mediumMultiple ChoiceObjective-mapped
220-1102 Practice Question: A technician is decommissioning a server that…
A technician is decommissioning a server that contained encrypted patient health records. The organization's policy requires data to be destroyed beyond recovery, but the server must be returned to the leasing company. Which method should the technician use?
⚠ Common exam trap
Many exam-takers choose degaussing (Option B) because it effectively destroys magnetic data, but they overlook the requirement to return the server to the leasing company, which degaussing would render inoperable by damaging non-storage electronics.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Remove the hard drives and physically shred them, then return the server without drives.
Physically shredding the hard drives ensures the encrypted patient health records are destroyed beyond any possible recovery, which satisfies the organization's policy. Returning the server without drives complies with the leasing company's requirement to return the server chassis, as the drives are typically owned by the organization or can be removed per lease terms. This method is the only one that guarantees data destruction at the physical media level, bypassing any residual data on the encrypted drives.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Perform a full format of all drives.
Why it's wrong here
A full format, while overwriting data with zeros, does not meet the stringent requirements for secure data destruction, especially for encrypted data from a decommissioned server. Specialized data recovery tools can often reconstruct data even after a single full format pass, particularly if the drive has been used extensively or if the overwrite process is not sufficiently robust. For sensitive information, a single pass of zeros is generally insufficient to prevent advanced forensic recovery.
- ✗
Use a degausser on the entire server chassis.
Why it's wrong here
Degaussing involves exposing magnetic storage media to a powerful magnetic field to randomize the magnetic domains, rendering data unreadable. Applying a degausser to an entire server chassis is highly inappropriate and dangerous. The intense magnetic field would not only destroy data on hard drives but also permanently damage other electronic components like RAM, motherboards, and CPUs, making the entire server inoperable and potentially unsafe. Proper degaussing requires removing the magnetic media (HDDs) from the system first.
- ✓
Remove the hard drives and physically shred them, then return the server without drives.
Why this is correct
Physical destruction, such as shredding or pulverizing hard drives, is the most secure and irreversible method for data sanitization, especially for encrypted data. This method ensures that the platters containing the data are completely destroyed, making any data recovery impossible, even with advanced forensic techniques. Removing the drives and then returning the server chassis without them also directly addresses the common scenario of leased equipment where the data-bearing components must be retained or destroyed by the organization, while the hardware itself is returned to the lessor.
- ✗
Run a disk cleanup and delete all files.
Why it's wrong here
Simply running a disk cleanup utility or deleting files through the operating system only removes pointers to the data, marking the space as available for new data. The actual data remains on the drive until it is overwritten, making it easily recoverable using readily available data recovery software. This method offers no data sanitization and is completely inadequate for decommissioning a server that contained sensitive, encrypted data, as it poses a significant risk of data breach.
Go deeper
Related to this question
Learn chapter
Data Destruction and Disposal
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
Key term
Recovery
Recovery is the process of restoring systems, data, and operations after a security incident, failure, or disaster to return to normal functioning.
About these practice questions
Courseiva writes every 220-1202 question from scratch — 495 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.