CompTIA CySA+CS0-002 – Question051

An employee was found to have performed fraudulent activities. The employee was dismissed, and the employee's laptop was sent to the IT service desk to undergo a data sanitization procedure. However, the security analyst responsible for the investigation wants to avoid data sanitization. Which of the following can the security analyst use to justify the request?

A.
GDPR
B. Data correlation procedure
C. Evidence retention
D. Data retention

Correct Answer: C