CISSP Asset Security Practice Question
A company has a data retention policy requiring customer transaction records to be kept for 7 years. After 7 years, the data should be destroyed. Which phase of the data lifecycle governs this action?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Destroy
The destroy phase is where data is permanently removed according to retention policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use
Why it's wrong here
Using customer data involves active processing, such as accessing, modifying, or analyzing it for business operations. While essential during the data's active lifecycle, 'use' does not represent the final disposition required by a retention policy once the specified period has expired. This action pertains to ongoing utility, not the mandated elimination of data.
- ✗
Share
Why it's wrong here
Sharing customer data involves transmitting or disclosing it to internal or external parties, often for collaborative purposes or service delivery. This action is a form of data transfer or disclosure that occurs during the data's operational phase, not the terminal phase where data must be permanently removed. Sharing extends data's reach rather than fulfilling a destruction requirement.
- ✗
Archive
Why it's wrong here
Archiving customer data involves moving it to long-term, often less accessible, storage for compliance, historical record-keeping, or future reference. While archiving preserves data for an extended period, it is a storage method, not a destruction method. Destruction is the subsequent, final step that occurs *after* the archiving and retention periods have both concluded, rendering the data unrecoverable.
- ✓
Destroy
Why this is correct
Destroying customer data is the definitive and irreversible process of rendering information unreadable and unrecoverable from all storage media. This action directly fulfills a data retention policy's requirement to eliminate data once its specified retention period has expired, ensuring compliance and mitigating future risks. Proper destruction methods prevent unauthorized access or recovery of sensitive information.
Go deeper
Related to this question
Learn chapter
Asset Security: Privacy and Data Retention
Key term
Retention policy
A retention policy is a set of rules that determines how long an organization keeps its data and what happens to it when the retention period expires.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.