CAS-004 Governance, Risk, and Compliance Practice Question
A security architect is designing a new system that will process personal data of European Union citizens. The architect must ensure that data protection principles are embedded into the design. Which of the following best exemplifies the principle of data minimization under the General Data Protection Regulation (GDPR)?
⚠ Common exam trap
The trap here is conflating data minimization with other GDPR principles like storage limitation, security of processing, or lawful basis, which address different aspects of data protection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Collecting only the personal data that is necessary for the specified purpose
Data minimization under GDPR means collecting and processing only the personal data that is necessary for the intended purpose. This principle is about limiting the scope of data collection, not about security measures, legal bases, or retention periods. The other options represent different GDPR principles or requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Encrypting all personal data at rest and in transit
Why it's wrong here
Encryption is a security measure that protects data confidentiality but does not relate to data minimization. Data minimization is about limiting the amount of data collected and retained, not about how it is protected. Encryption is important for GDPR compliance under Article 32, but it is not an example of minimization.
- ✗
Obtaining explicit consent before processing personal data
Why it's wrong here
Obtaining consent is a legal basis for processing under GDPR, but it is not related to data minimization. Consent ensures lawful processing but does not limit the amount of data collected. Data minimization focuses on collecting only what is necessary, regardless of the legal basis for processing.
- ✓
Collecting only the personal data that is necessary for the specified purpose
Why this is correct
Data minimization under GDPR requires that personal data be adequate, relevant, and limited to what is necessary for the purposes for which it is processed. Collecting only necessary data directly implements this principle. This approach reduces privacy risks and is a core requirement of GDPR Article 5(1)(c).
- ✗
Implementing a retention schedule to delete data after a set period
Why it's wrong here
A retention schedule addresses the storage limitation principle, which requires data to be kept no longer than necessary. While related to data protection, it is distinct from data minimization, which is about limiting collection to what is necessary. Retention schedules are important but do not exemplify minimization.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.