Certified Information Systems Security Professional CISSP · Free Practice Question Easy

Question 66

We keep our backup data for as long as the information is usable or if we are required to by law, standards, or regulations. What is this an example of?
  • A Data protection policy
  • B Data destruction policy
  • C Data security policy
  • D Data retention policy
Reveal correct answer

Correct answer: D

Explanation

The correct answer: A data retention policy refers to the protocol set by an organization regarding how long it should keep certain types of data. This policy is often determined by several factors, including the usability of the information, as well as any legal, regulatory, or standard requirements. In the question, the example explicitly mentions retaining backup data based on its usefulness and legal or regulatory obligations, fitting precisely into the definition of a data retention policy. The incorrect answers: A data destruction policy outlines the procedures for discarding or deleting data that is no longer needed. It specifies the means and methods to ensure data is completely and securely destroyed when it reaches its end of life or is no longer relevant. The example in the question does not mention data destruction, only retention, hence it doesn't exemplify a data destruction policy. A data protection policy is a set of rules and guidelines that ensure sensitive or private data is secured from unauthorized access, data breaches, and other forms of data loss. While retaining backup data could be a part of data protection to ensure recovery from potential data loss, the specific example given doesn't directly indicate procedures for protecting data from unauthorized access or breaches. Therefore, it isn't a clear representation of a data protection policy. Data security policy refers to the strategies or measures taken by an organization to ensure the confidentiality, integrity, and availability of its data. It generally involves strategies to prevent unauthorized access, data modification, and data disclosure. While data retention could be a small part of a data security policy (in terms of maintaining the availability of data), the example does not mention specifics about maintaining confidentiality or integrity of data, making it less suitable to be categorized as a data security policy.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need