nerdexam
(ISC)2

CISSP · Question #650

What should an auditor do when conducting a periodic audit on media retention?

The correct answer is A. Check electronic storage media to ensure records are not retained past their destruction date. During a media retention audit, the auditor's primary responsibility is to verify that data is not kept beyond its authorized retention period, ensuring compliance with data lifecycle policies.

Submitted by carter_n· Mar 5, 2026Security Assessment and Testing

Question

What should an auditor do when conducting a periodic audit on media retention?

Options

  • ACheck electronic storage media to ensure records are not retained past their destruction date.
  • BEnsure authorized personnel are in possession of paper copies containing Personally Identifiable
  • CCheck that hard disks containing backup data that are still within a retention cycle are being
  • DEnsure that data shared with outside organizations is no longer on a retention schedule.

How the community answered

(41 responses)
  • A
    83% (34)
  • B
    5% (2)
  • C
    2% (1)
  • D
    10% (4)

Why each option

During a media retention audit, the auditor's primary responsibility is to verify that data is not kept beyond its authorized retention period, ensuring compliance with data lifecycle policies.

ACheck electronic storage media to ensure records are not retained past their destruction date.Correct

Checking electronic storage media to ensure records are not retained past their destruction date is the core objective of a media retention audit. Retention policies define how long data must be kept and when it must be destroyed; auditing compliance means verifying that expired records have been purged or destroyed on schedule, preventing unauthorized data retention and reducing legal and privacy risk.

BEnsure authorized personnel are in possession of paper copies containing Personally Identifiable

Ensuring authorized personnel possess paper copies of PII addresses physical document access control, not the retention lifecycle management that is the focus of a media retention audit.

CCheck that hard disks containing backup data that are still within a retention cycle are being

Checking that hard disks within an active retention cycle are properly stored addresses physical security or chain-of-custody concerns, not whether data is being held beyond its permitted retention period.

DEnsure that data shared with outside organizations is no longer on a retention schedule.

Ensuring data shared with outside organizations is off a retention schedule conflates third-party data-sharing agreements with internal media retention policy compliance, which are separate audit domains.

Concept tested: Media retention policy compliance and data lifecycle auditing

Source: https://csrc.nist.gov/publications/detail/sp/800-88/rev-1/final

Topics

#media retention#data destruction#security audit

Community Discussion

No community discussion yet for this question.

Full CISSP Practice