hardMultiple ChoiceObjective-mapped
CISSP Practice Question: A government agency's data retention policy…
A government agency's data retention policy requires that classified documents be destroyed after 10 years. Which method ensures both the information and the media are completely destroyed in a way that is verifiable and auditable?
⚠ Common exam trap
Many exam-takers confuse 'sanitization' with 'destruction' — they may choose degaussing or overwriting because those methods effectively erase data, but the question explicitly requires complete destruction of both information and media, which only physical destruction methods like incineration achieve.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Incineration in a certified facility
Incineration in a certified facility is the only option that completely destroys both the information and the physical media, leaving no residue that could be reconstructed. For classified government documents, the destruction must be verifiable and auditable, which a certified incineration facility provides through documented chain-of-custody and destruction certificates. This method ensures the media is physically reduced to ash, eliminating any possibility of data recovery, unlike logical or magnetic techniques.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Incineration in a certified facility
Why this is correct
Incineration in a certified facility provides the most absolute method of data destruction by physically reducing the storage media to ash. This process renders all data completely unrecoverable, satisfying the highest security requirements for sensitive government information. The certification ensures compliance with environmental regulations and provides an essential audit trail through destruction certificates, verifying the complete and irreversible elimination of the data-bearing asset.
- ✗
Overwriting the data seven times
Why it's wrong here
Overwriting data multiple times, such as with a seven-pass method, attempts to obscure original data by writing new patterns over it. However, this software-based approach is often ineffective on modern storage devices like SSDs due to wear leveling, over-provisioning, and bad block remapping, which can leave residual data in inaccessible areas. Furthermore, overwriting does not physically destroy the media, meaning the device itself could still be identified or potentially subjected to advanced forensic recovery techniques.
- ✗
Degaussing the storage media
Why it's wrong here
Degaussing involves exposing magnetic storage media, such as hard disk drives or magnetic tapes, to a powerful magnetic field to randomize the magnetic domains, thereby erasing the stored data. While effective for magnetic media, this method is entirely unsuitable for non-magnetic storage types like Solid State Drives (SSDs), flash drives, or optical media. Crucially, degaussing does not physically destroy the media, leaving the device intact and potentially identifiable, which may not meet stringent government destruction policies.
- ✗
Deleting all files and emptying the recycle bin
Why it's wrong here
Deleting files and emptying the recycle bin performs only a logical removal of data, not a physical one. This action merely removes the file system's pointer to the data and marks the storage space as available for future use, leaving the actual data blocks intact on the drive. Consequently, the original data remains easily recoverable using common undelete utilities or forensic software until new data physically overwrites those specific sectors.
Go deeper
Related to this question
Learn chapter
Asset Security: Privacy and Data Retention
Key term
Retention policy
A retention policy is a set of rules that determines how long an organization keeps its data and what happens to it when the retention period expires.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.