Free Data Destruction and Disposal Methods practice questions
10 free 220-1202 questions on Data Destruction and Disposal Methods, each with a full explanation — no account needed. This section sits in the Security part of the exam. Answer every question to see your score, then read the lessons below for anything you missed.
A technician needs to permanently destroy the data on a batch of retired magnetic tape backups and traditional hard disk drives. The organization's policy requires a method that scrambles the magnetic domains rather than physically breaking the media apart. Which destruction method should the technician use?
Degaussing uses a strong magnetic field to disrupt the magnetic domains that represent data on magnetic media. This makes it ideal for hard disk drives and magnetic tape because both store data as magnetic patterns. When performed with properly rated equipment, degaussing provides high assurance for these media types and matches the policy requirement to scramble magnetic patterns rather than break the media apart. Shredding is incorrect because it physically breaks drives into small fragments using industrial equipment rather than scrambling magnetic domains. Drilling is incorrect because it creates holes that physically damage platters, not a magnetic field process, and it produces uneven results. Incineration is incorrect because it destroys media with high heat in specialized facilities and reduces the media to ash, which is not a magnetic scrambling method. Remember that degaussing is best matched to magnetic media like HDDs and tape, but it does not reliably destroy SSD flash memory because SSDs store charge in cells rather than magnetism.
An organization plans to physically destroy several solid-state drives that contained highly sensitive data. A junior technician suggests running them through a degausser like they do with the old hard drives. Why is this the WRONG approach for SSDs?
Solid-state drives store data in flash memory chips that hold electrical charge in cells, not as magnetic domains on spinning platters. Because degaussing works by disrupting magnetic patterns, it does not reliably destroy the data stored in an SSD's flash memory. The technology mismatch is the core reason degaussing is inappropriate for SSDs. The claim that SSDs simply need a stronger degausser is incorrect because the issue is not field strength but the fact that flash cells do not store data magnetically at all. The statement about damaging platters is incorrect because SSDs have no magnetic platters; they use memory packages and a controller. The suggestion to low-level format before degaussing is incorrect because true low-level formatting is a legacy factory process and does not enable degaussing to work on flash media. For SSDs, appropriate options include physically damaging the memory packages and controller through shredding or drilling, or using a verified secure erase or sanitize command when the drive remains healthy and reuse is planned.
A user deletes several confidential files and empties the Recycle Bin before donating their laptop. The technician is asked whether the data is now safe from recovery. Which statement BEST describes what happened to the data?
Deleting files and emptying the Recycle Bin only removes the references, or signposts, that point to the data. The operating system marks that disk space as available for reuse, but the actual bytes remain on the drive until new data overwrites them. This means recovery tools can often bring the files back, which is why simple deletion is not a valid sanitization method before donation. The claim that the data was overwritten is incorrect because deletion does not overwrite the underlying sectors; it only updates the file system pointers. The claim that the data was automatically encrypted is incorrect because emptying the Recycle Bin does not apply encryption of any kind. The claim that the data was fully sanitized is incorrect because true sanitization requires a wipe, meaning an overwrite for HDDs or a secure erase or sanitize command for SSDs, followed by verification. Erasing hides references, but wiping is what makes recovery impractical. Before donation, a verified wipe must be performed.
A small office wants to reuse a stable, working desktop with a healthy SSD as an internal print server. The machine previously stored moderately sensitive business data. What should the technician do FIRST before redeploying it?
When repurposing a device that stored sensitive data, the technician must first sanitize the storage using the correct method for the media type. For an SSD, a verified secure erase or sanitize command reliably removes recoverable data, and verification confirms the result before the machine is redeployed. Repurposing works well here because the device still performs reliably and the data risk is manageable once the drive is properly wiped. Performing a quick format and installing the role is incorrect because a quick format only rebuilds file system pointers and does not remove recoverable data; formatting is for readiness, not privacy. Degaussing the SSD is incorrect because degaussing targets magnetic domains and does not reliably affect flash memory cells. Sending the desktop to e-waste recycling is incorrect because the machine is healthy and a strong repurpose candidate, so destroying or recycling it wastes usable hardware. The correct sequence is to wipe and verify first, then optionally apply a standard format when preparing the system for its new role.
A company is retiring several multifunction copiers and leased laptops through a third-party disposal vendor. Auditors will later ask for proof that data-bearing devices were properly destroyed. Which document should the organization require from the vendor?
A certificate of destruction, also called a destruction report, is the document used to prove that data-bearing devices were destroyed or sanitized. When an organization outsources disposal, it usually cannot witness the destruction step directly, so it relies on this certificate along with chain-of-custody records to show what happened and when. This is exactly the evidence auditors will request for retired copiers and leased laptops. A service level agreement is incorrect because it defines response times, restore targets, and escalation paths for a service relationship, not proof of destruction. An acceptable use policy is incorrect because it governs how employees may use company systems and has nothing to do with disposal verification. An end user license agreement is incorrect because it covers the terms of using licensed software, not the destruction of hardware. A strong certificate of destruction should include vendor identity, date and location, method used, asset identifiers such as serial numbers, quantity, and tracking or witness information so the proof ties directly to specific devices.
