SY0-701 exam dumps

SY0-701 practice question 143 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 143

Single answerDecommissioning

A healthcare company is decommissioning several storage arrays that previously held patient records and internal financial data. Some drives will be returned to a leasing vendor, while others have failed and cannot be overwritten. The security administrator must reduce the risk of data exposure and satisfy regulatory expectations for handling sensitive data during the retirement process. Which action is the BEST choice?

  1. A

    Format all drives, update the asset inventory, and ship them to the vendor

  2. B

    Use cryptographic erasure for functional encrypted drives and physically destroy drives that cannot be sanitized

  3. C

    Delete the file shares, remove the arrays from Active Directory, and place them in storage for 30 days

  4. D

    Run a vulnerability scan against the arrays, then release them once no critical findings are reported

Show answer and explanation

Correct answer: B

Explanation

The best answer is to apply appropriate media sanitization methods as part of the decommissioning process. For functional encrypted drives, cryptographic erasure is an accepted method because destroying the encryption keys renders the data unreadable. For failed drives that cannot be sanitized logically, physical destruction is the safest choice. This is consistent with common security best practices and guidance such as NIST SP 800-88, Guidelines for Media Sanitization, which emphasizes selecting sanitization methods based on media condition, sensitivity of data, and disposition of the asset. In regulated environments like healthcare, proper decommissioning should also include documenting chain of custody, updating asset inventories, and retaining records of sanitization or destruction, but the primary control in this scenario is secure data sanitization before release or disposal.

  • A. Incorrect.

    Incorrect. Formatting a drive does not securely remove underlying data and is not sufficient for sensitive information such as patient records or financial data. While updating the asset inventory is a good administrative step, it does not address media sanitization. A common misconception is that formatting makes data unrecoverable, but in many cases data can still be recovered with forensic tools.

  • B. Correct.

    Correct. Cryptographic erasure is an effective sanitization method when the data is protected by strong encryption and the encryption keys can be securely destroyed, making the data unreadable. For drives that have failed and cannot be overwritten or sanitized logically, physical destruction is the appropriate choice. This approach aligns with established media sanitization best practices and is especially suitable when handling regulated or highly sensitive data during decommissioning.

  • C. Incorrect.

    Incorrect. Deleting file shares and removing systems from directory services may be part of deprovisioning, but those actions do not sanitize the storage media itself. Placing the arrays in storage also leaves residual data at risk. Someone might choose this option because it sounds like a complete retirement workflow, but it misses the most important requirement: securely eliminating access to the data on the drives.

  • D. Incorrect.

    Incorrect. Vulnerability scanning identifies security weaknesses in active systems; it does not verify that stored data has been sanitized or removed. An array can have no critical vulnerabilities and still contain recoverable sensitive data. This option reflects a misunderstanding between system hardening and media sanitization during decommissioning.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam