Courseiva
Security Program Management and OversighteasyMultiple SelectObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

A records clerk finds paper forms containing customer identifiers. The retention period has expired, and no legal hold applies. Which two actions are appropriate next? Select two.

⚠ Common exam trap

Many candidates assume that simply because the retention period has expired, immediate destruction is always the correct next step, overlooking the critical verification step to ensure no legal hold is in place.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Verify that the retention schedule has been satisfied and no hold exists

Before disposing of any records, the records clerk must confirm that the retention period has fully elapsed and that no legal hold (such as a litigation hold or regulatory hold) is active. This verification step ensures compliance with organizational data governance policies and avoids spoliation of evidence. Option B is correct because once verification is complete, the approved disposal method (e.g., cross-cut shredding, incineration, or secure shredding service) must be used to render the customer identifiers irrecoverable, aligning with data minimization and privacy requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Verify that the retention schedule has been satisfied and no hold exists

    Why this is correct

    Before destroying any record, the clerk must confirm both the retention schedule's minimum period has elapsed and that no legal, regulatory, or internal hold is currently active. Checking for holds is critical because a pending audit, litigation, or investigation suspends the right to dispose of records, even if the retention date has passed. Premature destruction under a hold could result in spoliation sanctions and severe legal penalties. This verification step is the gatekeeper that makes the subsequent disposal legally defensible.

  • Destroy the forms using the organization's approved disposal method

    Why this is correct

    Approved disposal methods for paper records typically include cross-cut shredding, pulverization, or secure incineration, all of which render the information unrecoverable. These methods are designed to prevent dumpster-diving attacks and identity theft by ensuring customer PII cannot be reconstructed from fragments. The clerk should follow the organization's documented disposal procedures and, in many cases, complete a destruction log or certificate to maintain an audit trail. Using any method outside the approved list exposes the organization to data breach liability.

  • Keep the forms in a personal desk drawer until someone asks for them

    Why it's wrong here

    Holding expired records in a personal desk drawer is an ad-hoc, unauthorized practice that bypasses the records management system. This action extends the retention period beyond the approved schedule, increasing the window of exposure for sensitive customer data and violating data minimization principles. It also removes the record from the custody controls and access logging that a proper records repository provides, making the information more vulnerable to loss, theft, or unauthorized viewing. If the records are later needed, there is no evidence they were managed per policy.

  • Take the papers home for safe keeping before shredding later

    Why it's wrong here

    Taking customer records home creates an unsanctioned chain of custody break and exposes the data to risks outside the organization's security boundary. Even if the clerk intends to shred the papers later, the transportation and temporary storage at a personal residence introduce substantial opportunities for loss, theft, or accidental disclosure. This action is especially problematic for PII because it circumvents physical and technical safeguards mandated by privacy regulations. The only compliant path is to destroy the records on-site using approved equipment or to deliver them through a vetted, audited disposal vendor.

  • Refile the forms in an archive cabinet because they are old records

    Why it's wrong here

    Refiling old records into an archive cabinet assumes that age alone makes a record worth preserving, which misinterprets the retention schedule. If the mandated retention period has passed and no hold applies, the record is designated for destruction, not continued storage. Archiving expired records needlessly prolongs the lifecycle of personal data, inflates storage costs, and increases the organization's compliance burden under privacy laws that require data minimization. The proper action for an expired record with no hold is disposal, not relocation.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.