CISSP Asset Security Practice Question
A company has a data retention policy requiring customer transaction records to be kept for 7 years. After 7 years, the data should be destroyed. Which phase of the data lifecycle governs this action?
⚠ Common exam trap
CISSP often tests the confusion between archiving and destruction; candidates may think archiving implies eventual destruction, but archiving is a separate phase focused on long-term retention, while destruction is the final, irreversible step.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Destroy
The destroy phase of the data lifecycle explicitly governs the secure disposal of data once its retention period ends. In this scenario, after 7 years, the policy mandates destruction, so the action falls under the Destroy phase. This phase ensures data is irrecoverable and compliant with legal and regulatory requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use
Why it's wrong here
Using customer data involves active processing, such as accessing, modifying, or analyzing it for business operations. While essential during the data's active lifecycle, 'use' does not represent the final disposition required by a retention policy once the specified period has expired. This action pertains to ongoing utility, not the mandated elimination of data.
- ✗
Share
Why it's wrong here
Sharing customer data involves transmitting or disclosing it to internal or external parties, often for collaborative purposes or service delivery. This action is a form of data transfer or disclosure that occurs during the data's operational phase, not the terminal phase where data must be permanently removed. Sharing extends data's reach rather than fulfilling a destruction requirement.
- ✗
Archive
Why it's wrong here
Archiving customer data involves moving it to long-term, often less accessible, storage for compliance, historical record-keeping, or future reference. While archiving preserves data for an extended period, it is a storage method, not a destruction method. Destruction is the subsequent, final step that occurs *after* the archiving and retention periods have both concluded, rendering the data unrecoverable.
- ✓
Destroy
Why this is correct
Destroying customer data is the definitive and irreversible process of rendering information unreadable and unrecoverable from all storage media. This action directly fulfills a data retention policy's requirement to eliminate data once its specified retention period has expired, ensuring compliance and mitigating future risks. Proper destruction methods prevent unauthorized access or recovery of sensitive information.
Go deeper
Related to this question
Learn chapter
Secure Network Architecture and Components
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
Data retention
Data retention is the practice of keeping data for a specific period to meet legal, business, or compliance needs, and then securely disposing of it.
About these practice questions
One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.