A company needs to keep the fewest records possible, meet compliance needs, and ensure destruction of records that are no longer needed. Which of the following best describes the policy that meets these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Retention policy.
Why this is the answer
A retention policy defines how long specific types of data or records must be kept and when they should be securely disposed of. This directly addresses the need to keep the fewest records possible, meet compliance requirements (which often dictate minimum retention periods), and ensure destruction of unneeded records. A security policy is too broad, covering overall security objectives and rules, but not specifically data lifecycle management. A classification policy categorizes data based on sensitivity, which is a prerequisite for a retention policy but doesn't define retention periods itself. An access control policy dictates who can access what resources, which is unrelated to how long data is stored.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed