Courseiva
Security Principles →hardMultiple Choice

ISC2 CC Security Principles Practice Question

An online retailer stores customer credit card numbers. Management decides to retain only the last four digits and delete the full numbers after payment authorization. Which security principle does this decision best illustrate?

⚠ Common exam trap

The trap here is equating any reduction in data exposure with least privilege, when the scenario is actually about how much data is collected and retained.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Data minimization

The retailer chooses to store only the last four digits and remove the full card number once authorization completes. That reduces the amount of sensitive data held, which is data minimization. Separation of duties concerns dividing tasks, defense in depth concerns layered controls, and least privilege concerns limiting user access, so none of them captures the decision to collect and keep less information.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Defense in depth

    Why it's wrong here

    Defense in depth layers multiple controls so that if one fails, others still protect the asset. Deleting full card numbers does reduce risk, but the scenario's decision is about how much data to keep rather than how many overlapping safeguards to deploy. The retailer is not adding layers of protection; it is shrinking the data footprint, which is the essence of data minimization instead.

  • ✗

    Least privilege

    Why it's wrong here

    Least privilege limits each user's access rights to only what is required for their role. It concerns who can reach systems and data, not how long data is retained or how much of it is stored. The retailer's action of truncating and deleting card numbers is a retention and collection decision, so least privilege does not describe the principle being applied.

  • ✗

    Separation of duties

    Why it's wrong here

    Separation of duties divides critical tasks among multiple people so that no single individual can complete a sensitive action alone. The scenario describes reducing the amount of stored card data, not splitting responsibilities across staff. While separation of duties is an important preventive control, it does not address retention limits or the deletion of full card numbers, so it is not the principle illustrated here.

  • ✓

    Data minimization

    Why this is correct

    Data minimization means collecting and retaining only the personal data actually needed for a stated purpose. By keeping just the last four digits for customer reference and deleting the full card number after authorization, the retailer reduces the volume of sensitive data at risk and limits potential harm from a breach. This directly matches the principle of not holding more information than necessary.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.