nerdexam
CompTIA

CAS-001 · Question #276

Which of the following is used to provide for the systematic review, retention and destruction of documents received or created in the course of business?

The correct answer is D. Document retention policy. A document retention policy defines the systematic processes for reviewing, retaining for required periods, and securely destroying business records in compliance with legal and regulatory obligations.

Integration of Computing, Communications and Business Disciplines

Question

Which of the following is used to provide for the systematic review, retention and destruction of documents received or created in the course of business?

Options

  • ADocument compliance policy
  • BDocument entitled policy
  • CDocument research policy
  • DDocument retention policy

How the community answered

(27 responses)
  • A
    7% (2)
  • C
    4% (1)
  • D
    89% (24)

Why each option

A document retention policy defines the systematic processes for reviewing, retaining for required periods, and securely destroying business records in compliance with legal and regulatory obligations.

ADocument compliance policy

A document compliance policy addresses adherence to external standards and regulations broadly, not the specific lifecycle management of individual records.

BDocument entitled policy

'Document entitled policy' is not a recognized information governance term and has no defined function in records management practice.

CDocument research policy

A document research policy would govern how documents are located or referenced for research purposes, not how they are retained over time or destroyed.

DDocument retention policyCorrect

A document retention policy is the formal governance instrument that governs the entire lifecycle of organizational records - from creation through storage to destruction - ensuring compliance with laws such as HIPAA, SOX, and GDPR that mandate specific retention schedules. It defines who is responsible for retention decisions, how long each document type must be kept, and what destruction methods are acceptable. Without it, organizations risk regulatory penalties and adverse legal inferences from improper destruction.

Concept tested: Document retention policy and records lifecycle management

Source: https://csrc.nist.gov/publications/detail/sp/800-188/final

Topics

#document retention policy#records management#compliance#data lifecycle

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice