CAS-003 · Question #950
Company policy mandates the secure disposal of sensitive data at the end of the useful lifespan of IT equipment. The IT department donates old devices to charity and recycles truly obsolete…
The correct answer is A. Secure shredding of SSOs separate from laptop chassis F. Removing and storing hard drives for archival purposes. Option A (secure shredding of SSDs separate from the laptop chassis) ensures that donated laptop chassis cannot be paired with the original storage containing sensitive data, and that the drives themselves are physically destroyed beyond recovery. Option F (removing and storing…
Question
Company policy mandates the secure disposal of sensitive data at the end of the useful lifespan of IT equipment. The IT department donates old devices to charity and recycles truly obsolete equipment. In addition to deleting workstations from the systems responsible for monitoring network connections which of the following actions should the company implement? (Select TWO)
Options
- ASecure shredding of SSOs separate from laptop chassis
- BRemoving the devices from the asset management system
- CDeleting and overwriting the boot sectors of each workstation
- DEnsuring change notices for each asset are recorded
- EStaggering device disposal dates to coordinate with acceptance testing
- FRemoving and storing hard drives for archival purposes
How the community answered
(29 responses)- A93% (27)
- B3% (1)
- D3% (1)
Explanation
Option A (secure shredding of SSDs separate from the laptop chassis) ensures that donated laptop chassis cannot be paired with the original storage containing sensitive data, and that the drives themselves are physically destroyed beyond recovery. Option F (removing and storing hard drives for archival purposes) is appropriate for devices donated to charity - by removing the drives before donation, the company retains control over its data while the hardware goes to a good cause. Together, these two actions ensure data confidentiality through either destruction or controlled retention. The other options (overwriting boot sectors, updating asset management, scheduling disposal dates) are either insufficient for secure data disposal or are administrative steps that don't directly mitigate data exposure.
Topics
Community Discussion
No community discussion yet for this question.