CCSP · Question #275
Which of the following methods for the safe disposal of electronic records can always be used in a cloud environment? Response:
The correct answer is B. Encryption. In a cloud environment, encryption combined with key destruction is the only method for safe electronic record disposal that a customer can consistently implement, as physical methods are not accessible.
Question
Which of the following methods for the safe disposal of electronic records can always be used in a cloud environment? Response:
Options
- APhysical destruction
- BEncryption
- COverwriting
- DDegaussing
How the community answered
(15 responses)- B93% (14)
- D7% (1)
Why each option
In a cloud environment, encryption combined with key destruction is the only method for safe electronic record disposal that a customer can consistently implement, as physical methods are not accessible.
Physical destruction of storage media is not an option for a cloud customer, as they do not own or have access to the physical hardware in the cloud provider's data center.
In a cloud environment, customers do not have physical access to the underlying storage media, making methods like physical destruction, degaussing, or direct overwriting unavailable for secure disposal. However, encrypting data at rest and then securely destroying the encryption keys effectively renders the data unrecoverable, serving as a reliable logical disposal method that customers can control.
Overwriting data on storage media is typically a low-level operation that cloud customers cannot directly perform on the provider's underlying storage infrastructure. While providers might offer "secure erase" functions, it's not a method the customer can always *use* directly.
Degaussing is a method for erasing data from magnetic media by exposing it to a powerful magnetic field, which is a physical process not available to cloud customers.
Concept tested: Cloud data disposal methods
Source: https://csrc.nist.gov/publications/detail/sp/800-144/final
Topics
Community Discussion
No community discussion yet for this question.