Courseiva
mediumMultiple ChoiceObjective-mapped

220-1102 Practice Question: A technician is decommissioning a server that…

A technician is decommissioning a server that contained encrypted patient health records. The organization's policy requires data to be destroyed beyond recovery, but the server must be returned to the leasing company. Which method should the technician use?

⚠ Common exam trap

Many exam-takers choose degaussing (Option B) because it effectively destroys magnetic data, but they overlook the requirement to return the server to the leasing company, which degaussing would render inoperable by damaging non-storage electronics.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Remove the hard drives and physically shred them, then return the server without drives.

Physically shredding the hard drives ensures the encrypted patient health records are destroyed beyond any possible recovery, which satisfies the organization's policy. Returning the server without drives complies with the leasing company's requirement to return the server chassis, as the drives are typically owned by the organization or can be removed per lease terms. This method is the only one that guarantees data destruction at the physical media level, bypassing any residual data on the encrypted drives.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Perform a full format of all drives.

    Why it's wrong here

    A full format, while overwriting data with zeros, does not meet the stringent requirements for secure data destruction, especially for encrypted data from a decommissioned server. Specialized data recovery tools can often reconstruct data even after a single full format pass, particularly if the drive has been used extensively or if the overwrite process is not sufficiently robust. For sensitive information, a single pass of zeros is generally insufficient to prevent advanced forensic recovery.

  • Use a degausser on the entire server chassis.

    Why it's wrong here

    Degaussing involves exposing magnetic storage media to a powerful magnetic field to randomize the magnetic domains, rendering data unreadable. Applying a degausser to an entire server chassis is highly inappropriate and dangerous. The intense magnetic field would not only destroy data on hard drives but also permanently damage other electronic components like RAM, motherboards, and CPUs, making the entire server inoperable and potentially unsafe. Proper degaussing requires removing the magnetic media (HDDs) from the system first.

  • Remove the hard drives and physically shred them, then return the server without drives.

    Why this is correct

    Physical destruction, such as shredding or pulverizing hard drives, is the most secure and irreversible method for data sanitization, especially for encrypted data. This method ensures that the platters containing the data are completely destroyed, making any data recovery impossible, even with advanced forensic techniques. Removing the drives and then returning the server chassis without them also directly addresses the common scenario of leased equipment where the data-bearing components must be retained or destroyed by the organization, while the hardware itself is returned to the lessor.

  • Run a disk cleanup and delete all files.

    Why it's wrong here

    Simply running a disk cleanup utility or deleting files through the operating system only removes pointers to the data, marking the space as available for new data. The actual data remains on the drive until it is overwritten, making it easily recoverable using readily available data recovery software. This method offers no data sanitization and is completely inadequate for decommissioning a server that contained sensitive, encrypted data, as it poses a significant risk of data breach.

About these practice questions

Courseiva writes every 220-1202 question from scratch — 495 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.