Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityHard
A compliance officer is reviewing the organization's data handling policies to ensure adherence to a new privacy regulation. The regulation mandates that customer data must be deleted upon request within a specific timeframe and that its retention period is strictly limited. Which compliance concept is most directly addressed by these requirements?
- AData Retention and Deletion
- BInformation Protection
- CData Loss Prevention (DLP)
- DData Classification
Show answer & explanationAnswer & explanation
Correct answer: A. Data Retention and Deletion
Data Retention and Deletion policies define how long data should be kept and when and how it should be securely disposed of. The scenario explicitly mentions 'data must be deleted upon request within a specific timeframe' and 'retention period is strictly limited', which are the core aspects of data retention and deletion.
Why the other options are wrong
- B. Information Protection is a broad term encompassing many security aspects, but not specifically the lifecycle of data retention and deletion.
- C. DLP prevents unauthorized sharing of data, not its lifecycle management.
- D. Data Classification categorizes data by sensitivity, but doesn't dictate its lifecycle.
Data Retention and Deletion
Policies and practices governing how long data is stored and the secure methods used for its disposal when no longer needed or legally required.
- Essential for compliance with privacy regulations (GDPR, CCPA).
- Minimizes risk by not retaining data longer than necessary.
- Involves secure deletion methods to prevent recovery.
Memory trick: Retention: Remember to Release and Remove.