easyMultiple Choice
CCSP Physical destruction Practice Question
A cloud customer is decommissioning a storage service that contains sensitive data. The cloud provider offers several data destruction options. Which method provides the HIGHEST assurance that data is irrecoverable?
⚠ Common exam trap
CCSP often tests the nuances of data destruction methods, and candidates may assume that cryptographic erasure is always the most secure, but physical shredding provides the highest assurance because it eliminates any possibility of data recovery, even from bad sectors or firmware areas.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Physical shredding of the storage drives
Physical shredding of the storage drives provides the highest assurance that data is irrecoverable because it physically destroys the media, making it impossible to reconstruct any data. Unlike degaussing, which may leave residual magnetization, or overwriting, which can leave data in bad sectors, shredding reduces the drives to small particles that cannot be reassembled. Cryptographic erasure is effective only if the encryption keys are securely destroyed and the encryption was properly implemented, but it still relies on the encryption being unbreakable.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Degaussing the storage media
Why it's wrong here
Degaussing applies only to magnetic media and is unavailable in cloud data centres, where providers typically cannot access or return the underlying disks. It tempts because it is a recognised physical sanitisation method, but it cannot be performed on provider-managed infrastructure, so it cannot deliver assurance here.
- ✓
Physical shredding of the storage drives
Why this is correct
Physical shredding destroys the storage media itself, so no residual magnetic or flash state remains recoverable. Cryptographic erasure and overwriting depend on correct key handling or overwrite completion, whereas shredding removes the physical substrate entirely, giving the highest assurance.
- ✗
Multiple overwrite passes with zeros and ones
Why it's wrong here
Overwriting with zeros and ones leaves data recoverable on worn or remapped sectors and is impractical on provider-managed virtual storage. It tempts because it is a classic media-sanitisation technique for self-managed disks, but the customer has no access to the physical media, so the method cannot be executed.
- ✗
Cryptographic erasure of encryption keys
Why it's wrong here
Cryptographic erasure destroys the keys protecting the data, but if keys are retained elsewhere or escrowed, ciphertext remains recoverable. It tempts because it is efficient for encrypted cloud storage, yet without verified key destruction it cannot guarantee irrecoverability of the underlying data.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.