Preserve held records without retaining expired copies

A hands-on CISSP lab. You produce the real artefact and 8 automated checks verify it behaves the way the exam expects.

Try this labAll CISSP practice

Certification
CISSP
Format
Structured configuration
Difficulty
medium
Estimated time
35 min
Automated checks
8

The brief

Edit disposal-plan.json. actions is an ordered ledger with unique id, whole-number day, op and actor. Use nondecreasing days starting at 1. custodian may copy, purge-records, unlink-object or purge-object; key-officer may sanitize-key only. copy also needs source, target and a nonempty records list. It copies ordinarily readable records to an active readable destination; it cannot mint, overwrite or recreate purged objects. purge-records needs target and records; it removes exactly those members only where supported. unlink-object and purge-object need target: unlink removes ordinary access but leaves content recoverable; the supplied approved purge removes all object members. sanitize-key needs key and slot; it effectively sanitizes that one actual key copy, not just its metadata. Any surviving key copy can decrypt all objects using that key. An incomplete-encryption history would leave plaintext recoverable even after every key copy is gone. Failed operations have no content effect and fail feasibility. Physically feasible operations are replayed even with a wrong actor or destination; custody fails separately. Preserve at least one ordinarily readable copy continuously through each retention/hold date, including between same-day actions. By each disposal deadline, no recoverable copy of that record may remain or later reappear. Isolate the held cohort and dispose of mixed copies, using effective key sanitization or approved object purge. reports needs one row for days 20,30,45,50: day, readable and recoverable distinct record IDs, copyCount and units. Count each recoverable record-object pair and its units once, including unlinked content; do not count inaccessible ciphertext as recoverable when all stated encryption/key assurances hold. Reports are end-of-day snapshots after that day's actions. Reconcile them with the ledger rather than declaring successful deletion.

What the checks verify

Your work is graded on 8 independent properties, not on matching one reference answer.

  • Distinct typed actions and complete report rows.
  • Chronologically executable operations honor source readability and actual capabilities.
  • Every operator and destination respects delegated duties and record classification.
  • Every record remains retrievable throughout its inclusive minimum-retention interval.
  • Held evidence remains continuously retrievable through the supplied release day.
  • Unheld expired data is absent from all recoverable copies by its deadline.
  • Released held data is absent from all recoverable copies by its extended deadline.
  • Cut-date populations, record-object counts and copied units reconcile with actual replay.

Where this sits in the CISSP blueprint

Domain
Asset Security
Objective
Data Lifecycle
Skill
Collection, Retention and Disposal

Part of CISSP preparation

Labs are written by ExamNova to teach the decisions the exam tests. They are not reproductions of vendor lab content.