Certified Cloud Security Professional (CCSP)Cloud Data SecurityEasy
A company is using a cloud-based video conferencing platform. They store recordings of meetings, some of which contain sensitive business discussions. To meet legal and regulatory obligations, these recordings must be retained for exactly 5 years and then securely deleted. Which cloud data security concept directly addresses the '5 years and then securely deleted' aspect?
- AData Classification
- BData Archiving
- CData Backup
- DData Retention
Show answer & explanationAnswer & explanation
Correct answer: D. Data Retention
Data retention directly defines how long specific types of data must be kept and how they should be disposed of afterward. The requirement to keep data for 'exactly 5 years and then securely deleted' falls squarely under data retention policies.
Why the other options are wrong
- A. Data classification categorizes data based on sensitivity, which informs retention policies, but isn't the policy itself.
- B. Data archiving is about moving inactive data to long-term, cost-effective storage, not primarily about defining the exact duration and deletion.
- C. Data backup creates copies for recovery purposes, not for defining how long data must be kept or when it should be deleted.
Data Retention
A policy that defines the period for which specific types of data must be kept and specifies the procedures for their secure disposal once that period expires, driven by legal, regulatory, or business requirements.
- Defines how long data must be kept.
- Specifies secure disposal methods.
- Driven by compliance and legal needs.
- Part of a broader data lifecycle management strategy.
Memory trick: Retention sets the timer for data's life and death.