Data Retention Policy for Compliance and Destruction

Answer Correct answer: C — Implement a retention policy that defines the duration for keeping records and mandates their secure destruction when no longer needed to meet compliance and data minimization goals.

A company needs to keep the fewest records possible, meet compliance needs, and ensure destruction of records that are no longer needed. Which of the following best describes the policy that meets these requirements?

  1. Security policy
  2. Classification policy
  3. Retention policy Correct Answer
  4. Access control policy

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the ability to distinguish between general security policies and specific lifecycle management rules, specifically highlighting that retention policies handle both storage duration and mandatory disposal.

A retention policy defines the duration for which records are kept and mandates their secure destruction when no longer needed, balancing compliance with data minimization. This page explains why this is the correct answer (C) among the given options.

Learners often select 'Security policy' because it covers broad protection, but fail to recognize that only a retention policy explicitly governs the timeline of existence and subsequent destruction of records.

Community Discussion (4 comments)

shady23 👍 1 Selected: C
C. Retention policy
Gregi 👍 1 Selected: C
C. Retention policy
salah112 👍 1 Selected: C
C. Retention policy A retention policy is designed to specify how long data or records should be kept, and it includes guidelines for the secure destruction of records when they are no longer needed. This helps organizations meet compliance requirements while minimizing the amount of data they retain, thereby enhancing security and privacy. Retention policies define the duration for which specific types of records need to be retained and outline the procedures for securely disposing of them when they reach the end of their lifecycle.
Hs1208 👍 2 Selected: C
C. Retention policy A retention policy is designed to specify the duration for which records or data should be retained and the procedures for their disposal when they are no longer needed.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A retention policy is the specific governance document that dictates how long data must be kept to satisfy legal or regulatory obligations and when it should be securely destroyed. By establishing these timeframes, organizations can adhere to the principle of data minimization, keeping the fewest records possible while ensuring compliance. The inclusion of destruction procedures in the policy directly addresses the requirement to eliminate unnecessary data.

Why the Other Options Are Wrong

A security policy provides broad guidelines for protecting information assets but does not specify timelines for data lifecycle management. A classification policy organizes data by sensitivity levels to determine appropriate handling controls, not retention periods. An access control policy defines who can interact with data and how, but it does not govern how long the data exists or its eventual disposal.

Community Comment Notes

The community consensus strongly supports option C, noting that retention policies are designed to specify data duration and disposal procedures. As user Hs1208 noted, "A retention policy is designed to specify the duration for which records or data should be retained and the procedures for their disposal when they are no longer needed." Similarly, salah112 emphasized that these policies help minimize retained data while enhancing security and privacy through secure destruction.

Exam Strategy

When a question mentions 'how long' data is kept or 'destruction' of old records, immediately look for keywords related to lifecycle or retention. Distinguish between policies that define access (who) versus those that define time (when).

Frequently Asked Questions

Why isn't a security policy the best answer?

Security policies are broad frameworks for protecting assets. They do not typically include specific operational directives on how long data must be retained or the technical steps for its destruction.

Does a retention policy cover legal compliance?

Yes, retention policies are primarily driven by legal and regulatory requirements. They ensure data is kept only as long as necessary to satisfy these laws before being destroyed.

Related Analysis

← Back to SY0-601 Study Guide