoint-focused telemetry that is critical for tracing process execution, lateral movement and malware behavior; reducing their retention can create major investigative blind spots. C OS security logs contain authentication, privilege and system events that are essential for timeline reconstruction and compliance, and they are not as storage-intensive as packet capture. D vulnerability scan data is structured and periodic rather than high-volume continuous traffic; it supports vulnerability management, remediation tracking and audit evidence, so cutting its retention may hurt risk reporting more than it saves. The question targets cost reduction, and packet capture is the clear outlier in storage volume.

Community Comment Notes

As e2ba0ff noted, packet capture is the "most detailed type of network data, capturing all traffic" and it "can quickly accumulate large volumes of data," which supports reducing its retention. ProudFather reinforced that "long-term value of most packet captures diminishes rapidly" while storage costs remain high. Fourgehan chose vulnerability scans and called them "less critical for ongoing investigations," but that rationale focuses on investigative priority rather than the storage-cost driver the question asks about. The vote pattern heavily favors A, consistent with the cost-versus-volume analysis.

Official Reference

Exam Strategy

When a question asks about reducing retention cost, rank the data sources by volume first, not by investigative glamour. Full packet capture is almost always the storage hog, while endpoint and OS logs are compact and high-value for host and timeline analysis.

Frequently Asked Questions

Why not reduce vulnerability scan retention instead of packet capture?

Vulnerability scan records are smaller and structured, and they support remediation tracking and compliance, while full packet capture consumes far more storage for the same period.

Are endpoint and OS security logs safe to retain longer than packet capture?

Yes, endpoint and OS security logs are far less voluminous and provide critical host and authentication evidence for investigations, so they usually justify longer retention.

More SY0-701 FAQ →

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide