Courseiva
Security and Risk ManagementmediumMultiple ChoiceObjective-mapped

CISSP Security and Risk Management Practice Question

Under GDPR, which of the following is a valid lawful basis for processing personal data?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Vital interests

GDPR Article 6 lists lawful bases including consent, contract, legal obligation, vital interests, public task, and legitimate interests. 'Vital interests' is a valid basis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Corporate policy

    Why it's wrong here

    Corporate policy, while crucial for internal governance and operational consistency, does not independently serve as a lawful basis for processing personal data under GDPR Article 6. GDPR explicitly requires a specific legal ground, such as consent, contract, legal obligation, vital interests, public task, or legitimate interests, to justify data processing activities. An internal policy merely dictates how an organization operates, not the legal permissibility of its data handling, meaning reliance solely on such a policy would result in non-compliance.

  • Profit motive

    Why it's wrong here

    Profit motive, while a primary driver for commercial enterprises, is not recognized as a standalone lawful basis for processing personal data under the GDPR. The desire for financial gain may underpin activities that could potentially be justified under the 'legitimate interests' basis, but only if a strict balancing test is performed. This test must demonstrate that the organization's interests are not overridden by the fundamental rights and freedoms of the data subject, making mere profit a insufficient justification.

  • Marketing preference

    Why it's wrong here

    Marketing preference refers to an individual's expressed choice regarding the receipt of marketing communications, or their opt-in/opt-out status. This preference itself is not a lawful basis for processing personal data under GDPR. Instead, the processing of data for marketing purposes must be justified by a specific lawful basis, typically either the data subject's explicit consent or the organization's legitimate interests, provided a robust impact assessment and balancing test are conducted. The preference merely dictates the scope or permissibility of marketing activities under an established basis.

  • Vital interests

    Why this is correct

    Vital interests is a lawful basis under GDPR Article 6(1)(d) that permits the processing of personal data when it is necessary to protect the life of the data subject or another natural person. This basis is typically invoked in emergency situations where obtaining consent is impossible or impractical, such as medical emergencies, humanitarian crises, or public health threats. It represents a very high threshold and is generally reserved for situations involving a serious threat to life or physical integrity, making it a basis of last resort rather than routine processing.

About these practice questions

One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.