220-1102 exam dumps

220-1102 practice question 748 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 748

Single answerPII

A help desk technician is replacing a failed laptop for an employee in the HR department. Before shipping the old laptop to a third-party repair vendor, the technician notices the device contains spreadsheets with employee names, home addresses, Social Security numbers, and payroll details. The company policy requires technicians to protect sensitive data and disclose only what is necessary for support. Which action should the technician take FIRST?

  1. A

    Back up the user's files and send the laptop to the vendor with a note that the data is confidential

  2. B

    Remove or sanitize the drive before the laptop leaves company control, following company policy for handling sensitive data

  3. C

    Email the spreadsheets to the repair vendor so the vendor can verify the laptop belongs to the company

  4. D

    Ask the employee to delete personal files, then ship the laptop once the Recycle Bin is emptied

Show answer and explanation

Correct answer: B

Explanation

This question tests recognition and proper handling of PII in a real support workflow. Names, addresses, Social Security numbers, and payroll data are examples of personally identifiable and sensitive information that must be protected from unauthorized access. In an A+ Core 2 context, technicians are expected to follow security best practices such as least privilege, need-to-know access, and proper media sanitization before sending systems to vendors, repair depots, or disposal channels. Best practice is to follow organizational policy for data handling and sanitization so that only the minimum necessary information is exposed. Guidance from sources such as the U.S. National Institute of Standards and Technology (NIST), including media sanitization guidance in SP 800-88, supports securely clearing or sanitizing storage media before transfer when sensitive data is present.

  • A. Incorrect.

    This is incorrect. Simply labeling data as confidential does not protect personally identifiable information (PII). If the device is sent with intact HR records, the vendor could access sensitive data. Backing up files may be appropriate as part of the replacement process, but it does not address the immediate risk of unauthorized exposure of PII.

  • B. Correct.

    This is correct. The spreadsheets contain clear examples of PII and highly sensitive data, including Social Security numbers and payroll information. The technician should follow organizational procedures to remove, sanitize, or otherwise protect the data before the system is transferred outside the organization. This aligns with the principle of minimizing exposure and protecting sensitive information during disposal, repair, or transfer.

  • C. Incorrect.

    This is incorrect. Sending PII to a third party without a documented need and authorization violates least privilege and data minimization practices. The vendor does not need employee Social Security numbers or payroll details to repair hardware. Sharing the files would increase the risk of a data breach.

  • D. Incorrect.

    This is incorrect. Having the employee delete files and empty the Recycle Bin is not a secure data protection method. Deleted files may still be recoverable unless the drive is properly sanitized according to policy. This option reflects a common misconception that normal deletion is equivalent to secure removal.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam