SY0-701 Security Program Management and Oversight Practice Question
A records clerk finds paper forms containing customer identifiers. The retention period has expired, and no legal hold applies. Which two actions are appropriate next? Select two.
⚠ Common exam trap
Many candidates assume that simply because the retention period has expired, immediate destruction is always the correct next step, overlooking the critical verification step to ensure no legal hold is in place.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify that the retention schedule has been satisfied and no hold exists
Before disposing of any records, the records clerk must confirm that the retention period has fully elapsed and that no legal hold (such as a litigation hold or regulatory hold) is active. This verification step ensures compliance with organizational data governance policies and avoids spoliation of evidence. Option B is correct because once verification is complete, the approved disposal method (e.g., cross-cut shredding, incineration, or secure shredding service) must be used to render the customer identifiers irrecoverable, aligning with data minimization and privacy requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Verify that the retention schedule has been satisfied and no hold exists
Why this is correct
Before destroying any record, the clerk must confirm both the retention schedule's minimum period has elapsed and that no legal, regulatory, or internal hold is currently active. Checking for holds is critical because a pending audit, litigation, or investigation suspends the right to dispose of records, even if the retention date has passed. Premature destruction under a hold could result in spoliation sanctions and severe legal penalties. This verification step is the gatekeeper that makes the subsequent disposal legally defensible.
- ✓
Destroy the forms using the organization's approved disposal method
Why this is correct
Approved disposal methods for paper records typically include cross-cut shredding, pulverization, or secure incineration, all of which render the information unrecoverable. These methods are designed to prevent dumpster-diving attacks and identity theft by ensuring customer PII cannot be reconstructed from fragments. The clerk should follow the organization's documented disposal procedures and, in many cases, complete a destruction log or certificate to maintain an audit trail. Using any method outside the approved list exposes the organization to data breach liability.
- ✗
Keep the forms in a personal desk drawer until someone asks for them
Why it's wrong here
Holding expired records in a personal desk drawer is an ad-hoc, unauthorized practice that bypasses the records management system. This action extends the retention period beyond the approved schedule, increasing the window of exposure for sensitive customer data and violating data minimization principles. It also removes the record from the custody controls and access logging that a proper records repository provides, making the information more vulnerable to loss, theft, or unauthorized viewing. If the records are later needed, there is no evidence they were managed per policy.
- ✗
Take the papers home for safe keeping before shredding later
Why it's wrong here
Taking customer records home creates an unsanctioned chain of custody break and exposes the data to risks outside the organization's security boundary. Even if the clerk intends to shred the papers later, the transportation and temporary storage at a personal residence introduce substantial opportunities for loss, theft, or accidental disclosure. This action is especially problematic for PII because it circumvents physical and technical safeguards mandated by privacy regulations. The only compliant path is to destroy the records on-site using approved equipment or to deliver them through a vetted, audited disposal vendor.
- ✗
Refile the forms in an archive cabinet because they are old records
Why it's wrong here
Refiling old records into an archive cabinet assumes that age alone makes a record worth preserving, which misinterprets the retention schedule. If the mandated retention period has passed and no hold applies, the record is designated for destruction, not continued storage. Archiving expired records needlessly prolongs the lifecycle of personal data, inflates storage costs, and increases the organization's compliance burden under privacy laws that require data minimization. The proper action for an expired record with no hold is disposal, not relocation.
Go deeper
Related to this question
Learn chapter
Compliance and Regulatory Frameworks
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
Key term
General Data Protection Regulation
A European Union law that gives individuals control over their personal data and sets strict rules for how organizations collect, store, and process that data.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.