Courseiva

CCNA Asset Security Questions

39 questions · Asset Security · All types, answers revealed

1
MCQhard

An organization uses full disk encryption on all laptops containing sensitive data. A laptop is to be decommissioned, and the data must be sanitized. The laptop's SSD cannot be overwritten reliably due to wear-leveling. Which method is most appropriate?

A.Degaussing
B.DoD 5220.22-M 7-pass overwrite
C.Cryptographic erasure by destroying the encryption key
D.Physical destruction (shredding)
AnswerC

Cryptographic erasure is the most appropriate and highly effective method for sanitizing data on encrypted Solid State Drives (SSDs). When full disk encryption (FDE) is employed, all data on the drive is rendered unreadable without the correct encryption key. By securely destroying or invalidating this master encryption key, all data on the drive becomes cryptographically inaccessible and irrecoverable, effectively sanitizing the media without physically altering the drive itself. This method is fast, efficient, and allows for device reuse.

Why this answer

Cryptographic erasure by destroying the encryption key is the most appropriate method because the data is already encrypted with full disk encryption; destroying the key renders the data unrecoverable without needing to overwrite the SSD, which is unreliable due to wear-leveling. This approach is efficient and secure for decommissioning.

Exam trap

CISSP often tests the confusion between physical destruction and cryptographic erasure, leading candidates to choose shredding when the scenario specifies encryption and SSD wear-leveling.

How to eliminate wrong answers

Option A is wrong because degaussing only works on magnetic media (HDDs), not SSDs, and can damage the drive without ensuring data removal. Option B is wrong because overwriting an SSD with a 7-pass method is ineffective due to wear-leveling, which may leave data in reserve blocks. Option D is wrong because physical destruction (shredding) is a valid method but is more resource-intensive and may not be necessary when cryptographic erasure is available; the question asks for the most appropriate method given the encryption.

2
Multi-Selectmedium

An organization is developing a new application that collects and processes European customers' personal data. To comply with the privacy by design principles under GDPR, which THREE measures should be implemented? (Select THREE.)

Select 3 answers
A.Retain the data only as long as necessary to fulfill the purpose (storage limitation)
B.Encrypt all personal data at rest and in transit
C.Use the data only for the purpose for which it was collected (purpose limitation)
D.Obtain explicit consent from users before data collection
E.Collect only the personal data necessary for the specified purpose (data minimization)
AnswersA, C, E

Storage limitation is a critical Privacy by Design principle requiring that personal data be retained only for the duration strictly necessary to fulfill the purpose for which it was collected. This principle prevents indefinite data retention, thereby reducing the long-term risk associated with holding sensitive information. Implementing robust data retention policies and automated deletion mechanisms directly into system architecture ensures compliance and mitigates future privacy liabilities.

Why this answer

Option A is correct because GDPR's storage limitation principle (Article 5(1)(e)) requires that personal data be kept in a form that permits identification of data subjects for no longer than is necessary for the purposes for which the data are processed, making retention limits a core privacy-by-design measure. Option C is correct because the purpose limitation principle (Article 5(1)(b)) requires data to be collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes, so restricting use to the original purpose is essential. Option E is correct because the data minimization principle (Article 5(1)(c)) requires processing to be adequate, relevant, and limited to what is necessary in relation to the purposes, so collecting only the minimum data needed directly implements privacy by design.

Option B is not marked correct because, while encryption is a valuable security safeguard under Article 32, it is not one of the core privacy-by-design data principles tested here and GDPR does not mandate encryption of all personal data in every case. Option D is not marked correct because explicit consent is only one of several lawful bases under Article 6 and is not always required, so it is not a universal privacy-by-design measure.

Exam trap

CISSP often tests the distinction between GDPR principles (Article 5) and other obligations like consent or encryption, causing candidates to select security controls instead of the actual privacy-by-design principles.

3
MCQmedium

A company's software asset management team discovers an unauthorized copy of a licensed application installed on several employee workstations. What is the primary risk associated with this finding?

A.Legal liability for software piracy
B.Reduction in employee productivity
C.Increased storage consumption
D.Incompatibility with other systems
AnswerA

Unauthorized software directly constitutes a breach of intellectual property rights and software licensing agreements. This exposes the company to significant legal action from software vendors, potentially resulting in substantial fines, penalties, and mandatory compliance audits. Such legal repercussions can severely impact the organization's financial stability and reputation, making it the most immediate and severe risk identified by a software asset management team.

Why this answer

Unauthorized software can expose the organization to legal liability for copyright infringement, security vulnerabilities due to lack of patching, and compliance issues.

4
Multi-Selectmedium

A data custodian is responsible for implementing controls to protect data. Which TWO of the following are typical responsibilities of a data custodian? (Select 2)

Select 2 answers
A.Classifying data according to sensitivity
B.Defining data usage policies
C.Performing regular backups of data
D.Restoring data from backups when needed
E.Determining data retention periods
AnswersC, D

Performing regular backups is a primary operational responsibility of a data custodian. This task involves the technical execution of data replication and storage to ensure data availability and recoverability in case of loss or corruption. Custodians are responsible for configuring backup systems, monitoring backup jobs, and verifying the integrity of backup media according to established policies and schedules.

Why this answer

Option C (Performing regular backups of data) is correct because the data custodian handles the day-to-day operational, technical execution of data protection controls, and running scheduled backups is a classic custodial task that enforces the protection decisions made by data owners. Option D (Restoring data from backups when needed) is also correct because recovery operations—retrieving and restoring data from backup media during an incident or data loss event—fall within the custodian's operational remit for maintaining data availability and integrity. By contrast, Option A (Classifying data according to sensitivity), Option B (Defining data usage policies), and Option E (Determining data retention periods) are strategic governance responsibilities belonging to the data owner (or steward), who sets classification, policy, and retention rules that the custodian then implements.

Exam trap

CISSP often tests the distinction between data owner and data custodian responsibilities, and candidates frequently confuse policy-level tasks (like classification and retention) with operational tasks (like backups and restoration).

5
MCQmedium

A healthcare organization must decommission an old server containing patient health information (PHI) stored on solid-state drives (SSDs). Standard overwriting techniques are ineffective for SSDs due to wear-leveling and bad block mapping. Which sanitization method is most appropriate for these drives?

A.Cryptographic erasure by deleting the encryption key
B.Degaussing with a high-coercivity degausser
C.Physical destruction such as shredding or pulverizing
D.Overwriting with the DoD 5220.22-M 7-pass standard
AnswerC

Physical destruction, through methods like shredding, pulverizing, or incineration, is the most secure and universally effective method for sanitizing Solid State Drives (SSDs). This process physically destroys the NAND flash memory chips and their individual cells, making data recovery absolutely impossible. Unlike other methods, physical destruction bypasses the complexities of wear-leveling, over-provisioning, and inaccessible blocks inherent to SSD architecture, guaranteeing complete data obliteration.

Why this answer

Physical destruction (e.g., shredding or pulverizing) is recommended for SSDs because overwriting may not reach all cells, and degaussing does not affect flash memory.

6
MCQeasy

Which phase of the data lifecycle involves the removal of data from active storage and placement into long-term storage for potential future use?

A.Use
B.Archive
C.Destroy
D.Store
AnswerB

Archiving is the process of systematically moving data from active, primary storage to a more cost-effective, long-term storage solution, typically for compliance, historical record-keeping, or future reference. While the data is 'removed' from immediate operational systems, it is retained and preserved, often under specific retention policies. This phase ensures data availability for regulatory or business needs without consuming expensive active storage resources.

Why this answer

The Archive phase of the data lifecycle is specifically defined as the stage where data is moved out of active, frequently accessed storage and placed into long-term retention for potential future reference or compliance needs. Unlike Destroy, which permanently eliminates data, Archive preserves the data in a lower-cost, less accessible tier. This aligns with lifecycle models (e.g., ISACA/ISO 27001 data lifecycle) where Archive follows Use and precedes eventual Destroy.

Exam trap

CISSP often tests the distinction between Archive (long-term retention for future use) and Destroy (permanent elimination), causing candidates to confuse preservation with disposal when the question emphasizes 'removal from active storage.'

How to eliminate wrong answers

Option A (Use) is wrong because the Use phase covers active access, processing, and consumption of data by applications or users, not relocation to long-term storage. Option C (Destroy) is wrong because Destroy is the permanent, irreversible removal of data (e.g., degaussing, crypto-shredding, secure deletion) — the opposite of preserving it for future use. Option D (Store) is wrong because Store refers to the initial placement of data into primary/active storage repositories, not the migration of data out of active storage into long-term archival tiers.

7
MCQmedium

A government contractor handles data classified as 'Secret'. According to government data classification levels, which of the following is the correct order from most restrictive to least restrictive?

A.Confidential, Secret, Top Secret, Unclassified
B.Top Secret, Secret, Confidential, Unclassified
C.Unclassified, Confidential, Secret, Top Secret
D.Secret, Top Secret, Confidential, Unclassified
AnswerB

This option correctly lists the U.S. government data classification levels in descending order of sensitivity and potential damage from unauthorized disclosure. 'Top Secret' indicates exceptionally grave damage to national security, 'Secret' indicates serious damage, 'Confidential' indicates damage, and 'Unclassified' indicates no expected damage. This hierarchy is fundamental for implementing appropriate security controls and access restrictions.

Why this answer

The U.S. government classification hierarchy, defined by Executive Order 13526, ranks information from most to least restrictive as Top Secret, Secret, Confidential, and Unclassified. Top Secret covers information whose unauthorized disclosure could cause 'exceptionally grave damage' to national security, while Secret and Confidential correspond to 'serious' and 'damage' respectively. Unclassified sits at the bottom with no restriction.

Option B is the only choice that lists this order correctly.

Exam trap

CISSP often tests the direction of the ordering (most-to-least vs. least-to-most) and the relative position of Confidential, which candidates mistakenly elevate above Secret because the word sounds more sensitive.

How to eliminate wrong answers

Option A is wrong because it places Confidential above Secret and Top Secret, inverting the true hierarchy — Confidential is the lowest of the three classified tiers. Option C is wrong because it lists the order in reverse (least to most restrictive), which is the opposite of what the question asks. Option D is wrong because it places Secret above Top Secret, but Top Secret is always the most restrictive classification level.

8
MCQmedium

A government contractor handles classified information up to the Secret level. The company's data classification policy recently changed, requiring that all documents marked as 'Confidential' be reclassified as 'Secret' after review. Who is ultimately accountable for ensuring that reclassification is performed correctly?

A.Data custodian
B.Data subject
C.Data steward
D.Data owner
AnswerD

The data owner holds ultimate organizational accountability for the protection and classification of specific data assets, often a senior business manager. They are responsible for determining the data's sensitivity (e.g., Top Secret, Confidential) and approving access requirements based on business needs and regulatory compliance. This role ensures appropriate security controls are defined and implemented to safeguard the information throughout its lifecycle, bearing the risk of mishandling.

Why this answer

The data owner is the senior-level manager accountable for data classification and protection. They have the authority and responsibility to assign classification levels and ensure data is properly classified.

9
MCQmedium

A financial services firm stores customer account data on a storage area network (SAN). The data is replicated to a secondary site for disaster recovery. The security team must ensure that when data is no longer needed, it is securely destroyed in accordance with the data retention policy. The primary site uses SSD-based storage, while the secondary site uses traditional HDDs. Which data destruction method is most appropriate for the SSD-based primary site?

A.Physical shredding of the SSDs
B.Cryptographic erasure (crypto-shredding)
C.Degaussing the SSDs
D.Overwriting with a single pass of random data
AnswerB

Cryptographic erasure involves destroying the encryption keys used to encrypt the data, rendering the data unrecoverable. For SSDs, where overwriting is unreliable due to wear leveling and spare blocks, crypto-shredding is a recommended method. It ensures that even if residual data remains, it cannot be decrypted, satisfying secure destruction requirements.

Why this answer

Cryptographic erasure is the most appropriate method for SSDs because it leverages encryption to render data unrecoverable by destroying the keys. Unlike overwriting, which is unreliable on SSDs due to wear leveling, crypto-shredding ensures that all data, including that in spare blocks, becomes inaccessible. It is also efficient and allows for secure disposal without physical destruction.

Exam trap

The trap here is assuming that overwriting works the same on SSDs as on HDDs, overlooking wear leveling and spare blocks.

10
MCQhard

A company has a data retention policy requiring customer transaction records to be kept for 7 years. After 7 years, the data should be destroyed. Which phase of the data lifecycle governs this action?

A.Use
B.Share
C.Archive
D.Destroy
AnswerD

Destroying customer data is the definitive and irreversible process of rendering information unreadable and unrecoverable from all storage media. This action directly fulfills a data retention policy's requirement to eliminate data once its specified retention period has expired, ensuring compliance and mitigating future risks. Proper destruction methods prevent unauthorized access or recovery of sensitive information.

Why this answer

The destroy phase of the data lifecycle explicitly governs the secure disposal of data once its retention period ends. In this scenario, after 7 years, the policy mandates destruction, so the action falls under the Destroy phase. This phase ensures data is irrecoverable and compliant with legal and regulatory requirements.

Exam trap

CISSP often tests the confusion between archiving and destruction; candidates may think archiving implies eventual destruction, but archiving is a separate phase focused on long-term retention, while destruction is the final, irreversible step.

How to eliminate wrong answers

Option A (Use) is wrong because it refers to the active utilization of data during its lifecycle, not its disposal. Option B (Share) is wrong because it involves distributing data to authorized parties, not destroying it. Option C (Archive) is wrong because archiving is the long-term storage of data for retention, not its final destruction.

11
MCQmedium

An organization uses a configuration management database (CMDB). Which of the following is the PRIMARY purpose of a CMDB?

A.Manage user passwords
B.Monitor network performance
C.Record asset relationships and configurations
D.Track software licenses
AnswerC

The primary purpose of a Configuration Management Database (CMDB) is to serve as a centralized repository for information about all Configuration Items (CIs) within an IT environment. This includes not only detailed attributes of each asset, such as hardware specifications, software versions, and network addresses, but critically, also the intricate relationships and dependencies between these CIs. By mapping these connections, a CMDB enables organizations to understand the impact of changes and facilitate effective incident and problem management.

Why this answer

A CMDB's core function is to serve as a repository that records configuration items (CIs) and, critically, the relationships between them — such as which server hosts which application, which application depends on which database, and how changes propagate. This relationship mapping is what enables impact analysis, change management, and incident root-cause analysis. Simply storing asset attributes without relationships would be an asset inventory, not a CMDB.

Exam trap

CISSP often tests the distinction between a CMDB (which emphasizes CI relationships and configuration state) and a simple asset inventory or license tracker, so candidates who focus only on 'recording assets' rather than 'recording relationships' may pick the license-tracking distractor.

How to eliminate wrong answers

Option A is wrong because managing user passwords is the function of an identity and access management (IAM) system or directory service (e.g., Active Directory, LDAP), not a CMDB. Option B is wrong because network performance monitoring is performed by tools such as SNMP-based NMS platforms, NetFlow analyzers, or APM solutions — a CMDB records configuration state, not real-time telemetry. Option D is wrong because tracking software licenses is a software asset management (SAM) function; while license data may be stored as attributes of CIs in a CMDB, license tracking is not the PRIMARY purpose of the CMDB itself.

12
MCQmedium

A security administrator needs to ensure that data stored on a server is unrecoverable after decommissioning. The server uses SSDs. Which sanitization method is MOST appropriate?

A.Quick format
B.Standard overwriting with multiple passes
C.Physical destruction (shredding)
D.Degaussing
AnswerC

Physical destruction, such as shredding, is the most secure and definitive method for sanitizing solid-state drives. This process involves mechanically breaking the SSD's components, including the NAND flash memory chips where data is stored, into tiny, unrecoverable fragments. By rendering the storage media physically unreadable and non-functional, shredding ensures that data cannot be reconstructed or accessed by any means, providing absolute data destruction.

Why this answer

SSDs cannot be reliably overwritten due to wear leveling; physical destruction or cryptographic erasure is recommended.

13
MCQeasy

Which term describes the process of modifying data so that it cannot be attributed to a specific individual without additional information that is kept separately?

A.Anonymisation
B.Differential privacy
C.Pseudonymisation
D.Encryption
AnswerC

Pseudonymisation is a data management and de-identification technique where directly identifying fields within a data record are replaced with artificial identifiers, or pseudonyms. While the direct identifiers are removed, a separate 'key' or mapping table is maintained, allowing for the re-identification of the original data subject if necessary, typically under strict controls and for specific purposes. This process reduces the linkability of a dataset to an individual without completely destroying the possibility of re-identification, making it a reversible de-identification method.

Why this answer

Pseudonymisation replaces identifying information with a pseudonym, and the mapping between the pseudonym and the original identity is kept separately, so re-identification is possible only with access to that additional information. This matches the definition exactly.

Exam trap

CISSP often tests the distinction between pseudonymisation (reversible with additional info) and anonymisation (irreversible), causing candidates to choose anonymisation when the scenario mentions separately kept additional information.

How to eliminate wrong answers

Option A is wrong because anonymisation irreversibly removes identifying information so that re-identification is not possible, even with additional data; the question specifies that additional information kept separately can re-attribute the data, which is pseudonymisation. Option B is wrong because differential privacy adds statistical noise to query results to protect individual privacy, not a process of replacing identifiers with pseudonyms. Option D is wrong because encryption transforms data into ciphertext to protect confidentiality, but it does not replace identifiers with pseudonyms; the data remains attributable if the key is available, and the definition does not match.

14
Multi-Selecthard

An organization is developing a privacy program. Which THREE of the following are core principles of privacy by design? (Select 3)

Select 3 answers
A.Open data sharing
B.Data minimization
C.Purpose limitation
D.Maximum data retention
E.Storage limitation
AnswersB, C, E

This core privacy principle dictates that organizations must limit the collection of personal data to what is strictly relevant and necessary to accomplish the specified, legitimate processing purposes. By reducing the volume of personally identifiable information (PII) ingested, organizations significantly lower their overall risk profile and potential breach impact.

Why this answer

Data minimization (B) is a core privacy-by-design principle because it requires collecting only the personal data that is adequate, relevant, and necessary for the specified purpose, reducing exposure and risk. Purpose limitation (C) is correct because personal data must be collected for specified, explicit, and legitimate purposes and not further processed in a way incompatible with those purposes. Storage limitation (E) is correct because data should be kept only as long as necessary for the stated purpose, after which it must be deleted or anonymized.

Open data sharing (A) is not a privacy-by-design principle, as unrestricted sharing conflicts with confidentiality and purpose controls, and maximum data retention (D) is the opposite of storage limitation and increases privacy risk.

Exam trap

CISSP often tests the distinction between privacy principles and general data handling concepts; candidates may pick 'open data sharing' or 'maximum data retention' because they sound like data management best practices, but they contradict privacy by design.

15
MCQhard

An organization is implementing privacy by design in a new application that collects user location data. Which practice best aligns with the data minimization principle?

A.Encrypting location data both at rest and in transit
B.Anonymizing location data after collection
C.Obtaining explicit consent from users before collection
D.Collecting location data only when the app is actively in use
AnswerD

This approach directly embodies the 'data minimization' principle of Privacy by Design by ensuring that location data is only acquired when it is essential for the application's active functionality. By limiting collection to periods of active use, the organization significantly reduces the overall volume of sensitive personal data held, thereby mitigating potential privacy risks and demonstrating a proactive commitment to user privacy.

Why this answer

Data minimization means collecting only the data that is necessary for the specified purpose. Collecting location data only when the app is actively in use limits collection to the minimum needed for the app's functionality, directly aligning with the principle.

Exam trap

CISSP often tests the distinction between data minimization (collect less) and other privacy controls like encryption, consent, or anonymization, which do not reduce collection scope.

How to eliminate wrong answers

Option A is wrong because encrypting data at rest and in transit is a security control that protects confidentiality but does not reduce the amount of data collected; it addresses protection, not minimization. Option B is wrong because anonymizing data after collection still involves collecting the full data set first; minimization requires limiting collection at the source, not transforming it afterward. Option C is wrong because obtaining explicit consent is a transparency and legal basis requirement, not a minimization practice; consent does not reduce the volume or scope of data collected.

16
MCQmedium

An organization is required to declassify a document that was previously classified as 'Secret' under government guidelines. What process must be followed before the document can be released to the public?

A.The data owner must reclassify it as 'Unclassified' without further action
B.The document can be released immediately after the classification period expires
C.A declassification review by authorized personnel must be conducted
D.The document should be shredded and a new version created without classified markings
AnswerC

This option is correct because declassification is a formal, systematic process that mandates a thorough review by personnel specifically authorized for this task. This review ensures that the information no longer meets the criteria for classification and that its release will not compromise national security, privacy, or other protected interests. It's a critical safeguard against inadvertent disclosure of still-sensitive data and ensures compliance with declassification policies.

Why this answer

Declassification under government guidelines (e.g., EO 13526 in the US, or equivalent national frameworks) requires a formal declassification review by authorized personnel before any classified material can be released. The review verifies whether the information still warrants protection, whether exemptions apply, and whether any portions must remain redacted. Only after this review and approval can the document be downgraded or released to the public.

Exam trap

CISSP often tests the misconception that classification automatically expires into public release or that a data owner can unilaterally declassify — the exam expects you to know that a formal declassification review by authorized personnel is mandatory.

How to eliminate wrong answers

Option A is wrong because a data owner cannot unilaterally reclassify a Secret document as Unclassified — declassification requires review by designated declassification authorities under the governing classification policy, not just an owner's decision. Option B is wrong because classification periods (e.g., 10, 25 years) trigger a review, not automatic release; documents may be reclassified or have exemptions extended. Option D is wrong because shredding and recreating a document does not declassify the underlying information — the same content remains classified regardless of the physical artifact, and this would constitute an unauthorized destruction of classified material.

17
MCQhard

An organization wants to ensure that data is protected throughout its lifecycle. Which step in the data lifecycle is most critical for enforcing data retention policies?

A.Archive
B.Use
C.Create/Collect
D.Share
AnswerA

Archiving is the process of moving data that is no longer actively used but must be retained for compliance, legal, or historical purposes to a separate, often less expensive, long-term storage system. This phase directly implements data retention policies by ensuring data is stored securely and immutably for its mandated lifecycle, distinct from active operational storage.

Why this answer

The Archive phase of the data lifecycle is where data retention policies are enforced, because this is the stage where data is moved to long-term storage and governed by retention schedules, legal holds, and disposition rules. Retention policies define how long data must be kept and when it must be securely destroyed, and these controls are applied at the archive stage. Without proper archival governance, data may be retained indefinitely or destroyed prematurely, violating regulatory requirements.

Exam trap

CISSP often tests the misconception that retention policies are enforced at data creation or use, when in fact they are enforced during the Archive phase where lifecycle governance and disposition controls reside.

How to eliminate wrong answers

Option B (Use) is wrong because the Use phase concerns active access, processing, and application of data — retention duration is not determined here. Option C (Create/Collect) is wrong because this is the point of data origination, where classification and labeling begin, but retention periods are not yet enforced. Option D (Share) is wrong because sharing governs data transfer and disclosure to third parties, not how long data is retained or when it is destroyed.

18
MCQeasy

What is the primary purpose of a configuration management database (CMDB) in asset management?

A.Monitor network traffic for anomalies
B.Store and manage data classification labels
C.Track software licenses and compliance
D.Provide a repository of configuration items and their relationships
AnswerD

The fundamental purpose of a Configuration Management Database (CMDB) is to serve as a centralized repository for all relevant information about Configuration Items (CIs) within an IT environment. CIs encompass any component, service, or other asset that needs to be managed to deliver an IT service, such as servers, applications, networks, and documentation. Crucially, the CMDB also meticulously maps the interdependencies and relationships between these CIs, providing a holistic view that is vital for impact analysis, incident resolution, and change management processes.

Why this answer

The primary purpose of a configuration management database (CMDB) is to provide a repository of configuration items (CIs) and their relationships, enabling IT service management processes like change management, incident management, and asset management. It tracks the components of an IT environment and how they interconnect.

Exam trap

CISSP often tests the confusion between a CMDB and other asset management tools, leading candidates to choose software license tracking or network monitoring as the primary purpose.

How to eliminate wrong answers

Option A is wrong because monitoring network traffic for anomalies is a function of network monitoring tools, not a CMDB. Option B is wrong because storing data classification labels is typically done in a data catalog or classification system, not a CMDB. Option C is wrong because tracking software licenses and compliance is a function of software asset management (SAM) tools, which may integrate with a CMDB but is not its primary purpose.

19
MCQeasy

Which phase of the data lifecycle includes the act of securely deleting data that is no longer needed, in accordance with retention policies?

A.Store
B.Share
C.Archive
D.Destroy
AnswerD

The Destroy phase is the critical final stage of the data lifecycle, specifically encompassing the secure and irreversible removal of data from all storage media. This involves employing methods like degaussing, cryptographic erasure, or physical destruction (e.g., shredding, pulverizing) to ensure data cannot be reconstructed or recovered. This phase directly addresses the act of secure deletion, preventing unauthorized access after data's useful life has ended.

Why this answer

The Destroy phase of the data lifecycle is explicitly the stage where data is securely deleted once it is no longer needed and retention policies permit disposal. It covers techniques like cryptographic erasure, degaussing, shredding, and secure overwrite, ensuring data cannot be recovered. This is the terminal phase before the lifecycle restarts.

Exam trap

CISSP often tests confusion between Archive (long-term retention for future access) and Destroy (irreversible secure disposal), so candidates pick Archive thinking retention equals eventual deletion.

How to eliminate wrong answers

Option A is wrong because Store covers the retention and protection of data at rest, not its disposal. Option B is wrong because Share covers controlled distribution of data to authorized parties, not deletion. Option C is wrong because Archive is a long-term retention stage for data kept for compliance or historical purposes — it precedes, not replaces, destruction.

20
MCQhard

A financial institution stores customer PII, including Social Security numbers (SSNs). Under privacy regulations, SSNs are considered sensitive PII. Which of the following techniques would best reduce the risk of re-identification while preserving the utility of the data for statistical analysis?

A.Anonymization by removing all direct identifiers
B.Encrypting the entire dataset at rest
C.Differential privacy by adding calibrated noise to the dataset
D.Pseudonymization by replacing names with random identifiers
AnswerC

Differential privacy offers a strong, mathematically provable guarantee of privacy by introducing carefully calibrated noise into the dataset or query results. This noise ensures that the presence or absence of any single individual's data point does not significantly alter the output, making it extremely difficult for an adversary to infer specific individual attributes, even with substantial auxiliary information. It allows for aggregate statistical analysis while rigorously protecting individual privacy against sophisticated re-identification attempts.

Why this answer

Differential privacy adds mathematically calibrated noise to query results or dataset statistics so that the presence or absence of any single individual cannot be inferred, while aggregate statistical properties remain accurate. This directly addresses re-identification risk — even with auxiliary data, an attacker cannot confidently determine whether a specific person is in the dataset. It preserves utility for statistical analysis because the noise is bounded and unbiased across large populations.

Exam trap

CISSP often tests the distinction between de-identification/pseudonymization (reversible or re-identifiable) and true anonymization techniques like differential privacy — the trap is picking 'remove identifiers' or 'pseudonymize' as sufficient when quasi-identifier attacks still enable re-identification.

How to eliminate wrong answers

Option A is wrong because removing direct identifiers (names, SSNs) is only de-identification, not anonymization — quasi-identifiers like ZIP code, birth date, and gender can be combined with external datasets to re-identify individuals (the classic Sweeney 1997 Massachusetts voter case). Option B is wrong because encryption at rest protects data from unauthorized access but does nothing to prevent re-identification once the data is decrypted for analysis — it is a confidentiality control, not a privacy-preserving technique. Option D is wrong because pseudonymization replaces identifiers with tokens but the mapping table still exists, and quasi-identifiers remain, so re-identification is still possible; GDPR explicitly treats pseudonymized data as still personal data.

21
MCQeasy

Which type of data is considered sensitive PII and requires enhanced protection?

A.Name and email address
B.Job title
C.Phone number
D.Social Security number
AnswerD

A Social Security number (SSN) is unequivocally considered sensitive PII due to its direct linkage to an individual's financial, medical, and governmental records. Its compromise presents an extremely high risk of identity theft, financial fraud, and other severe personal harm. Consequently, SSNs require the most stringent security controls and regulatory protections to safeguard individuals from significant adverse impacts.

Why this answer

A Social Security number is a government-issued unique identifier that, if exposed, enables identity theft and fraud, so it is classified as sensitive PII requiring enhanced protection under regulations like GLBA, HIPAA, and state privacy laws. Names, email addresses, and phone numbers are PII but generally lower sensitivity, while job titles are typically not considered sensitive PII at all. The SSN is the classic example of high-sensitivity personal data.

Exam trap

The trap is treating all PII as equally sensitive; the exam expects you to recognize that government identifiers like SSNs are categorically sensitive and demand enhanced protection beyond ordinary PII.

How to eliminate wrong answers

Option A is wrong because a name and email address, while PII, are commonly shared and do not by themselves enable identity theft the way an SSN does. Option B is wrong because a job title is generally not considered PII, let alone sensitive PII. Option C is wrong because a phone number is PII but is lower sensitivity than a government identifier like an SSN.

22
Multi-Selecthard

An organization is reviewing its media sanitization procedures. Which TWO methods are considered acceptable for sanitizing solid-state drives (SSDs) according to NIST SP 800-88 guidelines?

Select 2 answers
A.Degaussing
B.Cryptographic erase
C.Physical destruction (shredding or pulverizing)
D.Overwriting with a random pattern
E.Data wiping software
AnswersB, C

Cryptographic erasure (CE) sanitizes media by permanently deleting or overwriting the decryption keys associated with self-encrypting drives (SEDs). Without the key, the ciphertext remaining on the storage chips becomes mathematically infeasible to decrypt. This process is highly efficient and completed in seconds, making it ideal for both solid-state and magnetic media.

Why this answer

According to NIST SP 800-88, cryptographic erase (Option B) is an acceptable sanitization method for SSDs because it destroys the media encryption key (MEK) used by the drive's built-in self-encrypting drive (SED) controller, rendering all data on the NAND flash unreadable without ever needing to overwrite every cell. Physical destruction (Option C) via shredding or pulverizing is also acceptable because it reduces the flash memory chips to particles small enough that data recovery is infeasible, which NIST lists as a valid media disposal technique. Degaussing (Option A) does not belong because SSDs use flash memory rather than magnetic media, so a magnetic field has no effect on the stored charge.

Overwriting with a random pattern (Option D) is not reliable for SSDs due to wear leveling, over-provisioning, and remapped blocks that can retain residual data outside the logical address space. Data wiping software (Option E) is likewise not an approved SSD sanitization method in NIST SP 800-88 because it cannot guarantee that every flash cell, including spare and remapped blocks, is overwritten.

Exam trap

CISSP often tests the misconception that overwriting or degaussing works on SSDs, when in fact only cryptographic erase or physical destruction are reliable per NIST SP 800-88.

23
MCQhard

A company is designing a database that will contain personally identifiable information (PII). To reduce privacy risk, they decide to add controlled noise to query results. This technique is known as:

A.Data masking
B.Tokenization
C.Differential privacy
D.Anonymization
AnswerC

Differential privacy is a rigorous mathematical framework that quantifies and limits the privacy risk to individuals when their data is part of a dataset used for statistical queries. It achieves this by strategically injecting calibrated noise into query results or the data itself, ensuring that the presence or absence of any single individual's data in the dataset does not significantly alter the output of an analysis. This allows for aggregate insights while providing strong, provable guarantees against re-identification, even by an attacker with auxiliary information.

Why this answer

Differential privacy is a technique that adds controlled noise to query results to protect individual privacy while allowing aggregate analysis. It ensures that the inclusion or exclusion of a single individual's data does not significantly affect the output, thereby reducing privacy risk. This matches the scenario of adding noise to query results for PII.

Exam trap

CISSP often tests the confusion between differential privacy and anonymization or masking; candidates may think any privacy technique involving data alteration is differential privacy, but only differential privacy adds noise to query results with a formal privacy guarantee.

How to eliminate wrong answers

Option A (Data masking) is wrong because it involves obfuscating specific data fields, often for testing or non-production use, but does not add noise to query results. Option B (Tokenization) is wrong because it replaces sensitive data with non-sensitive tokens, preserving format but not adding noise. Option D (Anonymization) is wrong because it irreversibly removes personally identifiable information, but does not typically involve adding noise to query outputs.

24
MCQhard

A company uses differential privacy to release aggregate statistics from a dataset containing sensitive employee information. Which of the following is true regarding differential privacy?

A.It works by adding noise to the data or query results to protect individual privacy
B.It ensures that no individual's data can ever be inferred from the released statistics
C.It requires that data be encrypted before release
D.It is a method of pseudonymization that replaces identifiers with pseudonyms
AnswerA

Differential privacy achieves its robust privacy guarantees by systematically injecting carefully calibrated random noise into either the raw data before aggregation or directly into the query results. This noise obfuscates the contribution of any single individual, making it statistically difficult to determine if a particular individual's data was included in the dataset or query. This method allows for the release of aggregate statistics while mathematically bounding the risk of individual re-identification, balancing utility and privacy.

Why this answer

Differential privacy is a mathematical framework that adds calibrated noise (e.g., Laplace or Gaussian) to either the raw data or the query output so that the presence or absence of any single individual changes the result by only a bounded amount. This provides plausible deniability for each record while still allowing statistically useful aggregate results. Option A correctly captures this core mechanism.

Exam trap

CISSP often tests the misconception that differential privacy offers absolute non-inferability (Option B) — candidates confuse its probabilistic guarantee with the stronger, impossible promise of complete anonymity.

How to eliminate wrong answers

Option B is wrong because differential privacy provides probabilistic, not absolute, guarantees — it bounds the influence of any one record via epsilon, but inference is still possible in some cases (especially with small epsilon or repeated queries). Option C is wrong because encryption protects data in transit/at rest and is orthogonal to differential privacy; noise addition, not encryption, is the defining mechanism. Option D is wrong because pseudonymization simply swaps identifiers for tokens and is reversible with the mapping table — it does not provide the statistical indistinguishability that differential privacy guarantees.

25
MCQhard

During an audit, it is discovered that a database containing personally identifiable information (PII) has been retained for 10 years beyond the regulatory requirement. The data owner has not approved the retention extension. Which data lifecycle principle is primarily being violated?

A.Storage limitation
B.Data minimization
C.Purpose limitation
D.Integrity
AnswerA

Storage limitation mandates that personal data must not be kept for longer than is necessary for the purposes for which it was collected or processed. An audit discovering a database retaining data beyond its defined retention period directly indicates a violation of this principle, necessitating the secure deletion or anonymization of such data. This principle is crucial for minimizing the risk associated with data breaches and ensuring compliance with privacy regulations.

Why this answer

Storage limitation requires that PII be kept only as long as necessary for the stated purpose or as required by regulation, and then securely deleted. Retaining data 10 years beyond the regulatory requirement, without the data owner's approval for an extension, directly violates this principle. The other principles address collection scope, purpose of use, and accuracy/consistency — not retention duration.

Exam trap

CISSP often tests the distinction between storage limitation (how long you keep data) and data minimization (how much you collect) — candidates conflate the two because both sound like 'less data' principles.

How to eliminate wrong answers

Option B is wrong because data minimization concerns collecting only the minimum data necessary for the purpose, not how long data is retained. Option C is wrong because purpose limitation restricts using data only for the purpose it was collected for — it does not govern retention duration. Option D is wrong because integrity refers to ensuring data is accurate, complete, and protected from unauthorized modification, which is unrelated to over-retention.

26
MCQmedium

Under GDPR, a company processes personal data on behalf of a data controller. Which role does the company fulfill?

A.Data custodian
B.Data controller
C.Data processor
D.Data subject
AnswerC

Under GDPR, a data processor is an entity that processes personal data strictly on behalf of, and according to the documented instructions of, a data controller. This relationship is typically formalized through a data processing agreement (DPA), which outlines the scope, nature, and purpose of processing. The processor does not determine the purposes or means of processing independently but acts as a service provider executing tasks delegated by the controller.

Why this answer

Under GDPR Article 4(8), a processor is a natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller. Since the company is processing data on behalf of the controller, it is the data processor.

Exam trap

CISSP often tests the controller/processor distinction by using the phrase 'on behalf of,' which is the GDPR trigger for processor status — candidates who focus on who 'owns' the data rather than who 'determines the purpose' pick controller incorrectly.

How to eliminate wrong answers

Option A is wrong because 'data custodian' is not a GDPR-defined role; it is a data-governance term (often from ITIL/COBIT) describing someone who implements the controller's instructions technically, and it carries no GDPR legal obligations. Option B is wrong because the data controller determines the purposes and means of processing — here the company is acting on the controller's behalf, not deciding why and how data is processed. Option D is wrong because the data subject is the identifiable individual whose personal data is processed, not the organization doing the processing.

27
MCQeasy

Which role is ultimately accountable for the classification of data within an organization?

A.Data steward
B.Data custodian
C.Data processor
D.Data owner
AnswerD

The data owner holds ultimate accountability for the data's protection, value, and proper usage throughout its entire lifecycle. This includes the critical responsibility of determining the data's classification level based on its sensitivity, criticality, and potential business impact if compromised or misused. They are the primary decision-maker regarding how data should be categorized and protected, and they accept the residual risk associated with its handling and security measures.

Why this answer

The data owner is the senior manager or business leader ultimately accountable for the data's classification, protection, and use. They hold the authority and responsibility for deciding how data is categorized (e.g., public, internal, confidential, restricted) based on its sensitivity and business value. Accountability cannot be delegated to custodians or stewards, who execute the owner's decisions.

Exam trap

CISSP often tests the confusion between accountability (data owner) and execution (data steward/custodian) — candidates pick the role that does the work rather than the one that is ultimately answerable.

How to eliminate wrong answers

Option A is wrong because a data steward handles day-to-day data quality and metadata management, implementing the owner's classification decisions rather than being accountable for them. Option B is wrong because a data custodian performs the technical safeguarding (backups, access controls) of data on behalf of the owner, not the classification decision. Option C is wrong because a data processor (e.g., a cloud provider) processes data under the controller's instructions and has no accountability for classification.

28
MCQeasy

An organization is implementing a data retention policy. The legal team has determined that certain financial records must be retained for seven years due to regulatory requirements. The IT department is responsible for enforcing the retention and disposal of these records. Which of the following is the most critical factor to consider when implementing the retention policy?

A.Implementing a backup strategy for the retained data
B.Ensuring that data is easily accessible to all employees
C.Ensuring that data is stored in a cost-effective manner
D.Verifying that data is securely deleted after the retention period
AnswerD

The most critical factor is ensuring that data is securely deleted once the retention period expires. Failure to do so can result in legal liabilities, increased storage costs, and potential data breaches. Secure deletion must be verifiable and consistent with the organization's data destruction policies. This ensures compliance with retention schedules and reduces risk.

Why this answer

Secure deletion after the retention period is the most critical factor because it ensures that data is not kept beyond its legal or business requirement, reducing liability and risk. While cost, backups, and accessibility are relevant, they are secondary to the core purpose of a retention policy: to manage data throughout its lifecycle and dispose of it securely when no longer needed.

Exam trap

The trap here is focusing on operational concerns like cost or backups instead of the compliance-driven need for secure disposal.

29
MCQhard

A data warehouse contains anonymized customer transaction data used for analytics. The anonymization process removed direct identifiers and applied k-anonymity with k=10. An attacker obtains the dataset and attempts to re-identify individuals using auxiliary information. Which of the following best describes the residual privacy risk?

A.No risk because anonymization eliminates all PII
B.High risk because k=10 is too small to provide meaningful privacy
C.Low risk because k=10 ensures a group of at least 10 individuals
D.Moderate risk because k-anonymity does not protect against attribute disclosure if the group is homogeneous
AnswerD

This option correctly identifies a fundamental limitation of k-anonymity, known as the homogeneity attack. If all individuals within an equivalence class (a group of k records sharing identical quasi-identifiers) also share the same value for a sensitive attribute, then that attribute is effectively disclosed for everyone in the group. Despite the anonymity of individual identity, the sensitive information becomes known, leading to attribute disclosure and a moderate level of risk.

Why this answer

k-anonymity means each record is indistinguishable from at least k-1 other records, but attacks like homogeneity or background knowledge can still lead to re-identification, especially if auxiliary data is available.

30
MCQmedium

A company wants to ensure that data labeled 'Internal Use Only' is not inadvertently disclosed to unauthorized parties. What is the most effective way to communicate handling requirements to employees?

A.Using data loss prevention (DLP) software
B.Implementing a data classification policy and training employees on labeling and handling procedures
C.Encrypting all data at rest
D.Restricting access to the data through role-based access control
AnswerB

Implementing a robust data classification policy clearly defines what "internal use" data means, outlines specific labeling conventions, and details the mandatory handling procedures for such information. Coupled with comprehensive employee training, this approach directly communicates the organization's expectations and legal obligations to all personnel. This ensures employees understand their responsibilities and the implications of mishandling sensitive data, fostering a culture of compliance.

Why this answer

A data classification policy defines the categories (e.g., Public, Internal Use Only, Confidential) and the required handling procedures for each, and employee training ensures that everyone who creates or handles data knows how to label and protect it. This is the most effective way to communicate handling requirements because it establishes both the rule and the human behavior needed to follow it. Technical controls alone cannot fully prevent inadvertent disclosure by authorized users.

Exam trap

CISSP often tests the difference between administrative controls (policy, training) and technical controls (DLP, encryption, RBAC)—candidates may pick a technical control when the question asks how to communicate requirements to people.

How to eliminate wrong answers

Option A is wrong because DLP software is a technical enforcement tool that detects and blocks policy violations, but it does not communicate handling requirements to employees; it assumes the policy already exists and is known. Option C is wrong because encrypting all data at rest protects against physical theft or unauthorized storage access but does not address inadvertent disclosure by authorized users who can decrypt and share data. Option D is wrong because RBAC restricts access based on roles but does not tell employees how to handle data once they have access, nor does it prevent them from sharing it inappropriately.

31
Multi-Selecthard

A multinational corporation is implementing a data classification program. The information security manager must ensure that data is handled appropriately based on its classification level. The company operates in multiple jurisdictions, including the European Union and the United States. Which two of the following are key considerations when developing the data classification policy? (Choose two.)

Select 2 answers
A.Delegating classification decisions solely to the IT department
B.Defining clear criteria for each classification level based on data sensitivity and business impact
C.Aligning classification levels with legal and regulatory requirements in each jurisdiction
D.Ensuring that all data is classified as 'Confidential' by default to maximize protection
E.Implementing a single global classification scheme without considering local variations
AnswersB, C

Clear criteria ensure consistent application of classification levels across the organization. Without defined criteria, employees may classify data inconsistently, leading to either overprotection or underprotection. Criteria should consider factors such as confidentiality, integrity, availability, legal requirements, and business impact. This is essential for a successful data classification program.

Why this answer

Aligning classification with legal requirements and defining clear criteria are essential for a multinational data classification policy. Legal alignment ensures compliance across jurisdictions, while clear criteria promote consistent application. Other options are flawed: overclassification is inefficient, delegating solely to IT ignores business ownership, and a rigid global scheme fails to address local legal nuances.

Exam trap

The trap here is assuming that a one-size-fits-all classification scheme works globally, or that IT alone should classify data.

32
MCQhard

A company collects PII from European customers for order processing. Under GDPR, they engage a third-party logistics provider to handle shipping. Which role does the logistics provider typically assume in this scenario?

A.Data controller
B.Data custodian
C.Data processor
D.Data subject
AnswerC

The logistics provider processes PII solely on the controller's documented instructions for shipping, satisfying GDPR's Article 28 processor definition. It determines neither purposes nor means of processing, unlike a controller or joint controller. This distinction hinges on decision-making authority over processing, not data volume or technical access.

Why this answer

Under GDPR, the logistics provider processes personal data on behalf of the company and therefore assumes the role of data processor. The company that determines the purposes and means of processing is the data controller, and the processor acts only on the controller's documented instructions. This controller-processor relationship must be governed by a written data processing agreement.

Exam trap

CISSP often tests the confusion between controller and processor, and the invented-sounding 'data custodian' role, which is not a GDPR legal designation.

How to eliminate wrong answers

Option A is wrong because the data controller is the entity that determines why and how personal data is processed — here that is the company collecting PII, not the shipping vendor. Option B is wrong because 'data custodian' is not a GDPR-defined role; it is a term from other frameworks (like ITIL or internal data governance) referring to day-to-day data safekeeping, and it carries no GDPR legal meaning. Option D is wrong because the data subject is the individual whose personal data is being processed — the European customer — not the logistics provider.

33
MCQeasy

A data owner has classified a dataset as 'Confidential' in a commercial organization. Which of the following best describes the primary responsibility of the data owner for this dataset?

A.Determining the data's classification and ensuring it is labeled appropriately
B.Ensuring the data is accurate and complete
C.Implementing technical controls to protect the data
D.Performing daily backups of the data
AnswerA

The data owner holds ultimate accountability for the data, making them responsible for determining its classification level, such as "confidential," based on its business value, sensitivity, and regulatory compliance requirements. This classification dictates the necessary security controls and handling procedures. Furthermore, the data owner ensures that the data is appropriately labeled to communicate its sensitivity to all users and systems, thereby guiding its protection throughout its lifecycle.

Why this answer

The data owner is accountable for data classification and assigning protection requirements, while the custodian implements controls.

34
MCQeasy

Which of the following is the primary purpose of a configuration management database (CMDB) in asset management?

A.Store information about hardware and software components and their relationships
B.Track software licenses and compliance
C.Perform vulnerability scanning
D.Monitor network performance
AnswerA

A Configuration Management Database (CMDB) is fundamentally designed to serve as a centralized repository for detailed information about all Configuration Items (CIs) within an IT environment. This includes hardware assets, software applications, network devices, services, and documentation. Its primary purpose is to meticulously record the attributes of these components and, critically, map out their interdependencies and relationships, providing a comprehensive understanding of the IT infrastructure's structure and connections. This data is essential for effective IT service management processes.

Why this answer

A CMDB's primary purpose is to store information about configuration items (CIs) — hardware, software, and other assets — and the relationships between them. This relationship mapping supports impact analysis, incident management, and change management by showing how components depend on each other.

Exam trap

CISSP often tests the distinction between a CMDB and an asset inventory — candidates pick license tracking or scanning because they confuse asset management functions with the CMDB's relational purpose.

How to eliminate wrong answers

Option B is wrong because tracking software licenses and compliance is a function of license management or SAM tools, which may feed into a CMDB but are not its primary purpose. Option C is wrong because vulnerability scanning is performed by dedicated scanners (e.g., Nessus, Qualys), not by a CMDB. Option D is wrong because network performance monitoring is handled by monitoring tools (e.g., Nagios, SolarWinds), not by a CMDB.

35
MCQhard

An organization is implementing privacy by design for a new application that processes PII. Which practice BEST aligns with the data minimization principle?

A.Collecting only the PII required for the stated function.
B.Anonymizing data after collection.
C.Obtaining explicit consent from users.
D.Collecting all possible PII in case it is needed later.
AnswerA

This action directly embodies the Privacy by Design principle of data minimization, which mandates that organizations collect only the absolute minimum amount of personal identifiable information (PII) necessary to achieve a specified, legitimate purpose. By limiting data collection at the outset, the organization proactively reduces the attack surface and potential impact of a data breach, aligning with PBD's foundational, preventative approach rather than reactive measures.

Why this answer

Data minimization means collecting only the personal data that is necessary for the specified purpose. Collecting only the PII required for the stated function directly implements this principle by limiting the scope of data collection at the source, reducing privacy risk and compliance burden.

Exam trap

CISSP often tests the confusion between data minimization (collect less) and anonymization or consent (post-collection controls), tempting candidates to pick anonymization as the best minimization practice.

How to eliminate wrong answers

Option B is wrong because anonymizing data after collection does not minimize collection; it is a post-hoc risk reduction technique, and the data was still collected and processed. Option C is wrong because obtaining explicit consent addresses lawfulness and transparency, not minimization; consent does not justify collecting more data than needed. Option D is wrong because collecting all possible PII 'just in case' is the opposite of data minimization and violates privacy by design principles.

36
MCQmedium

An organization's data retention policy specifies that customer records must be retained for five years after the end of the business relationship. After that period, what should be done with the data according to best practices?

A.Continue retaining the data indefinitely for future use
B.Securely destroy the data
C.Archive the data to offline storage
D.Anonymize the data and keep it
AnswerB

Securely destroying the data is the correct action when its defined retention period has expired, as mandated by the organization's policy. This process involves irreversible sanitization methods, such as degaussing, cryptographic erasure, or physical destruction, to ensure the data cannot be reconstructed or accessed. This minimizes the organization's attack surface, reduces legal and regulatory compliance risks, and upholds data minimization principles by eliminating unnecessary data holdings.

Why this answer

Once the retention period expires, data should be securely destroyed to prevent unauthorized access and comply with privacy regulations.

37
MCQeasy

An organization's data retention policy requires that financial records be kept for seven years. After that period, the records must be destroyed in a manner that prevents reconstruction. Which of the following is the best sanitization method for paper records containing sensitive financial data?

A.Cross-cut shredding
B.Overwriting with random patterns multiple times
C.Cryptographic erasure
D.Degaussing with a strong magnetic field
AnswerA

Cross-cut shredding is the most appropriate physical destruction method for paper records containing sensitive financial data. This process cuts paper into small, irregular, confetti-like pieces, making reconstruction practically impossible, unlike strip-cut shredding which leaves longer strips. It ensures that the information cannot be recovered or deciphered, thereby meeting stringent data retention and destruction policy requirements for physical documents.

Why this answer

Cross-cut shredding is the best sanitization method for paper records because it physically destroys the paper into small, unreadable pieces, making reconstruction extremely difficult. It is a widely accepted method for destroying sensitive paper documents. Option A is correct as it meets the requirement to prevent reconstruction.

Exam trap

CISSP often tests the applicability of sanitization methods to different media types, and candidates may incorrectly choose degaussing or overwriting for paper records because they are familiar with those methods for electronic media.

How to eliminate wrong answers

Option B is wrong because overwriting with random patterns is a method for sanitizing magnetic media, not paper; it cannot be applied to paper records. Option C is wrong because cryptographic erasure involves destroying encryption keys for encrypted data, which is not applicable to paper records. Option D is wrong because degaussing uses a strong magnetic field to erase data on magnetic storage media, not paper.

38
MCQmedium

A database administrator (DBA) is responsible for implementing access controls and backup procedures for a customer database containing PII. The DBA reports to the data owner regarding security measures. Which role best describes the DBA's responsibilities?

A.Data steward
B.Data owner
C.Data custodian
D.Data processor
AnswerC

The data custodian, such as a Database Administrator (DBA), is responsible for the practical implementation and maintenance of security controls and data management tasks. They perform day-to-day operations like backups, access control enforcement, patching, and monitoring, ensuring the data's confidentiality, integrity, and availability as directed by the data owner. This role involves the technical execution of policies and procedures to safeguard the data assets.

Why this answer

A data custodian is the role responsible for the day-to-day operational handling of data, including implementing access controls, backups, and technical safeguards, while acting under the direction of the data owner. The DBA in this scenario performs exactly these operational duties and reports to the data owner, which matches the custodian role. The data owner retains ultimate accountability and sets policy, while the custodian executes it.

Exam trap

CISSP often tests the distinction between accountability (data owner) and operational responsibility (data custodian), tricking candidates into selecting 'data owner' simply because the DBA 'reports to' the owner or is described as responsible for security measures.

How to eliminate wrong answers

Option A is wrong because a data steward focuses on data quality, metadata, and business-level governance of data definitions, not on implementing technical access controls and backups. Option B is wrong because the data owner is the senior accountable role that determines classification and policy, not the one implementing operational controls; the DBA reports to the owner, so the DBA cannot be the owner. Option D is wrong because a data processor is an external entity (e.g., a third-party service provider) that processes data on behalf of the controller under GDPR, not an internal DBA implementing controls.

39
MCQmedium

Under the GDPR, which role is responsible for determining the purposes and means of processing personal data?

A.Data processor
B.Data controller
C.Data subject
D.Data protection officer
AnswerB

The data controller is the entity that, alone or jointly with others, determines the purposes (why data is processed) and the means (how data is processed) of personal data processing. This fundamental responsibility establishes their primary accountability under GDPR for compliance and safeguarding data subjects' rights. Their decision-making power over the processing lifecycle directly aligns with the question's premise.

Why this answer

Under the GDPR, the data controller is the entity (natural or legal person, public authority, agency, or other body) that alone or jointly with others determines the purposes and means of processing personal data. This role carries primary accountability for GDPR compliance, including lawful basis, data subject rights, and breach notification. The controller decides 'why' and 'how' data is processed, which is the defining characteristic of the role.

Exam trap

CISSP often tests the distinction between controller and processor, and candidates frequently confuse the two because both handle personal data; the key is that only the controller determines the purposes and means.

How to eliminate wrong answers

Option A is wrong because a data processor processes personal data on behalf of the controller and does not determine the purposes or means; the processor acts only on documented instructions from the controller. Option C is wrong because the data subject is the individual to whom the personal data relates, not an organizational role responsible for processing decisions. Option D is wrong because the Data Protection Officer (DPO) is an advisory and monitoring role that ensures compliance but does not determine the purposes and means of processing; the DPO may be mandatory in certain cases but is not the decision-maker.

Ready to test yourself?

Try a timed practice session using only Asset Security questions.