Courseiva
mediumMultiple ChoiceObjective-mapped

CISSP Practice Question: A financial institution must retain customer…

A financial institution must retain customer transaction records for 7 years. After that, what is the most appropriate action?

⚠ Common exam trap

A common mix-up: candidates confuse 'secure deletion' with 'physical destruction' or 'archiving,' failing to recognize that after the retention period, the primary goal is to eliminate the data securely, not to preserve or transfer it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Securely delete using overwriting

After the 7-year retention period, the most appropriate action is to securely delete the records using overwriting. This ensures that the data is irrecoverable while maintaining compliance with data disposal policies. Overwriting with multiple passes (e.g., using the Gutmann method or DoD 5220.22-M standard) prevents data remanence, which is critical for financial records.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Degauss and physically destroy

    Why it's wrong here

    Degaussing is highly effective for magnetic media by neutralizing magnetic domains, but it is entirely ineffective for solid-state drives (SSDs) or optical media. Physical destruction, such as shredding or pulverizing, provides the highest assurance for all media types but is often an expensive and environmentally impactful solution when simpler, less destructive methods could suffice. This approach is generally overkill and inefficient for routine data disposal, especially if the media could otherwise be reused.

  • Securely delete using overwriting

    Why this is correct

    Secure deletion through overwriting involves writing new data, such as zeros, ones, or random patterns, multiple times over the original data's physical location on the storage medium. This process renders the original data irretrievable, even with advanced forensic techniques, effectively meeting data disposal requirements for most regulatory and security standards. It is a cost-effective and widely applicable method for ensuring data confidentiality on reusable storage devices without destroying the media itself.

  • Transfer to a third-party storage vendor

    Why it's wrong here

    Transferring data to a third-party storage vendor does not constitute data disposal; instead, it merely shifts the custody and responsibility for the data. This action introduces new risks, including potential data breaches during transit, loss of direct control over the data's security posture, and reliance on the vendor's compliance with data retention and disposal policies. The financial institution remains ultimately accountable for the data's lifecycle, making this an inappropriate method for actual data disposal.

  • Archive to tape for additional redundancy

    Why it's wrong here

    Archiving data to tape, even for additional redundancy, is fundamentally a data *retention* strategy, not a disposal method. This action explicitly preserves the data, potentially beyond its legally or operationally required retention period, which directly contradicts the objective of data disposal. Retaining unnecessary data increases the attack surface, raises compliance risks, and incurs ongoing storage and management costs, making it an inappropriate response to a disposal requirement.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.