Courseiva

CAS-004 Governance, Risk, and Compliance Practice Question

A security architect is designing a new system that will process personal data of European Union citizens. The architect must ensure that data protection principles are embedded into the design. Which of the following best exemplifies the principle of data minimization under the General Data Protection Regulation (GDPR)?

⚠ Common exam trap

The trap here is conflating data minimization with other GDPR principles like storage limitation, security of processing, or lawful basis, which address different aspects of data protection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Collecting only the personal data that is necessary for the specified purpose

Data minimization under GDPR means collecting and processing only the personal data that is necessary for the intended purpose. This principle is about limiting the scope of data collection, not about security measures, legal bases, or retention periods. The other options represent different GDPR principles or requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Encrypting all personal data at rest and in transit

    Why it's wrong here

    Encryption is a security measure that protects data confidentiality but does not relate to data minimization. Data minimization is about limiting the amount of data collected and retained, not about how it is protected. Encryption is important for GDPR compliance under Article 32, but it is not an example of minimization.

  • ✗

    Obtaining explicit consent before processing personal data

    Why it's wrong here

    Obtaining consent is a legal basis for processing under GDPR, but it is not related to data minimization. Consent ensures lawful processing but does not limit the amount of data collected. Data minimization focuses on collecting only what is necessary, regardless of the legal basis for processing.

  • ✓

    Collecting only the personal data that is necessary for the specified purpose

    Why this is correct

    Data minimization under GDPR requires that personal data be adequate, relevant, and limited to what is necessary for the purposes for which it is processed. Collecting only necessary data directly implements this principle. This approach reduces privacy risks and is a core requirement of GDPR Article 5(1)(c).

  • ✗

    Implementing a retention schedule to delete data after a set period

    Why it's wrong here

    A retention schedule addresses the storage limitation principle, which requires data to be kept no longer than necessary. While related to data protection, it is distinct from data minimization, which is about limiting collection to what is necessary. Retention schedules are important but do not exemplify minimization.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.