easyMultiple Choice
CISSP Practice Question: A healthcare organization must decommission a…
A healthcare organization must decommission a server containing protected health information (PHI). Which data sanitization method ensures the data is irrecoverable while complying with regulatory requirements?
⚠ Common exam trap
Candidates often choose degaussing as the default 'strong' destruction method, but CISSP tests the understanding that degaussing only works on magnetic media. For modern servers that likely contain SSDs, physical destruction (shredding) is the only method that guarantees complete sanitization across all media types.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Physically shred the hard drive
Physical destruction, such as shredding, is the most secure method of data sanitization (the 'Destroy' level in NIST SP 800-88). It physically breaks the media into tiny pieces, ensuring that data is completely irrecoverable. This is the most compliant method under regulations like HIPAA for decommissioning assets containing PHI. Degaussing (Option B) is only effective for magnetic media (HDDs) and is completely ineffective on Solid-State Drives (SSDs), which are common in modern servers. Overwriting (Option D) and formatting (Option A) do not meet the strict destruction standards required for decommissioning high-sensitivity PHI assets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reformat the hard drive with a quick format
Why it's wrong here
A quick format only deletes the file system's pointers to the data, marking the storage space as available for new information without actually erasing the underlying data blocks. This leaves the sensitive Protected Health Information (PHI) fully recoverable using common data recovery tools. Consequently, it fails to meet any recognized standard for secure data sanitization or disposal, making it completely inadequate for decommissioning a server containing PHI.
- ✗
Degauss the hard drive
Why it's wrong here
Degaussing involves exposing the hard drive to a powerful magnetic field, which effectively randomizes the magnetic domains on the platters. This process completely erases all data, rendering it unrecoverable and permanently destroying the drive's functionality. As a highly effective and irreversible method, degaussing is an approved and recommended technique for sanitizing media containing sensitive data like Protected Health Information (PHI) under various regulatory guidelines.
- ✓
Physically shred the hard drive
Why this is correct
Physically shredding the hard drive is an extremely effective method for data destruction, as it mechanically breaks the platters into tiny, unrecoverable fragments. While this method undeniably destroys all data and meets stringent regulatory requirements for PHI disposal, it is an irreversible process that prevents any potential reuse of the drive or its components. Compared to degaussing, which can also destroy data effectively, shredding represents a more absolute and typically more costly form of destruction.
- ✗
Overwrite the hard drive with a single pass of zeros
Why it's wrong here
Overwriting a hard drive with a single pass of zeros attempts to replace all existing data with a uniform pattern. However, for sensitive data like Protected Health Information (PHI), a single pass is generally considered insufficient to meet stringent data sanitization standards. Advanced forensic techniques or specialized equipment can sometimes recover residual data from previous magnetic states, especially on modern high-density drives, making this method unreliable for ensuring complete data eradication.
Go deeper
Related to this question
Learn chapter
Physical Security and Environmental Controls
Key term
HIPAA
HIPAA is a U.S. law that sets national standards for protecting sensitive patient health information from being disclosed without the patient's consent or knowledge.
Key term
Data sanitization
Data sanitization is the process of deliberately, permanently, and irreversibly removing or destroying data stored on a device or media so that it cannot be recovered or reconstructed by any known method.
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.