mediumMultiple Choice
CISSP Practice Question: A multinational corporation must comply with GDPR…
A multinational corporation must comply with GDPR and CCPA. Which data protection strategy should they prioritize?
⚠ Common exam trap
The exam often tests the misconception that encryption or masking alone ensures compliance, but the trap here is that these are security controls, not privacy controls—they do not address the legal requirement to limit data collection, which is the foundational principle of data minimization under both GDPR and CCPA.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data minimization
Data minimization is the correct priority because both GDPR (Article 5(1)(c)) and CCPA (Cal. Civ. Code §1798.100) require organizations to limit the collection and processing of personal data to what is directly relevant and necessary for the stated purpose. By minimizing the data held, the corporation reduces its legal exposure, simplifies compliance obligations, and inherently lowers the risk of a data breach impacting sensitive information. This principle is foundational to privacy-by-design and directly addresses the regulatory mandates, whereas the other options are secondary controls that do not address the core requirement of limiting data collection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data masking
Why it's wrong here
Masking obscures data for non-production or analytical use, so it cannot govern live personal data processing across jurisdictions as GDPR and CCPA demand. It is tempting because masking supports data minimisation and privacy by design, and it would be correct when production data must be shared with testers or analysts who should not see real values.
- ✗
Data retention
Why it's wrong here
Retention schedules limit how long data is kept, but they do not address lawful basis, cross-border transfer, or subject access rights that GDPR and CCPA both require. It is tempting because storage limitation is a GDPR principle, and retention would be the priority when the compliance risk is keeping personal data beyond its permitted lifespan.
- ✗
Data encryption
Why it's wrong here
Encryption protects confidentiality at rest and in transit but does not itself satisfy GDPR or CCPA requirements for lawful processing, consent, or data subject rights. It is tempting because encryption is a recognised safeguard under both regimes, and it would be the right priority when the risk is unauthorised disclosure of stored personal data.
- ✓
Data minimization
Why this is correct
Data minimisation directly satisfies both GDPR and CCPA by limiting collection and retention to what is strictly necessary, reducing the regulated data footprint and breach exposure. This single principle addresses the core constraint of complying with two overlapping privacy regimes simultaneously without conflicting obligations.
Go deeper
Related to this question
Learn chapter
Physical Security and Environmental Controls
Key term
Data protection
Data protection refers to the practices and technologies used to safeguard personal and sensitive information from unauthorized access, loss, or corruption.
Key term
Privacy
Privacy in IT is the control over how personal data is collected, stored, used, and shared by systems and organizations.
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.