Preserve two incident evidence cohorts and dispose of incidental copies
A hands-on CS0-004 lab. You produce the real artefact and 8 automated checks verify it behaves the way the exam expects.
Try this labAll CS0-004 practice
- Certification
- CS0-004
- Format
- Structured configuration
- Difficulty
- hard
- Estimated time
- 35 min
- Automated checks
- 8
The brief
Repair evidence-lifecycle.json. actions is an ordered ledger, maximum40 rows: unique id, integer day>=1, op, actor. Days cannot decrease. copy adds source,target,records; purge-records adds target,records; unlink-object/purge-object add target; sanitize-key adds key,slot. IDs/record lists must be unique and known. Copy needs an ordinarily readable source and active readable target, actual source members and no duplicate destination members. Respect maximumClass at every transfer and the permitted actor; physically feasible actions still take effect with wrong delegation, while custody fails separately. Record purge works only in triage. Object purge removes all members under the supplied capability. Unlink removes ordinary access only; content remains recoverable. Key sanitization removes exactly one actual slot; any surviving slot can decrypt that key's objects. All key copies may remove recoverability only when encryption covered the object's entire history. Snapshot's prior plaintext survives even total case-key disposal. Failed actions have no content effect and fail feasibility. Preserve at least one ordinary readable copy continuously through each inclusive retention/hold date, including between same-day actions. Dispose of each unheld cohort by its own deadline and each held cohort by its separate post-release deadline; no expired cohort may later reappear. Do not retain personal data because memory/disk are held. reports needs exactly days5,8,15,18,22,26, with day, readable/recoverable distinct record IDs, copyCount and units. Count each recoverable record-object pair once, including unlinked or prior plaintext; inaccessible fully encrypted ciphertext with no key slots is not recoverable. Reports are end-of-day snapshots after actions that day. Distinct permitted storage routes and purge versus full key disposal remain valid. Save and repair without Reset; do not invent disposal success.
What the checks verify
Your work is graded on 8 independent properties, not on matching one reference answer.
- Distinct known typed actions and exact audit report fields form an editable evidence ledger.
- Every ordered storage/key action is executable against actual remaining evidence and capabilities.
- Evidence movement preserves delegated duties and destination classification.
- Every original cohort remains ordinarily available throughout its independent minimum interval.
- Memory and disk stay continuously retrievable through independently supplied hold-release dates.
- Incidental personal data is absent from every recoverable location by its own deadline.
- Each released held cohort becomes unrecoverable by its own post-release deadline.
- Audit cut populations and copied evidence units reconcile with actual recoverability.
Where this sits in the CS0-004 blueprint
- Domain
- Incident Response and Management
- Objective
- Incident Response Techniques
- Skill
- Evidence, Containment and Verification
Part of CS0-004 preparation
Labs are written by ExamNova to teach the decisions the exam tests. They are not reproductions of vendor lab content.