Courseiva
Asset Security →hardMultiple Choice

CISSP Asset Security Practice Question

An organization wants to ensure that data is protected throughout its lifecycle. Which step in the data lifecycle is most critical for enforcing data retention policies?

⚠ Common exam trap

CISSP often tests the misconception that retention policies are enforced at data creation or use, when in fact they are enforced during the Archive phase where lifecycle governance and disposition controls reside.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Archive

The Archive phase of the data lifecycle is where data retention policies are enforced, because this is the stage where data is moved to long-term storage and governed by retention schedules, legal holds, and disposition rules. Retention policies define how long data must be kept and when it must be securely destroyed, and these controls are applied at the archive stage. Without proper archival governance, data may be retained indefinitely or destroyed prematurely, violating regulatory requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Archive

    Why this is correct

    Archiving is the process of moving data that is no longer actively used but must be retained for compliance, legal, or historical purposes to a separate, often less expensive, long-term storage system. This phase directly implements data retention policies by ensuring data is stored securely and immutably for its mandated lifecycle, distinct from active operational storage.

  • ✗

    Use

    Why it's wrong here

    The 'Use' phase involves the active processing, retrieval, and manipulation of data within an organization's operational systems. While data protection, such as access controls and encryption, is paramount during this active stage, it focuses on immediate operational security rather than the long-term storage duration dictated by retention policies, which apply to data after its active utility has diminished.

  • ✗

    Create/Collect

    Why it's wrong here

    The 'Create/Collect' phase represents the initial generation or acquisition of data, where its classification and initial security attributes are typically assigned. Although retention policies are defined at this stage, their actual implementation, which involves storing data for a specified duration, occurs much later in the data lifecycle, making this phase distinct from the act of retaining data.

  • ✗

    Share

    Why it's wrong here

    Sharing data involves transmitting it to authorized internal or external recipients, requiring robust controls for data in transit and access management. While critical for secure collaboration, this activity focuses on the secure transfer of data rather than its mandated storage duration within the organization's own infrastructure, which is the core concern of data retention policies.

About these practice questions

Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.