SSCP Security Operations and Administration Practice Question
A security administrator is reviewing the organization's data retention policy. The policy states that customer financial records must be kept for seven years, but the IT team currently archives them indefinitely. Which action should the administrator take to align data handling with the policy while preserving records for legal discovery?
⚠ Common exam trap
The trap here is assuming that reducing storage cost or reclassifying data satisfies a retention policy, when the policy actually requires a specific retention duration and purge.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the archival system to apply a retention period of seven years and automatically purge records after that period.
The correct action is to enforce the documented seven-year retention with automatic purge. That aligns operational data handling with policy, reduces long-term breach impact, and still preserves records during the required legal window. Indefinite retention, immediate deletion, or reclassification all fail to meet the policy's specific retention requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Delete all archived financial records immediately to reduce the organization's data footprint.
Why it's wrong here
Immediate deletion violates the seven-year retention requirement and could destroy records needed for legal discovery or regulatory audit. The policy permits keeping data for seven years, not zero. This action would create compliance violations and potentially spoliation issues, so it is not an appropriate alignment step.
- ✓
Configure the archival system to apply a retention period of seven years and automatically purge records after that period.
Why this is correct
Setting a seven-year retention with automatic purge directly enforces the documented policy and limits unnecessary data exposure. It satisfies legal hold requirements during the retention window while reducing storage and breach impact afterward. This is the corrective action that brings technical controls in line with the approved data retention policy.
- ✗
Move the archived records to a lower-cost storage tier and continue retaining them indefinitely.
Why it's wrong here
Changing storage tier addresses cost, not policy compliance. Indefinite retention still contradicts the seven-year limit and prolongs the organization's discovery and breach exposure. A security administrator must enforce the retention schedule, not merely optimize where the noncompliant data lives.
- ✗
Reclassify financial records as public so they are exempt from retention requirements.
Why it's wrong here
Reclassification does not override legal retention obligations and would improperly expose sensitive customer financial data. Public classification typically removes confidentiality protections, which is the opposite of what a security administrator should do. Retention policy applies regardless of classification label, so this does not solve the alignment problem.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.