eDiscovery Flashcards

1
Q

What is eDiscovery?

A

Electronic discovery, or eDiscovery, is the process of identifying and delivering electronic information that can be used as evidence in legal cases.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is core eDiscovery?

A

An eDiscovery solution that builds on the Content search functionality by enabling you to create eDiscovery cases and assign eDiscovery managers to specific cases.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is content search?

A

A tool that searches for content across Microsoft 365 data sources (Exchange online, OneDrive for business, SharePoint Online, etc.) and can export the search results to a local computer.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is advanced eDiscovery?

A

A tool that builds on Core eDiscovery’s functionality by providing an end-to-end workflow to manage, analyse and export content for an organization’s internal and external investigations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the six stages of eDiscovery?

A

Identification - find docs that may have relevant info

Preservation - Protect identified data from tampering

Collection - transfer data to legal entities

Processing - prepare data for further review and analysis

Review - reduce data to what is relevant to case

Production - docs are exported to hand to legal.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the Unified Audit Log?

A

A centralized audit log that contains activities from most M365 services.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How long are Audit records kept?

A

90 - 365 days, depending on license.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Does MS let you export audits logs?

A

Yes, by using APIs or, for smaller logs sets, export to csv.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Can you configure alerts based on activities in the Unified Audit Log?

A

Yes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is advanced auditing?

A

A MS365 feature that brings three main features:

Long-term Retention of Audit Logs

Access to Crucial Events for Investigations

High-bandwidth Access to The O365 Management Activity API

requires extra licensing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What does long-term Retention of audit logs do?

A

It lets organizations create log retention policies to keep information for up to 10 years. This helps them support long running investigations and respond to various obligations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What does Access to Crucial Events for Investigations do?

A

It provides access to 4 crucial events in the aduit log

MailItemsAccessed - triggered by mail client or protocols

Send - triggered by sending, forwarding or replying to an email

SearchQueryIntiatedExchange - triggered by email searches

SearchQueryIntiatedSharePoint - triggered by SharePoint searches

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What does High-bandwidth Access to The O365 Management Activity API do?

A

Allows organization that use the API to access Audit log data with a higher bandwidth limit.

That means less throttling and more real-time info. The base is 2,000 request per minutes, which gets dynamically increased on seat count and licenses.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly