Courseiva
hardMultiple Choice

Legal Hold

Exhibit

Refer to the exhibit.

{
  "policy": {
    "id": "data-retention",
    "rules": [
      {
        "data_type": "PII",
        "retention_days": 365,
        "action": "delete"
      },
      {
        "data_type": "FinancialRecords",
        "retention_days": 2555,
        "action": "archive"
      }
    ],
    "exceptions": [
      {
        "reason": "Legal hold: Case 2024-007",
        "data_ids": ["FIN-001", "FIN-002"],
        "action": "preserve"
      }
    ]
  }
}

Refer to the exhibit. A legal hold exception preserves FinancialRecords FIN-001 and FIN-002. What is the correct action for FinancialRecords that are not under legal hold?

⚠ Common exam trap

Candidates often confuse retention with indefinite archiving. A retention policy dictates the maximum lifespan of data; once that lifespan is reached, the data must be destroyed/deleted to mitigate legal and security risks, unless a legal hold exception applies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

They should be deleted after 2555 days

In CISSP and general data lifecycle management, a retention policy defines the maximum period for which data should be kept. Once the retention period (e.g., 2555 days / 7 years) expires, the standard and legally compliant action is to securely destroy/delete the data to limit liability and adhere to data minimization principles (unless a legal hold is active). Archiving is a method of retention, not an action taken after the retention period expires. Therefore, Option C (deleted after 2555 days) is typically the correct compliance action, not Option B.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    They should be audited and then preserved indefinitely

    Why it's wrong here

    Auditing is a distinct process focused on verifying data integrity and compliance, separate from the prescribed retention action. While important, it does not automatically dictate indefinite preservation for all records. Standard data retention policies define specific durations and actions, such as archiving or deletion, based on data classification and regulatory requirements, not indefinite preservation. Indefinite preservation is typically an exception, reserved for data under a legal hold, which overrides routine retention schedules.

  • ✗

    They should be archived after 2555 days

    Why it's wrong here

    Financial records are subject to stringent regulatory requirements, often mandating their long-term preservation for audit and compliance purposes. Archiving after 2555 days, which equates to approximately seven years, aligns with common financial record retention periods stipulated by regulations such as Sarbanes-Oxley (SOX) or various tax laws. This action ensures the data remains accessible and verifiable for future reference while being moved off primary, more expensive storage solutions.

  • ✓

    They should be deleted after 2555 days

    Why this is correct

    Deleting financial records after 2555 days would directly violate most regulatory compliance mandates, which typically require these records to be retained and accessible for auditability over extended periods. The specified action for financial data is archiving, which preserves the data in a secure, immutable state for its required lifecycle, rather than permanent destruction. Deletion would render the organization non-compliant and unable to produce necessary documentation if requested by auditors or legal entities.

  • ✗

    They should be deleted after 365 days

    Why it's wrong here

    Deleting financial records after a mere 365 days is incorrect both in terms of the appropriate disposition action and the required duration for this critical data type. Such a short retention period for deletion is more commonly associated with certain types of Personally Identifiable Information (PII) or temporary operational data, not essential financial documentation. Financial records necessitate a significantly longer retention period, typically involving archiving, to meet extensive legal and regulatory obligations.

About these practice questions

Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.