ISC2 CC Security Principles Practice Question
An online retailer stores customer credit card numbers. Management decides to retain only the last four digits and delete the full numbers after payment authorization. Which security principle does this decision best illustrate?
⚠ Common exam trap
The trap here is equating any reduction in data exposure with least privilege, when the scenario is actually about how much data is collected and retained.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data minimization
The retailer chooses to store only the last four digits and remove the full card number once authorization completes. That reduces the amount of sensitive data held, which is data minimization. Separation of duties concerns dividing tasks, defense in depth concerns layered controls, and least privilege concerns limiting user access, so none of them captures the decision to collect and keep less information.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Defense in depth
Why it's wrong here
Defense in depth layers multiple controls so that if one fails, others still protect the asset. Deleting full card numbers does reduce risk, but the scenario's decision is about how much data to keep rather than how many overlapping safeguards to deploy. The retailer is not adding layers of protection; it is shrinking the data footprint, which is the essence of data minimization instead.
- ✗
Least privilege
Why it's wrong here
Least privilege limits each user's access rights to only what is required for their role. It concerns who can reach systems and data, not how long data is retained or how much of it is stored. The retailer's action of truncating and deleting card numbers is a retention and collection decision, so least privilege does not describe the principle being applied.
- ✗
Separation of duties
Why it's wrong here
Separation of duties divides critical tasks among multiple people so that no single individual can complete a sensitive action alone. The scenario describes reducing the amount of stored card data, not splitting responsibilities across staff. While separation of duties is an important preventive control, it does not address retention limits or the deletion of full card numbers, so it is not the principle illustrated here.
- ✓
Data minimization
Why this is correct
Data minimization means collecting and retaining only the personal data actually needed for a stated purpose. By keeping just the last four digits for customer reference and deleting the full card number after authorization, the retailer reduces the volume of sensitive data at risk and limits potential harm from a breach. This directly matches the principle of not holding more information than necessary.
Go deeper
Related to this question
Learn chapter
Risk Management and Security Controls
Key term
Separation of duties
Separation of duties is a security principle that splits critical tasks and privileges among multiple people to prevent fraud, errors, and abuse of power.
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.