CISSP Practice Question (Domain 2: Asset Security / Data Lifecycle & Retention)
An organization migrating legacy file shares to a cloud collaboration platform discovers that several datasets contain regulated records with no documented retention periods or data owners.
The business wants immediate migration to meet a project deadline.
What should the security manager do FIRST?
A. Migrate the data and address ownership and retention after cutover
B. Identify data owners and define retention requirements before migration
C. Apply default retention policies to all datasets to avoid delay
D. Escalate the issue to legal and halt the migration indefinitely
3
17 comments
Vincent Primiani
7
CISSP Practice Question (Domain 2: Asset Security / Data Lifecycle & Retention)
CISSP Study Group
skool.com/cybersecurity-study-group
Share resources, get advice, and connect with peers studying cybersecurity. Join our CISSP study group and connect with fellow professionals today!
Leaderboard (30-day)
Powered by