CISSP Asset Security Practice Question
An organization wants to ensure that data is protected throughout its lifecycle. Which step in the data lifecycle is most critical for enforcing data retention policies?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Archive
The 'archive' phase is when data is moved to long-term storage based on retention requirements, and the retention policy dictates how long it must be kept.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Archive
Why this is correct
Archiving is the process of moving data that is no longer actively used but must be retained for compliance, legal, or historical purposes to a separate, often less expensive, long-term storage system. This phase directly implements data retention policies by ensuring data is stored securely and immutably for its mandated lifecycle, distinct from active operational storage.
- ✗
Use
Why it's wrong here
The 'Use' phase involves the active processing, retrieval, and manipulation of data within an organization's operational systems. While data protection, such as access controls and encryption, is paramount during this active stage, it focuses on immediate operational security rather than the long-term storage duration dictated by retention policies, which apply to data after its active utility has diminished.
- ✗
Create/Collect
Why it's wrong here
The 'Create/Collect' phase represents the initial generation or acquisition of data, where its classification and initial security attributes are typically assigned. Although retention policies are defined at this stage, their actual implementation, which involves storing data for a specified duration, occurs much later in the data lifecycle, making this phase distinct from the act of retaining data.
- ✗
Share
Why it's wrong here
Sharing data involves transmitting it to authorized internal or external recipients, requiring robust controls for data in transit and access management. While critical for secure collaboration, this activity focuses on the secure transfer of data rather than its mandated storage duration within the organization's own infrastructure, which is the core concern of data retention policies.
Go deeper
Related to this question
Learn chapter
Asset Security: Privacy and Data Retention
Key term
Retention policy
A retention policy is a set of rules that determines how long an organization keeps its data and what happens to it when the retention period expires.
Key term
Data retention
Data retention is the practice of keeping data for a specific period to meet legal, business, or compliance needs, and then securely disposing of it.
About these practice questions
Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.