ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During a GDPR gap analysis, you are asked how the SaaS platform will fulfil a user's "right to be forgotten" request. Which approach best demonstrates compliance for personal data that also exists in nightly encrypted backups?
Purge the records from production databases at once and configure backup retention so the same records are automatically overwritten or cryptographically shredded at the next scheduled rotation.
Mark the records as inactive, deny further processing, but leave all identifiers in both production and backup datasets indefinitely.
Encrypt the records with a new key held only by administrators and document that as equivalent to deletion.
Delete the records from live systems yet keep them in the analytics data lake and backups for trend analysis purposes.
GDPR Article 17 requires that personal data be erased "without undue delay" unless a lawful basis to retain it exists. Because backups are created only for resilience, the data controller must ensure those copies are also permanently removed. The standard way is to overwrite or delete the data in active systems immediately and rely on the normal backup retention cycle to expire, guaranteeing that, when a backup is restored or reaches its retention limit, the data is either anonymised or deleted before becoming accessible again. Merely flagging, encrypting, or isolating the data keeps it identifiable and therefore does not satisfy the erasure requirement.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is GDPR Article 17?
Open an interactive chat with Bash
What is cryptographic shredding?
Open an interactive chat with Bash
How do backup retention policies support GDPR compliance?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Requirements
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .