ISC2 CISSP Data Roles Collection Retention And Destruction Practice Test
2 Asset Security • 27 original questions
This CISSP practice test focuses on data roles collection retention and destruction through original scenario-based questions aligned to the current ISC2 CISSP Certification Exam Outline. Use the full ExamSnap CISSP collection for practice across all eight domains. For broader exam preparation, review the ISC2 CISSP Exam Dumps page.
Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.
Wide World Importers is standardizing security across several business units. The customer identity platform raises a question about Data roles including owners, controllers, custodians, processors, users, and subjects. The security governance lead needs to address the control objective while keeping the process defensible to auditors and business owners. Which action provides the BEST governance and security outcome? The asset inventory records 6,000 records across production and backup locations.
Correct answer: D
Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data roles including owners, controllers, custodians, processors, users, and subjects while keeping the process defensible to auditors and business owners.
Option review:
A: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Data roles including owners, controllers, custodians, processors, users, and subjects in this scenario.
B: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Data roles including owners, controllers, custodians, processors, users, and subjects in this scenario.
C: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Data roles including owners, controllers, custodians, processors, users, and subjects in this scenario.
D: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data roles including owners, controllers, custodians, processors, users, and subjects while keeping the process defensible to auditors and business owners.
Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.
During a internal audit response, Bellows University asks the IAM architect to address Data collection for its data analytics lake. The requirement is to address the control objective while minimizing irreversible action until facts and authority are established. What should the organization do FIRST? The asset inventory records 23,000 records across production and backup locations.
Correct answer: B
Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data collection while minimizing irreversible action until facts and authority are established.
Option review:
A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Data collection in this scenario.
B: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data collection while minimizing irreversible action until facts and authority are established.
C: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Data collection in this scenario.
D: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Data collection in this scenario.
Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.
Litware Services is revising controls for its branch-office network. A review highlights Data location. The application security architect must address the control objective while preserving evidence needed for later review. Which action is the BEST next step? The asset inventory records 40,000 records across production and backup locations.
Correct answer: A
Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data location while preserving evidence needed for later review.
Option review:
A: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data location while preserving evidence needed for later review.
B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Data location in this scenario.
C: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Data location in this scenario.
D: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Data location in this scenario.
Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.
An auditor asks Humongous Insurance to demonstrate how it handles Data maintenance in the industrial control network. The incident response manager must address the control objective without granting broader privilege than the business need requires. Which response is MOST appropriate? The asset inventory records 57,000 records across production and backup locations.
Correct answer: C
Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data maintenance without granting broader privilege than the business need requires.
Option review:
A: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Data maintenance in this scenario.
B: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. That action can be useful in a different security decision, but it does not most directly address Data maintenance in this scenario.
C: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data maintenance without granting broader privilege than the business need requires.
D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Data maintenance in this scenario.
Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.
After a business change, Woodgrove Bank discovers that Data retention is not handled consistently for the research data repository. The security governance lead needs to address the control objective without creating a new single point of failure. Which recommendation BEST addresses the issue? The asset inventory records 74,000 records across production and backup locations.
Correct answer: B
Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data retention without creating a new single point of failure.
Option review:
A: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. That action can be useful in a different security decision, but it does not most directly address Data retention in this scenario.
B: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data retention without creating a new single point of failure.
C: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. That action can be useful in a different security decision, but it does not most directly address Data retention in this scenario.
D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Data retention in this scenario.
Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.
Relecloud Systems is preparing a security decision for the payment processing service. The decision involves Data remanence. The IAM architect must address the control objective while ensuring that emergency access cannot become permanent access. Which option BEST reflects CISSP-level security practice? The asset inventory records 91,000 records across production and backup locations.
Correct answer: C
Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data remanence while ensuring that emergency access cannot become permanent access.
Option review:
A: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. That action can be useful in a different security decision, but it does not most directly address Data remanence in this scenario.
B: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Data remanence in this scenario.
C: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data remanence while ensuring that emergency access cannot become permanent access.
D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Data remanence in this scenario.
Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.
During a risk workshop for the software delivery pipeline, the team identifies Data destruction as the deciding issue. The application security architect is expected to address the control objective while allowing independent verification of the control outcome. What is the MOST appropriate course of action? The asset inventory records 17,000 records across production and backup locations.
Correct answer: B
Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data destruction while allowing independent verification of the control outcome.
Option review:
A: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. That action can be useful in a different security decision, but it does not most directly address Data destruction in this scenario.
B: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data destruction while allowing independent verification of the control outcome.
C: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Data destruction in this scenario.
D: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Data destruction in this scenario.
Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.
A control owner at Lucerne Publishing proposes a quick technical fix for Data roles including owners, controllers, custodians, processors, users, and subjects in the AI-assisted customer service platform. The incident response manager must address the control objective while accounting for third-party and lifecycle dependencies. What should happen FIRST? The asset inventory records 34,000 records across production and backup locations.
Correct answer: D
Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data roles including owners, controllers, custodians, processors, users, and subjects while accounting for third-party and lifecycle dependencies.
Option review:
A: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Data roles including owners, controllers, custodians, processors, users, and subjects in this scenario.
B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Data roles including owners, controllers, custodians, processors, users, and subjects in this scenario.
C: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. That action can be useful in a different security decision, but it does not most directly address Data roles including owners, controllers, custodians, processors, users, and subjects in this scenario.
D: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data roles including owners, controllers, custodians, processors, users, and subjects while accounting for third-party and lifecycle dependencies.
Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.
Lamna Healthcare is standardizing security across several business units. The global collaboration platform raises a question about Data collection. The security governance lead needs to address the control objective while maintaining the organization’s stated risk appetite. Which action provides the BEST governance and security outcome? The asset inventory records 51,000 records across production and backup locations.
Correct answer: A
Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data collection while maintaining the organization’s stated risk appetite.
Option review:
A: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data collection while maintaining the organization’s stated risk appetite.
B: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Data collection in this scenario.
C: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Data collection in this scenario.
D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Data collection in this scenario.
Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.
During a identity modernization project, Fourth Coffee asks the IAM architect to address Data location for its e-commerce application. The requirement is to address the control objective while meeting the business objective with the least unnecessary operational complexity. What should the organization do FIRST? The asset inventory records 68,000 records across production and backup locations.
Correct answer: D
Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data location while meeting the business objective with the least unnecessary operational complexity.
Option review:
A: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Data location in this scenario.
B: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Data location in this scenario.
C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Data location in this scenario.
D: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data location while meeting the business objective with the least unnecessary operational complexity.
Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.
Consolidated Messenger is revising controls for its clinical records environment. A review highlights Data maintenance. The application security architect must address the control objective while keeping the control sustainable for normal operations. Which action is the BEST next step? The asset inventory records 85,000 records across production and backup locations.
Correct answer: D
Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data maintenance while keeping the control sustainable for normal operations.
Option review:
A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Data maintenance in this scenario.
B: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Data maintenance in this scenario.
C: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. That action can be useful in a different security decision, but it does not most directly address Data maintenance in this scenario.
D: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data maintenance while keeping the control sustainable for normal operations.
Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.
An auditor asks Proseware Labs to demonstrate how it handles Data retention in the remote access service. The incident response manager must address the control objective while ensuring the decision can be repeated consistently across business units. Which response is MOST appropriate? The asset inventory records 11,000 records across production and backup locations.
Correct answer: C
Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data retention while ensuring the decision can be repeated consistently across business units.
Option review:
A: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Data retention in this scenario.
B: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Data retention in this scenario.
C: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data retention while ensuring the decision can be repeated consistently across business units.
D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Data retention in this scenario.
Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.
After a business change, Southridge Media discovers that Data remanence is not handled consistently for the customer identity platform. The security governance lead needs to address the control objective while preserving clear accountability and audit evidence. Which recommendation BEST addresses the issue? The asset inventory records 28,000 records across production and backup locations.
Correct answer: A
Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data remanence while preserving clear accountability and audit evidence.
Option review:
A: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data remanence while preserving clear accountability and audit evidence.
B: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Data remanence in this scenario.
C: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. That action can be useful in a different security decision, but it does not most directly address Data remanence in this scenario.
D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Data remanence in this scenario.
Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.
