Courseiva
Asset Security →easyMultiple Choice

CISSP Asset Security Practice Question

An organization is implementing a data retention policy. The legal team has determined that certain financial records must be retained for seven years due to regulatory requirements. The IT department is responsible for enforcing the retention and disposal of these records. Which of the following is the most critical factor to consider when implementing the retention policy?

⚠ Common exam trap

The trap here is focusing on operational concerns like cost or backups instead of the compliance-driven need for secure disposal.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verifying that data is securely deleted after the retention period

Secure deletion after the retention period is the most critical factor because it ensures that data is not kept beyond its legal or business requirement, reducing liability and risk. While cost, backups, and accessibility are relevant, they are secondary to the core purpose of a retention policy: to manage data throughout its lifecycle and dispose of it securely when no longer needed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implementing a backup strategy for the retained data

    Why it's wrong here

    Backups are important for availability and disaster recovery, but they are not the most critical factor for a retention policy. In fact, backups can complicate retention because data may persist in backups beyond the retention period. The focus should be on the lifecycle of the primary data, including secure disposal. Backups must also be managed in accordance with retention requirements, but they are secondary.

  • ✗

    Ensuring that data is easily accessible to all employees

    Why it's wrong here

    Data accessibility should be restricted based on the principle of least privilege and the data's classification. Financial records are sensitive and should not be accessible to all employees. Broad accessibility increases the risk of unauthorized disclosure and misuse. Therefore, this is not a critical factor and could be detrimental to security.

  • ✗

    Ensuring that data is stored in a cost-effective manner

    Why it's wrong here

    While cost-effectiveness is a consideration in storage management, it is not the most critical factor for a retention policy driven by regulatory requirements. The primary goal is compliance and legal defensibility. Cost savings should not compromise the ability to retain and produce records when required. Therefore, this is not the most critical factor.

  • ✓

    Verifying that data is securely deleted after the retention period

    Why this is correct

    The most critical factor is ensuring that data is securely deleted once the retention period expires. Failure to do so can result in legal liabilities, increased storage costs, and potential data breaches. Secure deletion must be verifiable and consistent with the organization's data destruction policies. This ensures compliance with retention schedules and reduces risk.

About these practice questions

This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.