hardMultiple ChoiceObjective-mapped
CISSP Is decommissioning a data center Practice Question
An organization is decommissioning a data center. Which of the following is the most secure method for sanitizing hard drives that will be reused?
⚠ Common exam trap
Watch out — candidates often choose 'Physical destruction' because it seems most secure, but they overlook the explicit requirement that the drives will be reused, making destruction invalid.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Overwriting with random data multiple times
Overwriting with random data multiple times (option C) is the most secure method for sanitizing hard drives that will be reused because it ensures that the original data is irrecoverable through any known forensic technique. Unlike physical destruction, which renders the drive unusable, or file deletion and quick format, which only remove file system pointers and leave data intact, multiple-pass overwriting (e.g., using the DoD 5220.22-M standard) writes patterns over every sector, including remapped sectors, making the original data unrecoverable even with advanced magnetic force microscopy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Physical destruction
Why it's wrong here
Physical destruction, such as shredding or degaussing, renders the storage media unusable and unrecoverable. While this is the most secure method for ultimate data disposal, it prevents any possibility of reusing the hardware, which contradicts the common objective of decommissioning for potential redeployment or resale.
- ✗
Deleting all files
Why it's wrong here
Deleting all files through standard operating system commands only removes the file system's pointers to the data blocks. The actual data remains on the disk until it is overwritten, making it easily recoverable using readily available data recovery software and forensic tools, thus failing to sanitize the data securely.
- ✓
Overwriting with random data multiple times
Why this is correct
Overwriting the entire storage medium with random data multiple times is a highly effective and recognized method for data sanitization. This process ensures that residual magnetic or electrical traces of previous data are thoroughly obscured, making data recovery practically impossible even with advanced forensic techniques, thereby preparing the media for secure reuse.
- ✗
Quick format
Why it's wrong here
A quick format operation primarily rebuilds the file system structure and allocation tables, marking all sectors as available for new data. However, it does not overwrite the actual user data stored in those sectors. Consequently, the original data remains intact and is easily recoverable using specialized data recovery software, making it insufficient for secure data sanitization.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.