Adventure Works is preparing a security decision for the data analytics lake. The decision involves Data destruction. The IAM architect must address the control objective while protecting sensitive data throughout the change. Which option BEST reflects CISSP-level security practice? The asset inventory records 45,000 records across production and backup locations.
Correct answer: A
Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data destruction while protecting sensitive data throughout the change.
Option review:
A: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data destruction while protecting sensitive data throughout the change.
B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Data destruction in this scenario.
C: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. That action can be useful in a different security decision, but it does not most directly address Data destruction in this scenario.
D: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Data destruction in this scenario.
Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.
During a risk workshop for the branch-office network, the team identifies Data roles including owners, controllers, custodians, processors, users, and subjects as the deciding issue. The application security architect is expected to address the control objective while preserving availability of the critical business service. What is the MOST appropriate course of action? The asset inventory records 62,000 records across production and backup locations.
Correct answer: C
Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data roles including owners, controllers, custodians, processors, users, and subjects while preserving availability of the critical business service.
Option review:
A: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Data roles including owners, controllers, custodians, processors, users, and subjects in this scenario.
B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Data roles including owners, controllers, custodians, processors, users, and subjects in this scenario.
C: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data roles including owners, controllers, custodians, processors, users, and subjects while preserving availability of the critical business service.
D: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Data roles including owners, controllers, custodians, processors, users, and subjects in this scenario.
Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.
A control owner at Northwind Health proposes a quick technical fix for Data collection in the industrial control network. The incident response manager must address the control objective without replacing governance with a technology-only shortcut. What should happen FIRST? The asset inventory records 79,000 records across production and backup locations.
Correct answer: C
Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data collection without replacing governance with a technology-only shortcut.
Option review:
A: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. That action can be useful in a different security decision, but it does not most directly address Data collection in this scenario.
B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Data collection in this scenario.
C: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data collection without replacing governance with a technology-only shortcut.
D: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Data collection in this scenario.
Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.
Coho Insurance is standardizing security across several business units. The research data repository raises a question about Data location. The security governance lead needs to address the control objective while keeping the process defensible to auditors and business owners. Which action provides the BEST governance and security outcome? The asset inventory records 5,000 records across production and backup locations.
Correct answer: D
Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data location while keeping the process defensible to auditors and business owners.
Option review:
A: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Data location in this scenario.
B: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Data location in this scenario.
C: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. That action can be useful in a different security decision, but it does not most directly address Data location in this scenario.
D: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data location while keeping the process defensible to auditors and business owners.
Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.
During a architecture design review, A. Datum Analytics asks the IAM architect to address Data maintenance for its payment processing service. The requirement is to address the control objective while minimizing irreversible action until facts and authority are established. What should the organization do FIRST? The asset inventory records 22,000 records across production and backup locations.
Correct answer: C
Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data maintenance while minimizing irreversible action until facts and authority are established.
Option review:
A: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Data maintenance in this scenario.
B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Data maintenance in this scenario.
C: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data maintenance while minimizing irreversible action until facts and authority are established.
D: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. That action can be useful in a different security decision, but it does not most directly address Data maintenance in this scenario.
Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.
Blue Yonder Airlines is revising controls for its software delivery pipeline. A review highlights Data retention. The application security architect must address the control objective while preserving evidence needed for later review. Which action is the BEST next step? The asset inventory records 39,000 records across production and backup locations.
Correct answer: A
Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data retention while preserving evidence needed for later review.
Option review:
A: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data retention while preserving evidence needed for later review.
B: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Data retention in this scenario.
C: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Data retention in this scenario.
D: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Data retention in this scenario.
Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.
An auditor asks City Power to demonstrate how it handles Data remanence in the AI-assisted customer service platform. The incident response manager must address the control objective without granting broader privilege than the business need requires. Which response is MOST appropriate? The asset inventory records 56,000 records across production and backup locations.
Correct answer: A
Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data remanence without granting broader privilege than the business need requires.
Option review:
A: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data remanence without granting broader privilege than the business need requires.
B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Data remanence in this scenario.
C: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Data remanence in this scenario.
D: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Data remanence in this scenario.
Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.
After a business change, Tailspin Logistics discovers that Data roles including owners, controllers, custodians, processors, users, and subjects is not handled consistently for the global collaboration platform. The security governance lead needs to address the control objective without creating a new single point of failure. Which recommendation BEST addresses the issue? The asset inventory records 73,000 records across production and backup locations.
Correct answer: B
Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data roles including owners, controllers, custodians, processors, users, and subjects without creating a new single point of failure.
Option review:
A: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Data roles including owners, controllers, custodians, processors, users, and subjects in this scenario.
B: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data roles including owners, controllers, custodians, processors, users, and subjects without creating a new single point of failure.
C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Data roles including owners, controllers, custodians, processors, users, and subjects in this scenario.
D: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Data roles including owners, controllers, custodians, processors, users, and subjects in this scenario.
Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.
Alpine Sports is preparing a security decision for the e-commerce application. The decision involves Data collection. The IAM architect must address the control objective while ensuring that emergency access cannot become permanent access. Which option BEST reflects CISSP-level security practice? The asset inventory records 90,000 records across production and backup locations.
Correct answer: B
Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data collection while ensuring that emergency access cannot become permanent access.
Option review:
A: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Data collection in this scenario.
B: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data collection while ensuring that emergency access cannot become permanent access.
C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Data collection in this scenario.
D: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Data collection in this scenario.
Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.
During a risk workshop for the clinical records environment, the team identifies Data location as the deciding issue. The application security architect is expected to address the control objective while allowing independent verification of the control outcome. What is the MOST appropriate course of action? The asset inventory records 16,000 records across production and backup locations.
Correct answer: C
Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data location while allowing independent verification of the control outcome.
Option review:
A: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Data location in this scenario.
B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Data location in this scenario.
C: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data location while allowing independent verification of the control outcome.
D: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Data location in this scenario.
Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.
A control owner at Trey Research proposes a quick technical fix for Data maintenance in the remote access service. The incident response manager must address the control objective while accounting for third-party and lifecycle dependencies. What should happen FIRST? The asset inventory records 33,000 records across production and backup locations.
Correct answer: B
Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data maintenance while accounting for third-party and lifecycle dependencies.
Option review:
A: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. That action can be useful in a different security decision, but it does not most directly address Data maintenance in this scenario.
B: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data maintenance while accounting for third-party and lifecycle dependencies.
C: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Data maintenance in this scenario.
D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Data maintenance in this scenario.
Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.
Margie Travel is standardizing security across several business units. The customer identity platform raises a question about Data retention. The security governance lead needs to address the control objective while maintaining the organization’s stated risk appetite. Which action provides the BEST governance and security outcome? The asset inventory records 50,000 records across production and backup locations.
Correct answer: C
Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data retention while maintaining the organization’s stated risk appetite.
Option review:
A: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Data retention in this scenario.
B: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. That action can be useful in a different security decision, but it does not most directly address Data retention in this scenario.
C: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data retention while maintaining the organization’s stated risk appetite.
D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Data retention in this scenario.
Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.
During a internal audit response, Wide World Importers asks the IAM architect to address Data remanence for its data analytics lake. The requirement is to address the control objective while meeting the business objective with the least unnecessary operational complexity. What should the organization do FIRST? The asset inventory records 67,000 records across production and backup locations.
Correct answer: C
Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data remanence while meeting the business objective with the least unnecessary operational complexity.
Option review:
A: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Data remanence in this scenario.
B: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. That action can be useful in a different security decision, but it does not most directly address Data remanence in this scenario.
C: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data remanence while meeting the business objective with the least unnecessary operational complexity.
D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Data remanence in this scenario.
Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.
Bellows University is revising controls for its branch-office network. A review highlights Data destruction. The application security architect must address the control objective while keeping the control sustainable for normal operations. Which action is the BEST next step? The asset inventory records 84,000 records across production and backup locations.
Correct answer: D
Why: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data destruction while keeping the control sustainable for normal operations.
Option review:
A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Data destruction in this scenario.
B: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. That action can be useful in a different security decision, but it does not most directly address Data destruction in this scenario.
C: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. That action can be useful in a different security decision, but it does not most directly address Data destruction in this scenario.
D: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. It directly addresses Data destruction while keeping the control sustainable for normal operations.
Learning point: Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles. Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities.
Popular posts
Recent Posts
