220-1102 Security Practice Question
A security administrator needs to securely erase data from an SSD before repurposing it in another department. The company policy requires that data be completely unrecoverable. Which method should the administrator use?
⚠ Common exam trap
It's easy for candidates to confuse the Diskpart clean command with a secure erase, not realizing that it only removes partition metadata and does not touch the actual data stored in the NAND flash cells.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the ATA Secure Erase command via the drive's firmware or a trusted tool
The ATA Secure Erase command is the correct method because it issues a firmware-level instruction that triggers the SSD's internal controller to overwrite all user-accessible NAND blocks, including those in over-provisioned space and bad-block remapping tables. This ensures data is completely unrecoverable, as standard OS-level commands cannot access these hidden areas on an SSD due to its wear-leveling and garbage-collection algorithms.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Perform a standard format using Windows File Explorer
Why it's wrong here
A standard format via Windows File Explorer merely writes a new file system structure, such as a fresh partition table and boot sector, but it does not overwrite every user-accessible sector. On an SSD, this process also fails to address the flash translation layer, so previously stored data in NAND cells remains intact and recoverable with forensic tools. Even a full format, which attempts to write zeros, does not guarantee secure erasure because of wear leveling and the drive's internal mapping, making it an ineffective method for securely erasing an SSD before repurposing.
- ✗
Run the Diskpart clean command from a command prompt
Why it's wrong here
The Diskpart clean command removes the partition table and any volume-level metadata from the drive, but it does not overwrite or erase the actual data stored in the user data area of the SSD. After a clean, the drive appears empty at the OS level, yet the raw NAND flash still contains the original data, which can be recovered using data recovery software or forensic techniques. Additionally, Diskpart clean does not trigger the SSD's internal garbage collection or secure erase mechanisms, so it is not a secure deletion method for SSDs.
- ✓
Use the ATA Secure Erase command via the drive's firmware or a trusted tool
Why this is correct
ATA Secure Erase is a command defined in the ATA specification that instructs the SSD's firmware to internally erase all user data at the NAND flash level, including data in spare areas and cache. The drive controller performs a physical-level reset, often by regenerating the encryption key or directly clearing all memory cells, which makes the previous data unrecoverable. This method is specifically designed for SSDs and is recommended because it leverages the drive's own hardware and does not prematurely wear out the flash, unlike repeated OS-level writes.
- ✗
Degauss the drive with a strong magnetic field
Why it's wrong here
Degaussing relies on a powerful magnetic field to disrupt the magnetic domains on ferromagnetic media, which is effective for traditional hard disk drives but fundamentally incompatible with SSDs, which use NAND flash memory that stores charge in floating-gate transistors. Exposing an SSD to a strong magnetic field can induce destructive currents in the controller or other circuitry, potentially destroying the drive, but the data stored in the NAND cells remains unaffected because magnetic fields do not alter charge storage. As a result, degaussing can make the SSD unusable without achieving the goal of secure data erasure, leaving the original data on the chips and recoverable with specialized equipment.
Go deeper
Related to this question
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.