Which Data Type Should Have Reduced Retention for Investigations?
A security team at a large, global company needs to reduce the cost of storing data used for performing investigations. Which of the following types of data should have its retention length reduced?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests whether you can balance investigative value against storage cost, and the trap is choosing a smaller structured data type like vulnerability scans instead of the voluminous packet capture.
A global security team can cut investigation data storage costs most effectively by reducing packet capture retention, because full traffic captures are the largest and fastest-growing forensic data set. This SY0-701 guide explains why packet capture is the best choice over endpoint logs, OS security logs, and vulnerability scan data.
Many learners pick vulnerability scan data because it seems less important for investigations, but scans are structured and relatively small, while packet capture consumes enormous storage and has limited long-term forensic value.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Packet capture is full packet-level network traffic, often terabytes per day in a large global company, making it the most expensive investigation data to store. Its forensic value is highest immediately after an incident, but long retention often has diminishing returns compared with the storage cost. Reducing packet capture retention directly cuts storage expense while still preserving short-term incident response capability. Endpoint logs and OS security logs are much smaller and remain valuable for host-based and authentication investigations. Therefore A is the correct data type to reduce first.Why the Other Options Are Wrong
B endpoint logs are compact, endpoint-focused telemetry that is critical for tracing process execution, lateral movement and malware behavior; reducing their retention can create major investigative blind spots. C OS security logs contain authentication, privilege and system events that are essential for timeline reconstruction and compliance, and they are not as storage-intensive as packet capture. D vulnerability scan data is structured and periodic rather than high-volume continuous traffic; it supports vulnerability management, remediation tracking and audit evidence, so cutting its retention may hurt risk reporting more than it saves. The question targets cost reduction, and packet capture is the clear outlier in storage volume.Community Comment Notes
As e2ba0ff noted, packet capture is the "most detailed type of network data, capturing all traffic" and it "can quickly accumulate large volumes of data," which supports reducing its retention. ProudFather reinforced that "long-term value of most packet captures diminishes rapidly" while storage costs remain high. Fourgehan chose vulnerability scans and called them "less critical for ongoing investigations," but that rationale focuses on investigative priority rather than the storage-cost driver the question asks about. The vote pattern heavily favors A, consistent with the cost-versus-volume analysis.Official Reference
Exam Strategy
When a question asks about reducing retention cost, rank the data sources by volume first, not by investigative glamour. Full packet capture is almost always the storage hog, while endpoint and OS logs are compact and high-value for host and timeline analysis.
Frequently Asked Questions
Why not reduce vulnerability scan retention instead of packet capture?
Vulnerability scan records are smaller and structured, and they support remediation tracking and compliance, while full packet capture consumes far more storage for the same period.
Are endpoint and OS security logs safe to retain longer than packet capture?
Yes, endpoint and OS security logs are far less voluminous and provide critical host and authentication evidence for investigations, so they usually justify longer retention.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →