Security and Risk Management Question #53

While gathering personal data from potential customers for marketing purposes, which of the following options is the most effective for ensuring compliance with GDPR regulations?

A. Collect only required data, use it possibly only after tokenization, and respect Retention Policies.
B. Collect only required data, use it possibly only after Pseudonymization, and erase as soon as possible.
C. Backup data daily, encrypt data before any usage, and erase as soon as possible.
D. Encrypt and hash data before any usage, and inform Data Subject of any PII modification.
Domain Concept: Security and Risk Management

This scenario evaluates management-level decision making in Security and Risk Management. In CISSP exam scenarios, evaluate answers through executive governance, risk assessment, life safety, and due diligence before implementing technical controls.

💡 View the Answer & Detailed Explanation

The correct answer to this scenario-based question requires an understanding of the CISSP Managerial Mindset. Register to view our in-depth explanation and access 1100+ adaptive questions completely free.

Fuel the Mission ☕

Keep the vault updated and the servers running.

$
Secure Payment via PayPal

Verified Excellence

Spread the Word

If you like us, share us with your peers.

Scroll to Top