Courseiva
easyMultiple Choice

PT0-002 Practice Question: After completing a penetration test, a tester…

After completing a penetration test, a tester needs to dispose of test data securely. Which of the following methods is most appropriate for this purpose?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a secure data destruction tool that overwrites data multiple times

A secure data destruction tool that overwrites the data multiple times (e.g., using multi-pass overwrite algorithms like DoD 5220.22-M or Gutmann) renders the original test data unrecoverable, which is the goal of secure disposal after a penetration test. Standard deletion (A) only removes file system references, leaving data recoverable with forensic tools, and a single format (C) likewise does not guarantee the underlying blocks are wiped. Keeping the data encrypted (D) is not disposal at all and retains sensitive test data, creating ongoing confidentiality and compliance risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Delete the data using standard operating system commands

    Why it's wrong here

    Standard delete commands unlink directory entries while the underlying blocks remain intact, so forensic recovery is still possible. This suits routine housekeeping on non-sensitive files; secure disposal of test data requires overwriting or physical destruction of the media.

  • ✓

    Use a secure data destruction tool that overwrites data multiple times

    Why this is correct

    Overwriting data multiple times with a secure destruction tool renders the original bit patterns unrecoverable, satisfying the requirement to dispose of test data securely. Unlike degaussing, which only works on magnetic media, overwriting suits SSDs and HDDs alike, and it preserves the drive for reuse where the stem does not mandate physical destruction.

  • ✗

    Format the storage device once

    Why it's wrong here

    A single format overwrites the filesystem metadata, leaving residual data recoverable with forensic tools, so it does not satisfy secure disposal. Formatting suits repurposing a device for routine reuse where remnants pose no confidentiality risk, not clearing sensitive penetration-test artefacts.

  • ✗

    Keep the data encrypted for future reference

    Why it's wrong here

    Retaining encrypted test data fails secure disposal because the data persists and remains recoverable if the key is later compromised; disposal requires destruction, not storage. Encryption suits protecting data in use or transit, such as archived evidence during an active engagement, not end-of-test sanitisation.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.