easyMultiple Choice
PT0-002 Practice Question: After completing a penetration test, a tester…
After completing a penetration test, a tester needs to dispose of test data securely. Which of the following methods is most appropriate for this purpose?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a secure data destruction tool that overwrites data multiple times
A secure data destruction tool that overwrites the data multiple times (e.g., using multi-pass overwrite algorithms like DoD 5220.22-M or Gutmann) renders the original test data unrecoverable, which is the goal of secure disposal after a penetration test. Standard deletion (A) only removes file system references, leaving data recoverable with forensic tools, and a single format (C) likewise does not guarantee the underlying blocks are wiped. Keeping the data encrypted (D) is not disposal at all and retains sensitive test data, creating ongoing confidentiality and compliance risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Delete the data using standard operating system commands
Why it's wrong here
Standard delete commands unlink directory entries while the underlying blocks remain intact, so forensic recovery is still possible. This suits routine housekeeping on non-sensitive files; secure disposal of test data requires overwriting or physical destruction of the media.
- ✓
Use a secure data destruction tool that overwrites data multiple times
Why this is correct
Overwriting data multiple times with a secure destruction tool renders the original bit patterns unrecoverable, satisfying the requirement to dispose of test data securely. Unlike degaussing, which only works on magnetic media, overwriting suits SSDs and HDDs alike, and it preserves the drive for reuse where the stem does not mandate physical destruction.
- ✗
Format the storage device once
Why it's wrong here
A single format overwrites the filesystem metadata, leaving residual data recoverable with forensic tools, so it does not satisfy secure disposal. Formatting suits repurposing a device for routine reuse where remnants pose no confidentiality risk, not clearing sensitive penetration-test artefacts.
- ✗
Keep the data encrypted for future reference
Why it's wrong here
Retaining encrypted test data fails secure disposal because the data persists and remains recoverable if the key is later compromised; disposal requires destruction, not storage. Encryption suits protecting data in use or transit, such as archived evidence during an active engagement, not end-of-test sanitisation.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.