CISSP · domain
Asset Security
Asset Security covers classifying, handling, retaining, and disposing of information and the systems that hold it. CISSP questions here are scenario-based: you choose the right data role, control, or sanitization method for a given classification, lifecycle stage, or media type, and you justify it against business and legal requirements.
Focused practice
Practice Asset Security questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Asset Security
Be able to map data roles, classification, and lifecycle stages to the correct control, and choose a defensible sanitization method for the media type. The single most important thing: match the control to the data's classification and the storage technology, not to habit.
Assigning roles: data owner, data custodian, and data controller versus processor responsibilities.
Selecting sanitization for SSDs: crypto-erase or physical destruction when overwrite is unreliable.
Using a CMDB to track configuration items, ownership, and relationships for asset management.
Applying retention and destruction controls at the correct stage of the data lifecycle.
Watch out for
Common Asset Security exam traps
- ▸Treating the data custodian as the person who sets classification; the owner sets classification and the custodian implements controls.
- ▸Assuming overwriting works on SSDs and flash; wear-leveling leaves residual data, so use crypto-erase or destruction.
- ▸Confusing retention with deletion: retention defines how long data is kept and must be enforced before sanitization occurs.
Question index
All Asset Security questions (39)
Click any question to see the full explanation, or start a practice session above.
An organization uses full disk encryption on all laptops containing sensitive data. A laptop is to be decommissioned, and the data must be sanitized. The laptop's SSD cannot be overwritten reliably due to wear-leveling. Which method is most appropriate?
Hard2An organization is developing a new application that collects and processes European customers' personal data. To comply with the privacy by design principles under GDPR, which THREE measures should be implemented? (Select THREE.)
Medium3A company's software asset management team discovers an unauthorized copy of a licensed application installed on several employee workstations. What is the primary risk associated with this finding?
Medium4A data custodian is responsible for implementing controls to protect data. Which TWO of the following are typical responsibilities of a data custodian? (Select 2)
Medium5A healthcare organization must decommission an old server containing patient health information (PHI) stored on solid-state drives (SSDs). Standard overwriting techniques are ineffective for SSDs due to wear-leveling and bad block mapping. Which sanitization method is most appropriate for these drives?
Medium6Which phase of the data lifecycle involves the removal of data from active storage and placement into long-term storage for potential future use?
Easy7A government contractor handles data classified as 'Secret'. According to government data classification levels, which of the following is the correct order from most restrictive to least restrictive?
Medium8A government contractor handles classified information up to the Secret level. The company's data classification policy recently changed, requiring that all documents marked as 'Confidential' be reclassified as 'Secret' after review. Who is ultimately accountable for ensuring that reclassification is performed correctly?
Medium9A financial services firm stores customer account data on a storage area network (SAN). The data is replicated to a secondary site for disaster recovery. The security team must ensure that when data is no longer needed, it is securely destroyed in accordance with the data retention policy. The primary site uses SSD-based storage, while the secondary site uses traditional HDDs. Which data destruction method is most appropriate for the SSD-based primary site?
Medium10A company has a data retention policy requiring customer transaction records to be kept for 7 years. After 7 years, the data should be destroyed. Which phase of the data lifecycle governs this action?
Hard11An organization uses a configuration management database (CMDB). Which of the following is the PRIMARY purpose of a CMDB?
Medium12A security administrator needs to ensure that data stored on a server is unrecoverable after decommissioning. The server uses SSDs. Which sanitization method is MOST appropriate?
Medium13Which term describes the process of modifying data so that it cannot be attributed to a specific individual without additional information that is kept separately?
Easy14An organization is developing a privacy program. Which THREE of the following are core principles of privacy by design? (Select 3)
Hard15An organization is implementing privacy by design in a new application that collects user location data. Which practice best aligns with the data minimization principle?
Hard16An organization is required to declassify a document that was previously classified as 'Secret' under government guidelines. What process must be followed before the document can be released to the public?
Medium17An organization wants to ensure that data is protected throughout its lifecycle. Which step in the data lifecycle is most critical for enforcing data retention policies?
Hard18What is the primary purpose of a configuration management database (CMDB) in asset management?
Easy19Which phase of the data lifecycle includes the act of securely deleting data that is no longer needed, in accordance with retention policies?
Easy20A financial institution stores customer PII, including Social Security numbers (SSNs). Under privacy regulations, SSNs are considered sensitive PII. Which of the following techniques would best reduce the risk of re-identification while preserving the utility of the data for statistical analysis?
Hard21Which type of data is considered sensitive PII and requires enhanced protection?
Easy22An organization is reviewing its media sanitization procedures. Which TWO methods are considered acceptable for sanitizing solid-state drives (SSDs) according to NIST SP 800-88 guidelines?
Hard23A company is designing a database that will contain personally identifiable information (PII). To reduce privacy risk, they decide to add controlled noise to query results. This technique is known as:
Hard24A company uses differential privacy to release aggregate statistics from a dataset containing sensitive employee information. Which of the following is true regarding differential privacy?
Hard25During an audit, it is discovered that a database containing personally identifiable information (PII) has been retained for 10 years beyond the regulatory requirement. The data owner has not approved the retention extension. Which data lifecycle principle is primarily being violated?
Hard26Under GDPR, a company processes personal data on behalf of a data controller. Which role does the company fulfill?
Medium27Which role is ultimately accountable for the classification of data within an organization?
Easy28An organization is implementing a data retention policy. The legal team has determined that certain financial records must be retained for seven years due to regulatory requirements. The IT department is responsible for enforcing the retention and disposal of these records. Which of the following is the most critical factor to consider when implementing the retention policy?
Easy29A data warehouse contains anonymized customer transaction data used for analytics. The anonymization process removed direct identifiers and applied k-anonymity with k=10. An attacker obtains the dataset and attempts to re-identify individuals using auxiliary information. Which of the following best describes the residual privacy risk?
Hard30A company wants to ensure that data labeled 'Internal Use Only' is not inadvertently disclosed to unauthorized parties. What is the most effective way to communicate handling requirements to employees?
Medium31A multinational corporation is implementing a data classification program. The information security manager must ensure that data is handled appropriately based on its classification level. The company operates in multiple jurisdictions, including the European Union and the United States. Which two of the following are key considerations when developing the data classification policy? (Choose two.)
Hard32A company collects PII from European customers for order processing. Under GDPR, they engage a third-party logistics provider to handle shipping. Which role does the logistics provider typically assume in this scenario?
Hard33A data owner has classified a dataset as 'Confidential' in a commercial organization. Which of the following best describes the primary responsibility of the data owner for this dataset?
Easy34Which of the following is the primary purpose of a configuration management database (CMDB) in asset management?
Easy35An organization is implementing privacy by design for a new application that processes PII. Which practice BEST aligns with the data minimization principle?
Hard36An organization's data retention policy specifies that customer records must be retained for five years after the end of the business relationship. After that period, what should be done with the data according to best practices?
Medium37An organization's data retention policy requires that financial records be kept for seven years. After that period, the records must be destroyed in a manner that prevents reconstruction. Which of the following is the best sanitization method for paper records containing sensitive financial data?
Easy38A database administrator (DBA) is responsible for implementing access controls and backup procedures for a customer database containing PII. The DBA reports to the data owner regarding security measures. Which role best describes the DBA's responsibilities?
Medium39Under the GDPR, which role is responsible for determining the purposes and means of processing personal data?
MediumOther domains
All CISSP exam domains
Frequently asked questions
- What does the Asset Security domain cover on the CISSP exam?
- Be able to map data roles, classification, and lifecycle stages to the correct control, and choose a defensible sanitization method for the media type. The single most important thing: match the control to the data's classification and the storage technology, not to habit.
- How many questions are in this domain?
- This page lists all 39 Asset Security questions in the CISSP question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Asset Security questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.