Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium
A compliance officer is reviewing the organization's data handling policies to ensure adherence to privacy regulations like GDPR. They need to establish clear rules for how long different types of data should be kept and how they should be securely disposed of once their purpose is served. Which compliance concept is the officer primarily focused on?
- AeDiscovery
- BData Retention and Deletion
- CData Loss Prevention (DLP)
- DData Classification
Show answer & explanationAnswer & explanation
Correct answer: B. Data Retention and Deletion
Data Retention and Deletion rules define how long specific data must be kept for legal or business reasons, and the secure methods by which it should be permanently removed when no longer needed, directly addressing the scenario's requirements.
Why the other options are wrong
- A. eDiscovery is the process of identifying and preserving electronic data for legal cases, not general data lifecycle management.
- C. DLP prevents unauthorized exfiltration of data, not its lifecycle management.
- D. Data Classification categorizes data by sensitivity, not retention or deletion rules.
Data Retention and Deletion
The policies and processes that govern how long an organization keeps different types of data and how it is securely and permanently disposed of when no longer required.
- Critical for regulatory compliance (e.g., GDPR, HIPAA).
- Balances legal requirements with storage costs and privacy.
- Requires secure disposal methods to prevent data recovery.
Memory trick: Retention & Deletion: Keep what you must, trash what you don't.