A technician reviews a destruction certificate returned by a recycling vendor. The document lists the vendor name, date, and method but describes the destroyed items only as "misc drives" with no serial numbers. What is the technician's BEST course of action?
A destruction certificate must be specific enough to tie the document to your actual assets. Vague phrases like "misc drives" with no serial numbers do not prove which devices were destroyed, so the technician should ask the vendor to re-issue a detailed report or attach a pickup manifest that lists each asset by serial number or asset tag. This protects the organization during audits and helps detect missing items. Filing the certificate as-is is incorrect because a report that cannot identify the specific items destroyed offers weak protection and would fail an audit review. Discarding the certificate and assuming destruction is incorrect because it leaves no traceable evidence and breaks the chain-of-custody story that links each asset from removal to destruction. Recording the drives as still in service is incorrect and inaccurate, because retired assets should be marked as retired in inventory once properly documented, not left as "in service." Asset identifiers, quantity, and tracking or witness information are essential fields that give auditors a clear, defensible record.
A technician is drilling holes in retired HDDs for a small batch destruction task. To maximize the assurance that the data cannot be recovered, which practice should the technician follow?
On an HDD, the goal of drilling is to damage the magnetic platters where the data is stored. Drilling through multiple key internal areas that target the platters greatly reduces the chance that large, readable arcs of platter remain intact for recovery. A consistent multi-hole pattern combined with visual inspection and documentation makes drilling a more defensible destruction method. Drilling a single hole through one corner is incorrect because corners often avoid the platter area entirely on many HDDs, leaving most of the media untouched. Drilling only through the outer casing is incorrect because piercing just the casing may miss the platters completely, leaving the data recoverable. Drilling a small hole near the data connector is incorrect because damaging the connector or controller does not destroy the platters themselves, and a recovery lab could still access intact platter sections. Because drilling produces uneven results, process control matters: mark target areas, drill through multiple internal locations, verify visible internal damage, and record who performed the destruction, when, and which serial number was involved.
An organization needs to destroy thousands of retired drives at end of life and requires repeatable results plus strong audit documentation such as batch records and destruction certificates. Which method BEST meets these requirements?
Shredding breaks drives into small fragments using industrial mechanical equipment, turning the entire drive into pieces rather than hoping damage hit the right spot. This consistency lowers recovery chances and, because shredding typically runs as a controlled vendor service, it produces strong compliance reporting including batch records and destruction certificates. That makes it ideal for destroying drives at scale with strong audit proof. Drilling is incorrect because it depends on hitting the right internal areas and produces uneven, lower-assurance results that are harder to audit consistently across thousands of drives. Standard formatting is incorrect because formatting only prepares a file system for use and is not a guaranteed sanitization method, let alone a physical destruction method for bulk end-of-life disposal. Crypto-erase is incorrect because it is a logical sanitization method that destroys encryption keys on healthy encrypted drives rather than physically destroying media, and many policies still require a follow-up wipe or destruction. For large-scale destruction requiring repeatable outcomes and auditable evidence, shredding through a certified vendor is the strongest fit.
A backup vendor requests domain admin access to install a monitoring agent, stating it will be faster than configuring limited permissions. Following outsourcing best practices, what should the technician do FIRST?
When a vendor requests broad access, the technician should validate and reduce the request by applying the principle of least privilege. The first step is to ask what permissions the agent truly needs, then use a dedicated account with only the minimum rights required, protected by MFA and logging, and obtain written approval if policy requires it. This reduces the risk of data exposure while still allowing the vendor to complete the task. Granting domain admin access to save time is incorrect because broad access creates unnecessary risk and violates least privilege, which is a core control for third-party access. Denying all access and canceling the contract is incorrect because the vendor still needs some access to perform the contracted service; the goal is to manage risk, not eliminate the relationship over a fixable access request. Sharing an admin password by email is incorrect because credentials should be placed in an approved vault, never sent in email, and a shared admin account undermines accountability and logging. Outsourcing does not remove accountability, so access must be scoped, logged, and authorized.
A technician is preparing a batch of lithium-ion laptop batteries for pickup by an approved e-waste recycler. Several are being stored in a closet until the vendor arrives. Which handling practice reduces the risk of fire or short circuits?
Lithium-ion batteries can swell, vent, or catch fire if punctured or crushed, so proper handling is essential. Taping the battery terminals and storing the batteries in approved containers away from heat and moisture prevents short circuits and reduces fire risk while they await vendor pickup. This matches standard safe handling for hazardous e-waste. Puncturing each battery is incorrect and dangerous because damaging a lithium-ion cell can cause it to vent or ignite, which is exactly the hazard you are trying to avoid. Storing batteries loose in a bin near a heat source is incorrect because loose terminals can contact each other and short, and heat increases the risk of thermal runaway. Submerging the batteries in water is incorrect because moisture is one of the conditions you must keep batteries away from, and it does not make them safe to store or recycle. The safest defaults are to tape terminals, use approved containers, keep items dry, separate waste types, label containers, and follow the escalation path for any damaged or swollen battery.
Study this section
Every lesson that covers Data Destruction and Disposal Methods on the 220-1202 exam.