Courseiva

SSCP Security Operations and Administration Practice Question

A security administrator is implementing a formal data retention and destruction program for a financial services firm. The firm stores customer records, transaction logs, and email archives on a variety of media, including solid-state drives, magnetic tapes, and cloud object storage. Which TWO practices should the administrator include to ensure data is destroyed in a manner that is both effective and auditable? (Choose two.)

⚠ Common exam trap

The trap here is assuming a single overwriting method works on every media type and that a cloud provider's default terms are sufficient evidence of destruction.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Define retention periods by data category and apply destruction only after the retention period expires and any legal hold is released.

An effective destruction program pairs documented retention rules with verifiable destruction evidence. Retention periods must reflect legal and business requirements, with destruction delayed until holds are released. Certificates of destruction provide the audit trail that proves media was destroyed properly. Using one overwrite tool for all media, delegating without assurance, or merely storing expired media fails to deliver either effective destruction or the documentation auditors require.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Define retention periods by data category and apply destruction only after the retention period expires and any legal hold is released.

    Why this is correct

    Retention periods must be tied to legal, regulatory, and business requirements for each data category, and destruction should occur only after those periods end and any litigation hold is lifted. Destroying data too early can violate regulations or spoliation rules, while retaining it too long increases breach exposure. This practice ensures destruction is lawful, consistent, and defensible during audits or legal proceedings.

  • ✗

    Delegate all destruction activities to the cloud service provider and rely on the provider's standard terms of service for assurance.

    Why it's wrong here

    While a cloud provider may perform physical media destruction, the firm remains accountable for its data and must obtain specific contractual assurances, such as deletion certificates or audit reports. Standard terms of service rarely provide the granular evidence regulators expect. Relying solely on the provider removes the organization's ability to verify that destruction occurred as required, leaving compliance and audit gaps.

  • ✗

    Use the same overwriting utility on all media types to simplify the destruction procedure and reduce training requirements.

    Why it's wrong here

    A single overwriting utility cannot be effective across solid-state drives, magnetic tapes, and cloud object storage because each medium has different physical and logical characteristics. Overwriting is unreliable on SSDs due to wear leveling and on tapes due to their linear recording format. Cloud object storage is managed by the provider and may require cryptographic erasure or provider-specific deletion APIs. Standardizing on one tool creates gaps in destruction coverage.

  • ✓

    Maintain a certificate of destruction that records the media type, serial number, method used, date, and the personnel who performed the destruction.

    Why this is correct

    A certificate of destruction provides the audit evidence that regulators and internal auditors require to confirm that records were destroyed according to policy. Recording media type, serial number, method, date, and responsible personnel creates an unbroken chain of custody. Without this documentation, the organization cannot demonstrate compliance with retention schedules, and the destruction process becomes unverifiable even if the media was actually erased.

  • ✗

    Store all media in a locked room after the retention period expires until the media can be reused for other purposes.

    Why it's wrong here

    Storing expired media in a locked room does not destroy the data and extends the period during which it is exposed to theft, loss, or unauthorized access. Reusing media that contained regulated records without proper sanitization can also cause data leakage. Retention beyond the required period contradicts the principle of minimizing data at rest and increases both storage cost and legal discovery burden.

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.