220-1102 Security Practice Question
A technician is decommissioning a server that contained customer financial records. The server's hard drives will be recycled. Which of the following is the MOST secure method to ensure data is unrecoverable?
⚠ Common exam trap
Candidates often confuse logical deletion (quick format or file deletion) with physical data destruction, assuming the OS's 'delete' command permanently removes data, when in fact it only removes pointers to the data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Using a disk wiping utility that overwrites data multiple times
Disk wiping utilities, such as those compliant with the DoD 5220.22-M standard, overwrite every sector of the hard drive with patterns (e.g., zeros, ones, random data) multiple times. This process ensures that residual magnetic data, which could be recovered using forensic tools like a magnetic force microscope, is rendered unrecoverable. For financial records subject to regulations like PCI DSS or GDPR, this method meets the requirement for secure data sanitization.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Quick formatting the drives
Why it's wrong here
Quick formatting on a Windows system rebuilds the volume boot sector and file system metadata such as the MFT or FAT entries, marking the drive as empty and ready for new data. However, it does not zero-fill or overwrite the user-accessible data sectors, so the previous financial information remains physically present on the platters or flash cells. Recovery tools can scan for and reconstruct these residual data patterns, making quick formatting an unacceptable data-disposal method for sensitive information.
- ✓
Using a disk wiping utility that overwrites data multiple times
Why this is correct
A disk wiping utility, such as DBAN or a vendor-supplied secure erase tool, performs multiple passes of overwriting every logical block with patterns like zeros, ones, or random data. This disrupts the magnetic or flash-level representation of the formerly stored data to the point where it is no longer recoverable, even with forensic hardware or software. Because the process explicitly targets all addressable sectors and repeats across several passes, it meets industry standards for sanitization, unlike simple deletion or quick format.
- ✗
Deleting all files and emptying the Recycle Bin
Why it's wrong here
Deleting files and emptying the Recycle Bin only removes the directory entries and marks the associated clusters as available, but the underlying data bytes are still physically stored until new writes happen to overwrite them. On NTFS volumes, the MFT record is merely flagged as inactive, leaving the actual content intact in unallocated space. Forensic recovery tools can easily carve out these orphaned files, so this method fails to protect customer financial data from disclosure.
- ✗
Running the CHKDSK command
Why it's wrong here
CHKDSK is a file system integrity utility that verifies the consistency of the volume structure, checks the file system and security descriptors, and optionally scans for bad sectors. While it may reallocate data from damaged sectors or repair logical corruption, it does not perform any systematic erasure of user data across the entire drive. In fact, CHKDSK has no data sanitization capability and can even preserve or rebuild data structures, making it a maintenance tool rather than a secure deletion mechanism.
Go deeper
Related to this question
Learn chapter
Data Destruction and Disposal
Key term
Data sanitization
Data sanitization is the process of deliberately, permanently, and irreversibly removing or destroying data stored on a device or media so that it cannot be recovered or reconstructed by any known method.
Key term
PCI
PCI (Peripheral Component Interconnect) is a standard bus interface used in computers to connect hardware devices like graphics cards, network adapters, and storage controllers to the motherboard.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.