nerdexam
CompTIA

CAS-001 · Question #23

An Information Security Officer (ISO) has asked a security team to randomly retrieve discarded computers from the warehouse dumpster. The security team was able to retrieve two older computers and a…

The correct answer is D. Update the hardware decommissioning procedures. Sensitive data was recoverable from a discarded printer's hard drive, indicating that the organization's hardware disposal process failed to include proper data sanitization before physical disposal.

Enterprise Security

Question

An Information Security Officer (ISO) has asked a security team to randomly retrieve discarded computers from the warehouse dumpster. The security team was able to retrieve two older computers and a broken MFD network printer. The security team was able to connect the hard drives from the two computers and the network printer to a computer equipped with forensic tools. The security team was able to retrieve PDF files from the network printer hard drive but the data on the two older hard drives was inaccessible. Which of the following should the Warehouse Manager do to remediate the security issue?

Options

  • ARevise the hardware and software maintenance contract.
  • BDegauss the printer hard drive to delete data.
  • CImplement a new change control process.
  • DUpdate the hardware decommissioning procedures.

How the community answered

(47 responses)
  • A
    2% (1)
  • C
    4% (2)
  • D
    94% (44)

Why each option

Sensitive data was recoverable from a discarded printer's hard drive, indicating that the organization's hardware disposal process failed to include proper data sanitization before physical disposal.

ARevise the hardware and software maintenance contract.

A hardware and software maintenance contract governs ongoing support and repairs, not end-of-life data sanitization practices during disposal.

BDegauss the printer hard drive to delete data.

Degaussing the printer hard drive after the fact is a reactive remediation of one device, not a systemic fix that prevents the same issue with future hardware disposals.

CImplement a new change control process.

A change control process governs modifications to systems and configurations, not the secure decommissioning and disposal of retired hardware assets.

DUpdate the hardware decommissioning procedures.Correct

Updating hardware decommissioning procedures directly addresses the root cause - the warehouse was disposing of devices containing readable data without first sanitizing storage media, so formalizing a process that mandates data wiping, degaussing, or physical destruction before disposal prevents future data exposure.

Concept tested: Secure hardware decommissioning and data sanitization

Source: https://csrc.nist.gov/publications/detail/sp/800-88/rev-1/final

Topics

#hardware decommissioning#media sanitization#data disposal#policy

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice