Courseiva
Asset Security →hardMultiple Choice

CISSP Asset Security Practice Question

A company has a data retention policy requiring customer transaction records to be kept for 7 years. After 7 years, the data should be destroyed. Which phase of the data lifecycle governs this action?

⚠ Common exam trap

CISSP often tests the confusion between archiving and destruction; candidates may think archiving implies eventual destruction, but archiving is a separate phase focused on long-term retention, while destruction is the final, irreversible step.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Destroy

The destroy phase of the data lifecycle explicitly governs the secure disposal of data once its retention period ends. In this scenario, after 7 years, the policy mandates destruction, so the action falls under the Destroy phase. This phase ensures data is irrecoverable and compliant with legal and regulatory requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use

    Why it's wrong here

    Using customer data involves active processing, such as accessing, modifying, or analyzing it for business operations. While essential during the data's active lifecycle, 'use' does not represent the final disposition required by a retention policy once the specified period has expired. This action pertains to ongoing utility, not the mandated elimination of data.

  • ✗

    Share

    Why it's wrong here

    Sharing customer data involves transmitting or disclosing it to internal or external parties, often for collaborative purposes or service delivery. This action is a form of data transfer or disclosure that occurs during the data's operational phase, not the terminal phase where data must be permanently removed. Sharing extends data's reach rather than fulfilling a destruction requirement.

  • ✗

    Archive

    Why it's wrong here

    Archiving customer data involves moving it to long-term, often less accessible, storage for compliance, historical record-keeping, or future reference. While archiving preserves data for an extended period, it is a storage method, not a destruction method. Destruction is the subsequent, final step that occurs *after* the archiving and retention periods have both concluded, rendering the data unrecoverable.

  • ✓

    Destroy

    Why this is correct

    Destroying customer data is the definitive and irreversible process of rendering information unreadable and unrecoverable from all storage media. This action directly fulfills a data retention policy's requirement to eliminate data once its specified retention period has expired, ensuring compliance and mitigating future risks. Proper destruction methods prevent unauthorized access or recovery of sensitive information.

About these practice questions

One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.