ISC2 CISSP Data Roles Collection Retention And Destruction Practice Test

 

2 Asset Security • 27 original questions

This CISSP practice test focuses on data roles collection retention and destruction through original scenario-based questions aligned to the current ISC2 CISSP Certification Exam Outline. Use the full ExamSnap CISSP collection for practice across all eight domains. For broader exam preparation, review the ISC2 CISSP Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

Wide World Importers is standardizing security across several business units. The customer identity platform raises a question about Data roles including owners, controllers, custodians, processors, users, and subjects. The security governance lead needs to address the control objective while keeping the process defensible to auditors and business owners. Which action provides the BEST governance and security outcome? The asset inventory records 6,000 records across production and backup locations.

  1. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  2. Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner.
  3. Define handling rules that follow the asset classification through access, storage, transmission, sharing, and disposal.
  4. Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles.

Correct answer: D

Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data roles including owners, controllers, custodians, processors, users, and subjects while keeping the process defensible to auditors and business owners.

Option review:

A: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Data roles including owners, controllers, custodians, processors, users, and subjects in this scenario.

B: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Data roles including owners, controllers, custodians, processors, users, and subjects in this scenario.

C: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Data roles including owners, controllers, custodians, processors, users, and subjects in this scenario.

D: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data roles including owners, controllers, custodians, processors, users, and subjects while keeping the process defensible to auditors and business owners.

Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.

Question 2

During a internal audit response, Bellows University asks the IAM architect to address Data collection for its data analytics lake. The requirement is to address the control objective while minimizing irreversible action until facts and authority are established. What should the organization do FIRST? The asset inventory records 23,000 records across production and backup locations.

  1. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  2. Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles.
  3. Retain assets only as long as business, legal, and regulatory requirements justify, and replace or retire unsupported assets through a controlled process.
  4. Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner.

Correct answer: B

Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data collection while minimizing irreversible action until facts and authority are established.

Option review:

A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Data collection in this scenario.

B: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data collection while minimizing irreversible action until facts and authority are established.

C: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Data collection in this scenario.

D: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Data collection in this scenario.

Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.

Question 3

Litware Services is revising controls for its branch-office network. A review highlights Data location. The application security architect must address the control objective while preserving evidence needed for later review. Which action is the BEST next step? The asset inventory records 40,000 records across production and backup locations.

  1. Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles.
  2. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  3. Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner.
  4. Define handling rules that follow the asset classification through access, storage, transmission, sharing, and disposal.

Correct answer: A

Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data location while preserving evidence needed for later review.

Option review:

A: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data location while preserving evidence needed for later review.

B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Data location in this scenario.

C: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Data location in this scenario.

D: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Data location in this scenario.

Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.

Question 4

An auditor asks Humongous Insurance to demonstrate how it handles Data maintenance in the industrial control network. The incident response manager must address the control objective without granting broader privilege than the business need requires. Which response is MOST appropriate? The asset inventory records 57,000 records across production and backup locations.

  1. Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner.
  2. Select data controls according to classification, data state, scope, and compliance needs, using DLP, DRM, CASB, encryption, or other controls where they fit.
  3. Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles.
  4. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.

Correct answer: C

Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data maintenance without granting broader privilege than the business need requires.

Option review:

A: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Data maintenance in this scenario.

B: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. That action can be useful in a different security decision, but it does not most directly address Data maintenance in this scenario.

C: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data maintenance without granting broader privilege than the business need requires.

D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Data maintenance in this scenario.

Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.

Question 5

After a business change, Woodgrove Bank discovers that Data retention is not handled consistently for the research data repository. The security governance lead needs to address the control objective without creating a new single point of failure. Which recommendation BEST addresses the issue? The asset inventory records 74,000 records across production and backup locations.

  1. Select data controls according to classification, data state, scope, and compliance needs, using DLP, DRM, CASB, encryption, or other controls where they fit.
  2. Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles.
  3. Establish ownership, inventory the asset, assign accountability, and provision it through an approved secure process before production use.
  4. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.

Correct answer: B

Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data retention without creating a new single point of failure.

Option review:

A: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. That action can be useful in a different security decision, but it does not most directly address Data retention in this scenario.

B: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data retention without creating a new single point of failure.

C: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. That action can be useful in a different security decision, but it does not most directly address Data retention in this scenario.

D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Data retention in this scenario.

Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.

Question 6

Relecloud Systems is preparing a security decision for the payment processing service. The decision involves Data remanence. The IAM architect must address the control objective while ensuring that emergency access cannot become permanent access. Which option BEST reflects CISSP-level security practice? The asset inventory records 91,000 records across production and backup locations.

  1. Establish ownership, inventory the asset, assign accountability, and provision it through an approved secure process before production use.
  2. Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner.
  3. Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles.
  4. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.

Correct answer: C

Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data remanence while ensuring that emergency access cannot become permanent access.

Option review:

A: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. That action can be useful in a different security decision, but it does not most directly address Data remanence in this scenario.

B: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Data remanence in this scenario.

C: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data remanence while ensuring that emergency access cannot become permanent access.

D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Data remanence in this scenario.

Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.

Question 7

During a risk workshop for the software delivery pipeline, the team identifies Data destruction as the deciding issue. The application security architect is expected to address the control objective while allowing independent verification of the control outcome. What is the MOST appropriate course of action? The asset inventory records 17,000 records across production and backup locations.

  1. Establish ownership, inventory the asset, assign accountability, and provision it through an approved secure process before production use.
  2. Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles.
  3. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  4. Retain assets only as long as business, legal, and regulatory requirements justify, and replace or retire unsupported assets through a controlled process.

Correct answer: B

Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data destruction while allowing independent verification of the control outcome.

Option review:

A: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. That action can be useful in a different security decision, but it does not most directly address Data destruction in this scenario.

B: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data destruction while allowing independent verification of the control outcome.

C: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Data destruction in this scenario.

D: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Data destruction in this scenario.

Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.

Question 8

A control owner at Lucerne Publishing proposes a quick technical fix for Data roles including owners, controllers, custodians, processors, users, and subjects in the AI-assisted customer service platform. The incident response manager must address the control objective while accounting for third-party and lifecycle dependencies. What should happen FIRST? The asset inventory records 34,000 records across production and backup locations.

  1. Define handling rules that follow the asset classification through access, storage, transmission, sharing, and disposal.
  2. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  3. Select data controls according to classification, data state, scope, and compliance needs, using DLP, DRM, CASB, encryption, or other controls where they fit.
  4. Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles.

Correct answer: D

Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data roles including owners, controllers, custodians, processors, users, and subjects while accounting for third-party and lifecycle dependencies.

Option review:

A: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Data roles including owners, controllers, custodians, processors, users, and subjects in this scenario.

B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Data roles including owners, controllers, custodians, processors, users, and subjects in this scenario.

C: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. That action can be useful in a different security decision, but it does not most directly address Data roles including owners, controllers, custodians, processors, users, and subjects in this scenario.

D: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data roles including owners, controllers, custodians, processors, users, and subjects while accounting for third-party and lifecycle dependencies.

Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.

Question 9

Lamna Healthcare is standardizing security across several business units. The global collaboration platform raises a question about Data collection. The security governance lead needs to address the control objective while maintaining the organization’s stated risk appetite. Which action provides the BEST governance and security outcome? The asset inventory records 51,000 records across production and backup locations.

  1. Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles.
  2. Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner.
  3. Retain assets only as long as business, legal, and regulatory requirements justify, and replace or retire unsupported assets through a controlled process.
  4. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.

Correct answer: A

Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data collection while maintaining the organization’s stated risk appetite.

Option review:

A: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data collection while maintaining the organization’s stated risk appetite.

B: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Data collection in this scenario.

C: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Data collection in this scenario.

D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Data collection in this scenario.

Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.

Question 10

During a identity modernization project, Fourth Coffee asks the IAM architect to address Data location for its e-commerce application. The requirement is to address the control objective while meeting the business objective with the least unnecessary operational complexity. What should the organization do FIRST? The asset inventory records 68,000 records across production and backup locations.

  1. Retain assets only as long as business, legal, and regulatory requirements justify, and replace or retire unsupported assets through a controlled process.
  2. Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner.
  3. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  4. Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles.

Correct answer: D

Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data location while meeting the business objective with the least unnecessary operational complexity.

Option review:

A: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Data location in this scenario.

B: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Data location in this scenario.

C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Data location in this scenario.

D: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data location while meeting the business objective with the least unnecessary operational complexity.

Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.

Question 11

Consolidated Messenger is revising controls for its clinical records environment. A review highlights Data maintenance. The application security architect must address the control objective while keeping the control sustainable for normal operations. Which action is the BEST next step? The asset inventory records 85,000 records across production and backup locations.

  1. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  2. Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner.
  3. Select data controls according to classification, data state, scope, and compliance needs, using DLP, DRM, CASB, encryption, or other controls where they fit.
  4. Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles.

Correct answer: D

Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data maintenance while keeping the control sustainable for normal operations.

Option review:

A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Data maintenance in this scenario.

B: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Data maintenance in this scenario.

C: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. That action can be useful in a different security decision, but it does not most directly address Data maintenance in this scenario.

D: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data maintenance while keeping the control sustainable for normal operations.

Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.

Question 12

An auditor asks Proseware Labs to demonstrate how it handles Data retention in the remote access service. The incident response manager must address the control objective while ensuring the decision can be repeated consistently across business units. Which response is MOST appropriate? The asset inventory records 11,000 records across production and backup locations.

  1. Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner.
  2. Retain assets only as long as business, legal, and regulatory requirements justify, and replace or retire unsupported assets through a controlled process.
  3. Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles.
  4. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.

Correct answer: C

Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data retention while ensuring the decision can be repeated consistently across business units.

Option review:

A: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Data retention in this scenario.

B: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Data retention in this scenario.

C: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data retention while ensuring the decision can be repeated consistently across business units.

D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Data retention in this scenario.

Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.

Question 13

After a business change, Southridge Media discovers that Data remanence is not handled consistently for the customer identity platform. The security governance lead needs to address the control objective while preserving clear accountability and audit evidence. Which recommendation BEST addresses the issue? The asset inventory records 28,000 records across production and backup locations.

  1. Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles.
  2. Define handling rules that follow the asset classification through access, storage, transmission, sharing, and disposal.
  3. Establish ownership, inventory the asset, assign accountability, and provision it through an approved secure process before production use.
  4. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.

Correct answer: A

Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data remanence while preserving clear accountability and audit evidence.

Option review:

A: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data remanence while preserving clear accountability and audit evidence.

B: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Data remanence in this scenario.

C: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. That action can be useful in a different security decision, but it does not most directly address Data remanence in this scenario.

D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Data remanence in this scenario.

Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.

Question 14

Adventure Works is preparing a security decision for the data analytics lake. The decision involves Data destruction. The IAM architect must address the control objective while protecting sensitive data throughout the change. Which option BEST reflects CISSP-level security practice? The asset inventory records 45,000 records across production and backup locations.

  1. Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles.
  2. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  3. Select data controls according to classification, data state, scope, and compliance needs, using DLP, DRM, CASB, encryption, or other controls where they fit.
  4. Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner.

Correct answer: A

Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data destruction while protecting sensitive data throughout the change.

Option review:

A: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data destruction while protecting sensitive data throughout the change.

B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Data destruction in this scenario.

C: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. That action can be useful in a different security decision, but it does not most directly address Data destruction in this scenario.

D: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Data destruction in this scenario.

Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.

Question 15

During a risk workshop for the branch-office network, the team identifies Data roles including owners, controllers, custodians, processors, users, and subjects as the deciding issue. The application security architect is expected to address the control objective while preserving availability of the critical business service. What is the MOST appropriate course of action? The asset inventory records 62,000 records across production and backup locations.

  1. Retain assets only as long as business, legal, and regulatory requirements justify, and replace or retire unsupported assets through a controlled process.
  2. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  3. Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles.
  4. Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner.

Correct answer: C

Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data roles including owners, controllers, custodians, processors, users, and subjects while preserving availability of the critical business service.

Option review:

A: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Data roles including owners, controllers, custodians, processors, users, and subjects in this scenario.

B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Data roles including owners, controllers, custodians, processors, users, and subjects in this scenario.

C: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data roles including owners, controllers, custodians, processors, users, and subjects while preserving availability of the critical business service.

D: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Data roles including owners, controllers, custodians, processors, users, and subjects in this scenario.

Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.

Question 16

A control owner at Northwind Health proposes a quick technical fix for Data collection in the industrial control network. The incident response manager must address the control objective without replacing governance with a technology-only shortcut. What should happen FIRST? The asset inventory records 79,000 records across production and backup locations.

  1. Select data controls according to classification, data state, scope, and compliance needs, using DLP, DRM, CASB, encryption, or other controls where they fit.
  2. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  3. Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles.
  4. Define handling rules that follow the asset classification through access, storage, transmission, sharing, and disposal.

Correct answer: C

Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data collection without replacing governance with a technology-only shortcut.

Option review:

A: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. That action can be useful in a different security decision, but it does not most directly address Data collection in this scenario.

B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Data collection in this scenario.

C: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data collection without replacing governance with a technology-only shortcut.

D: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Data collection in this scenario.

Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.

Question 17

Coho Insurance is standardizing security across several business units. The research data repository raises a question about Data location. The security governance lead needs to address the control objective while keeping the process defensible to auditors and business owners. Which action provides the BEST governance and security outcome? The asset inventory records 5,000 records across production and backup locations.

  1. Retain assets only as long as business, legal, and regulatory requirements justify, and replace or retire unsupported assets through a controlled process.
  2. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  3. Establish ownership, inventory the asset, assign accountability, and provision it through an approved secure process before production use.
  4. Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles.

Correct answer: D

Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data location while keeping the process defensible to auditors and business owners.

Option review:

A: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Data location in this scenario.

B: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Data location in this scenario.

C: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. That action can be useful in a different security decision, but it does not most directly address Data location in this scenario.

D: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data location while keeping the process defensible to auditors and business owners.

Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.

Question 18

During a architecture design review, A. Datum Analytics asks the IAM architect to address Data maintenance for its payment processing service. The requirement is to address the control objective while minimizing irreversible action until facts and authority are established. What should the organization do FIRST? The asset inventory records 22,000 records across production and backup locations.

  1. Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner.
  2. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  3. Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles.
  4. Establish ownership, inventory the asset, assign accountability, and provision it through an approved secure process before production use.

Correct answer: C

Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data maintenance while minimizing irreversible action until facts and authority are established.

Option review:

A: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Data maintenance in this scenario.

B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Data maintenance in this scenario.

C: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data maintenance while minimizing irreversible action until facts and authority are established.

D: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. That action can be useful in a different security decision, but it does not most directly address Data maintenance in this scenario.

Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.

Question 19

Blue Yonder Airlines is revising controls for its software delivery pipeline. A review highlights Data retention. The application security architect must address the control objective while preserving evidence needed for later review. Which action is the BEST next step? The asset inventory records 39,000 records across production and backup locations.

  1. Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles.
  2. Define handling rules that follow the asset classification through access, storage, transmission, sharing, and disposal.
  3. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  4. Retain assets only as long as business, legal, and regulatory requirements justify, and replace or retire unsupported assets through a controlled process.

Correct answer: A

Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data retention while preserving evidence needed for later review.

Option review:

A: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data retention while preserving evidence needed for later review.

B: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Data retention in this scenario.

C: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Data retention in this scenario.

D: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Data retention in this scenario.

Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.

Question 20

An auditor asks City Power to demonstrate how it handles Data remanence in the AI-assisted customer service platform. The incident response manager must address the control objective without granting broader privilege than the business need requires. Which response is MOST appropriate? The asset inventory records 56,000 records across production and backup locations.

  1. Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles.
  2. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  3. Define handling rules that follow the asset classification through access, storage, transmission, sharing, and disposal.
  4. Retain assets only as long as business, legal, and regulatory requirements justify, and replace or retire unsupported assets through a controlled process.

Correct answer: A

Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data remanence without granting broader privilege than the business need requires.

Option review:

A: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data remanence without granting broader privilege than the business need requires.

B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Data remanence in this scenario.

C: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Data remanence in this scenario.

D: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Data remanence in this scenario.

Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.

Question 21

After a business change, Tailspin Logistics discovers that Data roles including owners, controllers, custodians, processors, users, and subjects is not handled consistently for the global collaboration platform. The security governance lead needs to address the control objective without creating a new single point of failure. Which recommendation BEST addresses the issue? The asset inventory records 73,000 records across production and backup locations.

  1. Retain assets only as long as business, legal, and regulatory requirements justify, and replace or retire unsupported assets through a controlled process.
  2. Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles.
  3. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  4. Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner.

Correct answer: B

Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data roles including owners, controllers, custodians, processors, users, and subjects without creating a new single point of failure.

Option review:

A: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Data roles including owners, controllers, custodians, processors, users, and subjects in this scenario.

B: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data roles including owners, controllers, custodians, processors, users, and subjects without creating a new single point of failure.

C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Data roles including owners, controllers, custodians, processors, users, and subjects in this scenario.

D: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Data roles including owners, controllers, custodians, processors, users, and subjects in this scenario.

Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.

Question 22

Alpine Sports is preparing a security decision for the e-commerce application. The decision involves Data collection. The IAM architect must address the control objective while ensuring that emergency access cannot become permanent access. Which option BEST reflects CISSP-level security practice? The asset inventory records 90,000 records across production and backup locations.

  1. Define handling rules that follow the asset classification through access, storage, transmission, sharing, and disposal.
  2. Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles.
  3. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  4. Retain assets only as long as business, legal, and regulatory requirements justify, and replace or retire unsupported assets through a controlled process.

Correct answer: B

Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data collection while ensuring that emergency access cannot become permanent access.

Option review:

A: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Data collection in this scenario.

B: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data collection while ensuring that emergency access cannot become permanent access.

C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Data collection in this scenario.

D: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Data collection in this scenario.

Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.

Question 23

During a risk workshop for the clinical records environment, the team identifies Data location as the deciding issue. The application security architect is expected to address the control objective while allowing independent verification of the control outcome. What is the MOST appropriate course of action? The asset inventory records 16,000 records across production and backup locations.

  1. Define handling rules that follow the asset classification through access, storage, transmission, sharing, and disposal.
  2. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  3. Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles.
  4. Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner.

Correct answer: C

Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data location while allowing independent verification of the control outcome.

Option review:

A: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Data location in this scenario.

B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Data location in this scenario.

C: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data location while allowing independent verification of the control outcome.

D: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Data location in this scenario.

Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.

Question 24

A control owner at Trey Research proposes a quick technical fix for Data maintenance in the remote access service. The incident response manager must address the control objective while accounting for third-party and lifecycle dependencies. What should happen FIRST? The asset inventory records 33,000 records across production and backup locations.

  1. Select data controls according to classification, data state, scope, and compliance needs, using DLP, DRM, CASB, encryption, or other controls where they fit.
  2. Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles.
  3. Retain assets only as long as business, legal, and regulatory requirements justify, and replace or retire unsupported assets through a controlled process.
  4. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.

Correct answer: B

Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data maintenance while accounting for third-party and lifecycle dependencies.

Option review:

A: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. That action can be useful in a different security decision, but it does not most directly address Data maintenance in this scenario.

B: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data maintenance while accounting for third-party and lifecycle dependencies.

C: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Data maintenance in this scenario.

D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Data maintenance in this scenario.

Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.

Question 25

Margie Travel is standardizing security across several business units. The customer identity platform raises a question about Data retention. The security governance lead needs to address the control objective while maintaining the organization’s stated risk appetite. Which action provides the BEST governance and security outcome? The asset inventory records 50,000 records across production and backup locations.

  1. Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner.
  2. Select data controls according to classification, data state, scope, and compliance needs, using DLP, DRM, CASB, encryption, or other controls where they fit.
  3. Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles.
  4. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.

Correct answer: C

Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data retention while maintaining the organization’s stated risk appetite.

Option review:

A: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Data retention in this scenario.

B: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. That action can be useful in a different security decision, but it does not most directly address Data retention in this scenario.

C: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data retention while maintaining the organization’s stated risk appetite.

D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Data retention in this scenario.

Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.

Question 26

During a internal audit response, Wide World Importers asks the IAM architect to address Data remanence for its data analytics lake. The requirement is to address the control objective while meeting the business objective with the least unnecessary operational complexity. What should the organization do FIRST? The asset inventory records 67,000 records across production and backup locations.

  1. Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner.
  2. Establish ownership, inventory the asset, assign accountability, and provision it through an approved secure process before production use.
  3. Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles.
  4. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.

Correct answer: C

Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data remanence while meeting the business objective with the least unnecessary operational complexity.

Option review:

A: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Data remanence in this scenario.

B: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. That action can be useful in a different security decision, but it does not most directly address Data remanence in this scenario.

C: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data remanence while meeting the business objective with the least unnecessary operational complexity.

D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Data remanence in this scenario.

Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.

Question 27

Bellows University is revising controls for its branch-office network. A review highlights Data destruction. The application security architect must address the control objective while keeping the control sustainable for normal operations. Which action is the BEST next step? The asset inventory records 84,000 records across production and backup locations.

  1. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  2. Establish ownership, inventory the asset, assign accountability, and provision it through an approved secure process before production use.
  3. Select data controls according to classification, data state, scope, and compliance needs, using DLP, DRM, CASB, encryption, or other controls where they fit.
  4. Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles.

Correct answer: D

Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data destruction while keeping the control sustainable for normal operations.

Option review:

A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Data destruction in this scenario.

B: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. That action can be useful in a different security decision, but it does not most directly address Data destruction in this scenario.

C: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. That action can be useful in a different security decision, but it does not most directly address Data destruction in this scenario.

D: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data destruction while keeping the control sustainable for normal operations.

Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.

Popular posts

img