About this interactive
The data lifecycle is usually met as a list of seven words, and a student who can recite them still cannot say what is actually protecting the data at any one of those stages — which is the part the job and the exam both ask about. Closing that gap is what this set is for, and it is why no card opens with its stage name. Each card describes what is happening to the data and which controls apply while it is happening, and names its stage only at the end, so the security work is read first and the vocabulary attaches to behaviour rather than standing in for it. The controls are the real content. Creation is where an owner is assigned and a label applied, and the reason that counts as a control at all is that everything downstream depends on it: a DLP engine cannot stop the exfiltration of a file nobody ever marked sensitive. Classification is the decision the whole rest of the lifecycle turns on — the label determines whether encryption is mandatory, who may be granted access, how long the data is kept and how it is eventually destroyed — and classifying too high is a real failure mode rather than a safe default, because a policy that over-protects trains staff to route around it. Storage is data at rest, so the controls assume an attacker who reaches the media: encryption at rest with the key management that makes it mean anything, and access control enforcing least privilege for the case encryption does not cover, which is an authorized account that has been compromised. Use is data decrypted in memory in front of someone, so the controls move from protecting media to authorizing people: authentication and authorization on each access, need-to-know, access logging, TLS on the network hop, and masking so work can happen without the full value ever being displayed. Sharing is the boundary crossing, and it is where the label applied back at creation finally earns its keep — DLP inspects outbound content against that label, an encrypted channel protects the transfer, and rights management is the only control that retains any authority once the file is on someone else's machine. Archival and Destruction are the pair students most often collapse into each other, and the distinction is a retention clock: archival is a holding pattern with an expiry date, still encrypted, still access-reviewed, still restore-tested; destruction is what happens when that clock runs out. The last card carries the point the module's own lesson makes hardest — deleting a file removes the pointer and leaves the contents recoverable with tools anyone can download, so real sanitization means overwriting, degaussing, cryptographic erase or physical destruction, with a certificate of destruction as the evidence, because in an audit an organization has to prove the data is gone rather than assert it. All seven stages are presented on every run rather than sampled. This is the naturally finite domain the pool guideline makes an exception for: a lifecycle with a stage removed is not a shorter version of the same object, it is a broken chain, and the chain is the entire skill being assessed. Padding it would mean inventing stages the model does not have. This pairs with fscs-05-0040, Confidentiality — Data Lifecycle, which teaches the same arc in three coarser phases (creation, management, retirement); run this after that lesson, and after the Data Classification Sorter, so the label the second stage produces is already familiar when this set asks what depends on it.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →