220-1102 exam dumps

220-1102 practice question 40 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 40

Single answerOther considerations

A support technician is preparing to decommission 25 company laptops that were used by multiple employees and contain confidential client data. The laptops will be donated to a local nonprofit. Management wants to reduce legal and security risk while keeping costs low. Which action should the technician take FIRST before the devices leave the company?

  1. A

    Perform a secure data wipe on each drive using an approved sanitization method and document the process

  2. B

    Delete user profiles and clear the Recycle Bin so the next users cannot access previous files

  3. C

    Remove the laptops from the domain and create new local administrator accounts for the nonprofit

  4. D

    Reinstall the operating system over the existing partitions and apply all current updates

Show answer and explanation

Correct answer: A

Explanation

This question tests an important A+ Core 2 'other considerations' objective: proper handling of devices during disposal, repurposing, or donation. In real environments, technicians must consider data privacy, legal exposure, and organizational policy when retiring hardware. Best practice is to sanitize storage media using an approved method before a device leaves company control. For reusable drives, logical sanitization such as secure erase or overwriting may be appropriate depending on the media type and company policy; for highly sensitive environments, physical destruction may be required instead. Documentation is also important for auditability and asset management. These practices align with common industry guidance such as NIST SP 800-88 media sanitization recommendations and standard organizational security policies for asset disposition.

  • A. Correct.

    Correct. Before devices are transferred outside the organization, the priority is protecting sensitive data through proper media sanitization. A secure wipe using an approved method is appropriate when the organization plans to reuse or donate the systems. Documenting the sanitization process also supports chain-of-custody, compliance, and asset disposition procedures. This is the best first step because it directly addresses the primary risk: unauthorized disclosure of confidential information.

  • B. Incorrect.

    Incorrect. Deleting profiles and emptying the Recycle Bin does not securely remove data. Files can often be recovered with forensic or recovery tools because the underlying data may remain on the drive until overwritten. This is a common misconception among less experienced technicians who confuse file deletion with data sanitization.

  • C. Incorrect.

    Incorrect. Removing devices from the domain and creating local accounts may be part of repurposing the systems, but it does not address the more urgent issue of residual confidential data on the storage media. If the laptops are donated without proper sanitization, sensitive information could still be recovered.

  • D. Incorrect.

    Incorrect. Reinstalling the OS is not the same as securely sanitizing the drive. Standard reinstallation may leave recoverable data in unallocated space or on existing partitions, depending on the installation method used. While reimaging might be appropriate after sanitization, it should not be the first action when data protection is the main concern.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam