220-1102 exam dumps

220-1102 practice question 745 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 745

Single answerRegulated data

A technician is replacing a doctor's laptop at a small medical clinic. The old laptop contains patient records, and the technician must prepare it to be sent to an external recycling company. The clinic manager wants to reduce risk of exposing regulated data and remain compliant with healthcare privacy requirements. Which of the following should the technician do FIRST?

  1. A

    Back up the patient files to a USB flash drive and include the drive with the laptop for the recycler

  2. B

    Perform a proper data wipe or physical destruction of the old drive according to company policy before disposal

  3. C

    Delete the patient files from the user profile and uninstall the electronic health record application

  4. D

    Remove the doctor's login account and then ship the laptop after a quick format

Show answer and explanation

Correct answer: B

Explanation

The best answer is to sanitize the drive before disposal. In this scenario, the laptop contains patient records, which are regulated data under healthcare privacy requirements such as HIPAA. When devices containing protected health information are retired, recycled, or reassigned, organizations should follow formal media disposal and sanitization procedures to prevent unauthorized disclosure. CompTIA A+ Core 2 expects candidates to recognize that regulated data requires stricter handling than ordinary business files. Best practices also align with NIST SP 800-88 Guidelines for Media Sanitization, which recommends methods such as clearing, purging, or destroying media based on risk and reuse requirements. Deleting files, uninstalling software, removing accounts, or performing a quick format does not adequately protect regulated data.

  • A. Incorrect.

    Incorrect. Backing up regulated patient data to an unprotected USB flash drive and sending it with the device increases the risk of unauthorized disclosure. For healthcare-related regulated data, removable media must be controlled, encrypted if used, and handled according to policy. Including the backup with the recycled device is not an appropriate disposal control.

  • B. Correct.

    Correct. Patient records are regulated data, and before a system is recycled or transferred, the storage media must be sanitized using an approved method such as secure wiping or physical destruction, depending on company policy and the media type. This aligns with common best practices for media sanitization and helps protect confidential healthcare information from unauthorized access.

  • C. Incorrect.

    Incorrect. Simply deleting files and uninstalling the application does not remove the underlying data from the drive. Deleted files can often be recovered with forensic tools. This is a common misconception when handling regulated data: removing visible access is not the same as securely sanitizing the storage media.

  • D. Incorrect.

    Incorrect. Removing the login account and performing a quick format is insufficient for regulated data. A quick format mainly removes file system references and does not reliably sanitize data. Someone might choose this option because it seems faster and more thorough than simple deletion, but it still does not meet proper disposal expectations for sensitive data.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam