Courseiva
Asset Security →mediumMultiple Choice

CISSP Asset Security Practice Question

A financial services firm stores customer account data on a storage area network (SAN). The data is replicated to a secondary site for disaster recovery. The security team must ensure that when data is no longer needed, it is securely destroyed in accordance with the data retention policy. The primary site uses SSD-based storage, while the secondary site uses traditional HDDs. Which data destruction method is most appropriate for the SSD-based primary site?

⚠ Common exam trap

The trap here is assuming that overwriting works the same on SSDs as on HDDs, overlooking wear leveling and spare blocks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cryptographic erasure (crypto-shredding)

Cryptographic erasure is the most appropriate method for SSDs because it leverages encryption to render data unrecoverable by destroying the keys. Unlike overwriting, which is unreliable on SSDs due to wear leveling, crypto-shredding ensures that all data, including that in spare blocks, becomes inaccessible. It is also efficient and allows for secure disposal without physical destruction.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Physical shredding of the SSDs

    Why it's wrong here

    Physical shredding is an effective method for destroying SSDs, but it is typically used for media that is being disposed of and cannot be reused. In this scenario, the SSDs are in a primary site that may need to be redeployed or returned to a vendor; shredding would be overly destructive and costly. The question asks for the most appropriate method, implying a balance of security and practicality.

  • ✓

    Cryptographic erasure (crypto-shredding)

    Why this is correct

    Cryptographic erasure involves destroying the encryption keys used to encrypt the data, rendering the data unrecoverable. For SSDs, where overwriting is unreliable due to wear leveling and spare blocks, crypto-shredding is a recommended method. It ensures that even if residual data remains, it cannot be decrypted, satisfying secure destruction requirements.

  • ✗

    Degaussing the SSDs

    Why it's wrong here

    Degaussing uses a strong magnetic field to erase data on magnetic media such as HDDs and tapes. SSDs store data in flash memory chips, which are not magnetic; therefore, degaussing would have no effect on the data and could damage the drive. This method is inappropriate for SSDs and would not meet the requirement for secure destruction.

  • ✗

    Overwriting with a single pass of random data

    Why it's wrong here

    Overwriting with a single pass is generally ineffective on SSDs because wear leveling and internal controller algorithms may write data to different physical blocks, leaving original data intact in spare areas. This method does not guarantee that all data is overwritten, so it fails to securely destroy the data on SSDs.

About these practice questions

This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.