mediumMultiple ChoiceObjective-mapped
CISSP Practice Question: A financial institution must retain customer…
A financial institution must retain customer transaction records for 7 years. After that, what is the most appropriate action?
⚠ Common exam trap
A common mix-up: candidates confuse 'secure deletion' with 'physical destruction' or 'archiving,' failing to recognize that after the retention period, the primary goal is to eliminate the data securely, not to preserve or transfer it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Securely delete using overwriting
After the 7-year retention period, the most appropriate action is to securely delete the records using overwriting. This ensures that the data is irrecoverable while maintaining compliance with data disposal policies. Overwriting with multiple passes (e.g., using the Gutmann method or DoD 5220.22-M standard) prevents data remanence, which is critical for financial records.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Degauss and physically destroy
Why it's wrong here
Degaussing is highly effective for magnetic media by neutralizing magnetic domains, but it is entirely ineffective for solid-state drives (SSDs) or optical media. Physical destruction, such as shredding or pulverizing, provides the highest assurance for all media types but is often an expensive and environmentally impactful solution when simpler, less destructive methods could suffice. This approach is generally overkill and inefficient for routine data disposal, especially if the media could otherwise be reused.
- ✓
Securely delete using overwriting
Why this is correct
Secure deletion through overwriting involves writing new data, such as zeros, ones, or random patterns, multiple times over the original data's physical location on the storage medium. This process renders the original data irretrievable, even with advanced forensic techniques, effectively meeting data disposal requirements for most regulatory and security standards. It is a cost-effective and widely applicable method for ensuring data confidentiality on reusable storage devices without destroying the media itself.
- ✗
Transfer to a third-party storage vendor
Why it's wrong here
Transferring data to a third-party storage vendor does not constitute data disposal; instead, it merely shifts the custody and responsibility for the data. This action introduces new risks, including potential data breaches during transit, loss of direct control over the data's security posture, and reliance on the vendor's compliance with data retention and disposal policies. The financial institution remains ultimately accountable for the data's lifecycle, making this an inappropriate method for actual data disposal.
- ✗
Archive to tape for additional redundancy
Why it's wrong here
Archiving data to tape, even for additional redundancy, is fundamentally a data *retention* strategy, not a disposal method. This action explicitly preserves the data, potentially beyond its legally or operationally required retention period, which directly contradicts the objective of data disposal. Retaining unnecessary data increases the attack surface, raises compliance risks, and incurs ongoing storage and management costs, making it an inappropriate response to a disposal requirement.
Go deeper
Related to this question
Learn chapter
Asset Security: Privacy and Data Retention
Key term
Data remanence
Data remanence is the residual representation of data that remains on a storage medium even after attempts to erase or remove it.
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.