SY0-701 Question 291
Select 2Disposal/decommissioning: Sanitization , Destruction , CertificationA healthcare organization is retiring several storage systems after a data center refresh. The environment includes SATA hard drives that will be reused internally for a lower-sensitivity lab, failed SSDs that cannot be accessed by software tools, and backup tapes that are scheduled for disposal by a third-party recycling vendor. Because the systems previously stored ePHI, the security manager must choose actions that reduce data remanence risk and provide defensible proof for auditors. Which TWO actions best meet these requirements?
- A
Run a documented sanitization process on the reusable SATA hard drives, verify the results, and retain records of the procedure
- B
Perform a standard quick format on the SATA hard drives before moving them to the lab, since the destination environment is internal
- C
Physically destroy the failed SSDs and backup tapes using an approved destruction method, and obtain a certificate of destruction from the vendor for outsourced disposal
- D
Delete the file system indexes on the backup tapes and archive the serial numbers as evidence that the data is no longer accessible
- E
Store the failed SSDs in a locked cabinet indefinitely instead of destroying them, because chain of custody is sufficient for compliance
Show answer and explanation
Correct answers: A, C
Explanation
The best answers are the documented sanitization of reusable hard drives and the physical destruction of failed SSDs and disposal-bound backup tapes, along with obtaining a certificate of destruction when a third party is involved. In real environments, the correct media handling method depends on whether the device is functional, whether it will be reused, and the sensitivity of the data it held. Functional magnetic drives can often be sanitized and verified for reuse. Failed SSDs are more problematic because wear leveling and inaccessible cells can make logical sanitization unreliable if the device is not functioning normally, so destruction is often the safer choice. For media leaving organizational control, certification is important because it provides evidence that the destruction service was performed. These practices are consistent with NIST SP 800-88 Rev. 1 guidance on media sanitization and with common compliance expectations for regulated data handling, including maintaining documentation to demonstrate due care during disposal and decommissioning.
- A. Correct.
Correct. For magnetic hard drives that will be reused, sanitization is appropriate when the media remains functional. A documented sanitization method, followed by verification and record retention, addresses both operational reuse and audit requirements. This aligns with common best practices and guidance such as NIST SP 800-88 Rev. 1, which emphasizes selecting an appropriate sanitization method and maintaining records when media contained sensitive data.
- B. Incorrect.
Incorrect. A quick format does not sanitize a drive; it typically removes file system references rather than reliably removing the underlying data. This is a common misconception because the drive may appear empty to users, but data recovery may still be possible. Internal reuse does not eliminate the need to properly sanitize media that previously stored regulated data such as ePHI.
- C. Correct.
Correct. Failed SSDs that cannot be sanitized through normal logical methods should be physically destroyed because the organization cannot rely on software-based overwriting or purge operations. Backup tapes being sent to a third party for disposal should also be destroyed using an appropriate method, and a certificate of destruction provides formal documentation for compliance and audit purposes. This combines destruction with certification, which is especially important when disposal is outsourced.
- D. Incorrect.
Incorrect. Backup tapes do not become safely disposable by removing catalog entries or file system references. The underlying data remains on the media. Recording serial numbers may help inventory tracking, but it does not prove sanitization or destruction occurred. This option confuses asset tracking with secure media disposition.
- E. Incorrect.
Incorrect. Secure storage can be a temporary chain-of-custody control, but it is not a disposal or decommissioning method. Keeping failed SSDs locked up indefinitely leaves residual sensitive data on the media and does not satisfy the requirement to reduce remanence risk during decommissioning. Compliance frameworks generally expect actual sanitization or destruction, not permanent storage as a substitute.