220-1102 Question 750
Single answerData retention requirementsA medical office is replacing several Windows workstations that contain locally stored patient billing records and scanned insurance forms. Company policy states that records related to patient care and billing must be retained for several years to meet legal and business requirements. Before the old PCs are disposed of, the technician must ensure the organization can still access the required records if audited later. Which action should the technician take FIRST to best meet the data retention requirement?
- A
Back up the required records to an approved long-term storage location according to company policy, then document where the data was archived
- B
Delete the files from the local drives so unauthorized users cannot access them during disposal
- C
Reformat the drives and reinstall Windows so the records are no longer visible to end users
- D
Move the files to a shared folder on another employee's workstation to keep a copy available
Show answer and explanation
Correct answer: A
Explanation
The key issue is the difference between data retention and data disposal. Retention requirements mean data must be preserved for a defined period based on company policy, legal obligations, regulatory rules, contracts, or business needs. In a real support scenario, a technician should first verify that required data has been archived to an approved, managed location and that the retention process is documented. Only after that should the organization proceed with secure disposal or sanitization of the old systems. This aligns with common security and records-management best practices: identify data that must be retained, store it in an authorized repository, maintain availability for future retrieval, and document the process. On A+ Core 2, candidates should recognize that protecting confidentiality through deletion or drive wiping does not replace the separate obligation to retain required records.
- A. Correct.
Correct. Data retention requirements focus on preserving required business or regulated data for the necessary period and ensuring it remains retrievable. The technician should first archive or back up the records to an approved retention location, such as a managed file server, document management system, or backup/archive platform defined by policy. Documenting the archive location supports later retrieval for audits, legal requests, or business needs.
- B. Incorrect.
Incorrect. Deleting the files may help reduce exposure on the old systems, but it does not satisfy the retention requirement. If the organization must keep the records for a defined period, deleting them before they are properly archived could create a compliance and business continuity problem.
- C. Incorrect.
Incorrect. Reformatting or reinstalling the OS addresses system reuse or basic sanitization concerns, not retention. It may actually destroy the only remaining copy of required records if no approved archive exists. Retention must be handled before any disposal or sanitization step.
- D. Incorrect.
Incorrect. Copying regulated or important records to another employee's workstation is not an appropriate retention method. A user workstation is not typically an approved archival repository, may lack backups and access controls, and makes retrieval and chain of custody more difficult.