SY0-701 exam dumps

SY0-701 practice question 290 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 290

Select 2Disposal/decommissioning: Sanitization , Destruction , Certification

A healthcare organization is retiring several storage systems from a claims-processing environment. The systems include encrypted SSDs that will be returned at the end of a lease and older magnetic hard drives from servers that stored regulated patient data and will be disposed of by a third-party recycler. During an audit, the security manager must prove that data was handled appropriately throughout decommissioning. Which TWO actions best address both secure disposal and audit evidence requirements?

  1. A

    Use a cryptographic erase or other approved sanitization method for the leased SSDs, and obtain documentation showing the sanitization was completed successfully

  2. B

    Perform a single-pass overwrite on all SSDs and keep the recycler's pickup receipt as sufficient proof that the data is no longer recoverable

  3. C

    Physically destroy the magnetic hard drives before release to the recycler, and retain a certificate of destruction or documented chain of custody

  4. D

    Delete the patient-data partitions, reformat the drives, and record the asset tags in the inventory system as retired

  5. E

    Rely on full-disk encryption alone and return both the SSDs and hard drives without additional sanitization or destruction because the keys are managed internally

Show answer and explanation

Correct answers: A, C

Explanation

The best answers are the SSD sanitization option and the HDD destruction option because they apply appropriate disposal methods to different media types while also producing evidence for auditors. Security+ expects candidates to understand that disposal and decommissioning are not just technical tasks; they also require documentation such as sanitization logs, certificates of destruction, and chain-of-custody records. In practice, organizations should follow established media sanitization guidance such as NIST SP 800-88 Rev. 1, which distinguishes among clear, purge, and destroy methods and emphasizes verification and documentation. SSDs often require cryptographic erase or a vendor-supported sanitization mechanism rather than simple overwriting, while magnetic drives slated for disposal are often physically destroyed. Certification in this context means maintaining records that prove the organization performed the chosen sanitization or destruction method correctly and can demonstrate compliance during an audit.

  • A. Correct.

    Correct. For SSDs, traditional overwrite methods are not consistently reliable because of wear leveling and controller behavior. Approved sanitization methods such as cryptographic erase, when properly implemented, are appropriate for media that will be reused or returned, especially if the drive uses strong encryption and the media encryption key can be securely destroyed. Just as important, the organization needs evidence for the audit, so retaining records that sanitization was successfully performed supports certification and accountability.

  • B. Incorrect.

    Incorrect. A single-pass overwrite is not the best choice for SSDs because logical overwrites may not affect all physical storage locations. In addition, a pickup receipt only proves transfer of custody, not that data was sanitized or destroyed. This option reflects a common misconception that any overwrite method works equally well across media types and that shipping documentation is equivalent to certification of sanitization or destruction.

  • C. Correct.

    Correct. For magnetic hard drives containing regulated data that are being discarded through a recycler, physical destruction is a strong control when the media will not be reused. Retaining a certificate of destruction, along with chain-of-custody documentation if applicable, helps demonstrate that the organization followed a defensible disposal process. This addresses both secure destruction and the audit requirement for documented proof.

  • D. Incorrect.

    Incorrect. Deleting partitions and reformatting do not sanitize data; they primarily remove file system references and make the media appear empty. Data may still be recoverable with forensic tools. Recording assets as retired is useful for inventory management, but it does not satisfy secure sanitization, destruction, or certification requirements for regulated data.

  • E. Incorrect.

    Incorrect. Full-disk encryption reduces risk, but by itself it is not sufficient in every decommissioning case unless an approved cryptographic erase process is actually performed and documented. Simply trusting that encryption was enabled and keys were internally managed does not provide the same assurance as verified sanitization or destruction, particularly for audit and compliance purposes.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam