nerdexam
CompTIA

CAS-001 · Question #319

Company XYZ plans to donate 1,000 used computers to a local school. The company has a large research and development section and some of the computers were previously used to store proprietary…

The correct answer is B. Delay the donation until all storage media on the computers can be sanitized. Answer B is correct because protecting proprietary research data takes precedence over expediency. Delaying the donation until storage media is properly sanitized (via NIST 800-88 methods such as clearing, purging, or physical destruction) eliminates the risk of data remnants…

Enterprise Security

Question

Company XYZ plans to donate 1,000 used computers to a local school. The company has a large research and development section and some of the computers were previously used to store proprietary research. The security administrator is concerned about data remnants on the donated machines, but the company does not have a device sanitization section in the data handling policy. Which of the following is the BEST course of action for the security administrator to take?

Options

  • ADelay the donation until a new policy is approved by the Chief Information Officer (CIO), and then
  • BDelay the donation until all storage media on the computers can be sanitized.
  • CReload the machines with an open source operating system and then donate the machines.
  • DMove forward with the donation, but remove all software license keys from the machines.

How the community answered

(42 responses)
  • A
    5% (2)
  • B
    71% (30)
  • C
    7% (3)
  • D
    17% (7)

Explanation

Answer B is correct because protecting proprietary research data takes precedence over expediency. Delaying the donation until storage media is properly sanitized (via NIST 800-88 methods such as clearing, purging, or physical destruction) eliminates the risk of data remnants reaching an uncontrolled environment. The absence of a formal policy does not eliminate the obligation to protect sensitive data - prudent security practice demands sanitization regardless. Answer A also delays appropriately but adds unnecessary dependency on CIO policy approval before taking protective action. Answer C (reloading the OS) is dangerously insufficient - data remnants persist on storage media and can be recovered with forensic tools even after an OS reinstall. Answer D (removing license keys) addresses software licensing, not data security, and provides no protection against data recovery.

Topics

#data sanitization#media disposal#data remnants#data handling policy

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice