220-1102 exam dumps

220-1102 practice question 484 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 484

Single answerSecure personally identifiable information (PII) and passwords

A technician is replacing several laptops for a human resources department. The old laptops contain spreadsheets with employees' Social Security numbers, salary data, and saved browser passwords for access to payroll systems. The laptops will be reassigned internally to a different department. Which action should the technician take FIRST to best protect sensitive data and credentials before reissuing the devices?

  1. A

    Delete the user profiles and empty the Recycle Bin on each laptop

  2. B

    Perform a secure wipe of the drives or reimage them using the organization's approved sanitization process

  3. C

    Disable browser password saving and require the next users to create new passwords

  4. D

    Move the HR files to an encrypted folder and rename the local administrator account

Show answer and explanation

Correct answer: B

Explanation

The key issue is protecting sensitive HR data, which includes personally identifiable information such as Social Security numbers and salary records, as well as stored authentication data like saved passwords. Before a device is reassigned, the technician should use the organization's approved sanitization process to remove old data so it cannot be recovered by the next user. This aligns with common security best practices for handling PII and credentials, including media sanitization guidance such as NIST SP 800-88 and general principles of least exposure and secure disposal/redeployment. Simply deleting files, changing settings, or relocating data is not sufficient when a system previously contained sensitive information.

  • A. Incorrect.

    This is incorrect. Deleting user profiles and emptying the Recycle Bin does not securely remove data from storage. Recoverable remnants of files, cached credentials, and browser data may still remain on the drive. This is a common misconception because the data appears to be gone from the user interface, but it is not sanitized.

  • B. Correct.

    This is correct. When devices containing PII and saved credentials are being reassigned, the best practice is to sanitize the storage media according to organizational policy, typically by secure wiping or approved reimaging procedures. This helps ensure that employee PII and stored passwords are not recoverable by the next user. In a real environment, the technician should follow the company's data handling and asset disposal or redeployment process.

  • C. Incorrect.

    This is incorrect. Disabling future password saving does nothing to address passwords and PII already stored on the device. The existing browser cache, profile data, and locally stored files could still expose sensitive information to the next user.

  • D. Incorrect.

    This is incorrect. Encrypting a folder and renaming the administrator account do not adequately protect data during reassignment. If the same system is reused, the sensitive files and credentials may still exist elsewhere on the drive, and account renaming does not sanitize stored PII or browser passwords. Someone might choose this option because encryption sounds secure, but it does not replace proper data sanitization before redeployment.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam