220-1102 - Security (25% of the exam) - Section 2.8

Use common data destruction and disposal methods.

Choose the correct data destruction method for a scenario - physical destruction (drilling, shredding, degaussing, incinerating) versus recycling or repurposing best practices (erasing and wiping, low-level formatting, standard formatting). Apply outsourcing concepts including the use of a third-party vendor and obtaining a certificate of destruction or recycling, and match the method to the sensitivity of the data being disposed of.

Physical destructionDegaussingErasing/wipingCertificate of destructionThird-party vendor

Practice question for this objective

Free sampleSecuritymedium

A finance firm ships its decommissioned drives to an outside disposal vendor for shredding. Auditors require documented proof, for chain of custody, that each specific drive was actually destroyed. What should the technician make sure the vendor provides?

  • AA signed non-disclosure agreement committing the vendor to keep any recovered data confidential.
  • BA recycling receipt confirming the vendor collected the sealed boxes of drives from the site.
  • CA certificate of destruction that records each drive's serial number and the date it was destroyed. Correct
  • DA full disk image of every drive taken before shipping so the data can be verified afterwards.
When a third-party vendor handles destruction, a certificate of destruction listing the media is the record that proves chain of custody. Chain-of-custody compliance for outsourced disposal is met by a certificate of destruction, which itemises the destroyed media and the destruction date, unlike a transfer receipt or a confidentiality agreement.

Why A is wrong: An NDA is a reasonable contractual control, but it protects confidentiality, not proof of destruction, so it does not satisfy the auditors' chain-of-custody evidence.

Why B is wrong: A collection receipt proves only that the drives were handed over, not that they were destroyed, leaving a gap in the destruction evidence trail.

Why C is correct: A certificate of destruction is the standard document that proves specific media were destroyed, giving auditors the chain-of-custody evidence they require.

Why D is wrong: Imaging the drives first creates an extra copy of the sensitive data and proves nothing about destruction, which runs counter to the goal.

See more 220-1102 practice questions, answers explained.

Exam traps in Security

Answers that look right on this material and are not. Each one is a distractor from a different question in the 220-1102 bank for this domain.

  • Run the manufacturer's secure erase utility to overwrite every flash cell on the drive

    Why it is wrong: Secure erase is a valid sanitisation method for a working SSD, but the utility needs a drive that powers on and responds to commands, which this dead unit cannot do.

  • Overwrite the discs with random data using a disk wiping utility

    Why it is wrong: Overwriting is the right idea for a rewritable hard drive, but pressed or write-once optical discs cannot be reliably rewritten, so the data stays intact.

  • Run a multi-pass overwrite utility such as DBAN against the drive to sanitise every sector.

    Why it is wrong: Overwriting sounds thorough, but software wiping needs a drive the system can access, and this drive will not spin up or be detected, so the pass cannot run.

Examworthy is not affiliated with or endorsed by CompTIA. Original, blueprint-aligned practice material only.