Courseiva
easyMultiple SelectObjective-mapped

CISSP Practice Question: Which TWO of the following are principles of the…

Which TWO of the following are principles of the data minimization concept under privacy regulations such as GDPR?

⚠ Common exam trap

ISC2 often tests the distinction between the seven GDPR principles (lawfulness, fairness, transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; accountability) and the data subject rights (access, rectification, erasure, etc.), so candidates mistakenly select a right like access as a minimization principle.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Collect only the personal data that is directly relevant and necessary for the specified purpose

Data minimization under GDPR (Article 5(1)(c)) requires that personal data collected be 'adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.' This principle directly mandates collecting only the data that is directly relevant and necessary for the specified purpose, preventing over-collection and reducing privacy risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Ensure personal data is accurate and kept up to date

    Why it's wrong here

    This statement describes the "Accuracy" principle, which mandates that personal data must be accurate and, where necessary, kept up to date throughout its lifecycle. While crucial for maintaining data integrity, ensuring fairness to data subjects, and supporting reliable decision-making, it is distinct from data minimization, which focuses on limiting the volume and scope of data collected and processed in the first place, rather than its quality after collection.

  • Collect only the personal data that is directly relevant and necessary for the specified purpose

    Why this is correct

    This option directly reflects a core aspect of data minimization, which dictates that organizations should only collect personal data that is absolutely essential and directly pertinent to achieving a clearly defined, legitimate purpose. By restricting initial data acquisition to the minimum required, it prevents unnecessary accumulation, reduces the potential attack surface, and mitigates privacy risks associated with holding excessive or irrelevant data.

  • Store personal data for as long as possible for future analysis

    Why it's wrong here

    Storing personal data "as long as possible" directly contradicts both the principle of data minimization and the related principle of storage limitation. Data minimization requires that data retention periods be strictly limited to what is necessary for the original specified purpose, or for legal/regulatory obligations, thereby preventing indefinite storage and reducing long-term risk exposure. Indefinite retention for speculative future analysis is a clear violation of these principles.

  • Limit the processing of personal data to only what is necessary for the intended purpose

    Why this is correct

    This statement accurately describes another critical facet of data minimization, emphasizing that even after collection, the subsequent processing activities involving personal data must be strictly limited to what is genuinely necessary to fulfill the explicitly stated and legitimate purpose. This includes restricting access, operations, and sharing of data, ensuring that data is not used or exposed beyond its intended scope, thereby minimizing privacy impact and potential misuse.

  • Provide individuals with access to their data upon request

    Why it's wrong here

    Providing individuals with access to their data upon request is a fundamental aspect of data subject rights, specifically the "Right of Access," which empowers individuals to review their personal information held by an organization. While vital for transparency, accountability, and enabling other rights like rectification, this principle is separate from data minimization, which focuses on reducing the volume and scope of data collected and processed from the outset, rather than managing access to existing data.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.