Courseiva
mediumMultiple ChoiceObjective-mapped

CISSP Practice Question: A multinational corporation must comply with GDPR…

A multinational corporation must comply with GDPR and CCPA. Which data protection strategy should they prioritize?

⚠ Common exam trap

The exam often tests the misconception that encryption or masking alone ensures compliance, but the trap here is that these are security controls, not privacy controls—they do not address the legal requirement to limit data collection, which is the foundational principle of data minimization under both GDPR and CCPA.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Data minimization

Data minimization is the correct priority because both GDPR (Article 5(1)(c)) and CCPA (Cal. Civ. Code §1798.100) require organizations to limit the collection and processing of personal data to what is directly relevant and necessary for the stated purpose. By minimizing the data held, the corporation reduces its legal exposure, simplifies compliance obligations, and inherently lowers the risk of a data breach impacting sensitive information. This principle is foundational to privacy-by-design and directly addresses the regulatory mandates, whereas the other options are secondary controls that do not address the core requirement of limiting data collection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Data masking

    Why it's wrong here

    Hides data for specific purposes but does not reduce overall data collection.

  • Data retention

    Why it's wrong here

    Addresses storage duration, not the fundamental reduction of data.

  • Data encryption

    Why it's wrong here

    Protects data but does not address the principle of collection limitation.

  • Data minimization

    Why this is correct

    Core principle under GDPR and CCPA, reducing data collection and storage.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.