220-1102 Question 747
Single answerPersonal government-issued informationA help desk technician is decommissioning several office laptops that were used by HR staff to process employee onboarding forms. During a spot check, the technician finds scanned copies of driver's licenses and Social Security cards stored in a local folder on one of the systems. The laptops will be reassigned internally to another department. Which action should the technician take FIRST to best protect this type of data and follow security best practices?
- A
Move the files to a shared network folder so HR can access them later, then delete the local copies
- B
Use the organization's approved data sanitization and disposal procedure to securely remove the files before reassignment
- C
Rename the folder and restrict it so only administrators can access it on the reassigned laptop
- D
Compress the files into a password-protected archive and leave them on the laptop for future audits
Show answer and explanation
Correct answer: B
Explanation
Personal government-issued information, including documents such as driver's licenses and Social Security cards, must be handled as highly sensitive data. In a real support scenario, the best first step is to follow the organization's approved data retention, sanitization, and device reassignment procedures so the information is securely removed from systems that no longer need it. This aligns with common security principles such as least privilege, data minimization, and secure disposal. CompTIA A+ Core 2 emphasizes identifying sensitive information types and applying appropriate operational security controls during device reuse, disposal, and reassignment. If business retention is required, that should occur only through approved storage locations and documented procedures, not by leaving the data on the endpoint.
- A. Incorrect.
This is incorrect because moving sensitive personal government-issued information, such as driver's license and Social Security card scans, to a shared location does not address the immediate problem of improper storage on a device being reassigned. It may also expand exposure if the share is not specifically approved for regulated or sensitive data. A candidate might choose this because preserving business records sounds helpful, but the first priority is to protect and properly handle the sensitive data according to policy.
- B. Correct.
This is correct because scanned government-issued identifiers are highly sensitive personal information and should not remain on a device being repurposed. The technician should follow the organization's approved sanitization and disposal process to securely remove the data before reassignment. In CompTIA A+ Core 2, proper handling of sensitive data includes minimizing exposure, following policy, and using secure disposal or sanitization methods rather than ordinary deletion.
- C. Incorrect.
This is incorrect because access controls alone are not sufficient when the system is being reassigned and the data is no longer needed on that endpoint. Leaving the files on the laptop increases the risk of unauthorized disclosure. Someone might choose this option because permissions are a valid security control, but they are not the best first action for unnecessary sensitive data on a repurposed device.
- D. Incorrect.
This is incorrect because password-protecting an archive is not a substitute for proper data handling and secure removal. The files would still remain on the laptop, creating unnecessary risk. This distractor reflects the common misconception that simple password protection by itself is enough to safeguard highly sensitive records, especially when the device is changing custody.