CISSP Asset Security Practice Question
An organization is reviewing its media sanitization procedures. Which TWO methods are considered acceptable for sanitizing solid-state drives (SSDs) according to NIST SP 800-88 guidelines?
⚠ Common exam trap
CISSP often tests the misconception that overwriting or degaussing works on SSDs, when in fact only cryptographic erase or physical destruction are reliable per NIST SP 800-88.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cryptographic erase
According to NIST SP 800-88, cryptographic erase (Option B) is an acceptable sanitization method for SSDs because it destroys the media encryption key (MEK) used by the drive's built-in self-encrypting drive (SED) controller, rendering all data on the NAND flash unreadable without ever needing to overwrite every cell. Physical destruction (Option C) via shredding or pulverizing is also acceptable because it reduces the flash memory chips to particles small enough that data recovery is infeasible, which NIST lists as a valid media disposal technique. Degaussing (Option A) does not belong because SSDs use flash memory rather than magnetic media, so a magnetic field has no effect on the stored charge. Overwriting with a random pattern (Option D) is not reliable for SSDs due to wear leveling, over-provisioning, and remapped blocks that can retain residual data outside the logical address space. Data wiping software (Option E) is likewise not an approved SSD sanitization method in NIST SP 800-88 because it cannot guarantee that every flash cell, including spare and remapped blocks, is overwritten.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Degaussing
Why it's wrong here
Degaussing relies on a strong magnetic field to disrupt the magnetic domains on hard disk drives (HDDs) and magnetic tapes. Because solid-state drives (SSDs) store data electronically in NAND flash memory cells rather than magnetically, degaussing has absolutely no effect on them. Consequently, this method fails to sanitize modern flash-based storage media.
- ✓
Cryptographic erase
Why this is correct
Cryptographic erasure (CE) sanitizes media by permanently deleting or overwriting the decryption keys associated with self-encrypting drives (SEDs). Without the key, the ciphertext remaining on the storage chips becomes mathematically infeasible to decrypt. This process is highly efficient and completed in seconds, making it ideal for both solid-state and magnetic media.
- ✓
Physical destruction (shredding or pulverizing)
Why this is correct
Physical destruction, such as shredding or disintegrating, physically breaks the storage media into tiny fragments to prevent data recovery. For solid-state drives, the shred size must be extremely small (typically 2mm or less) to ensure the individual NAND flash memory chips are completely destroyed. This method provides the highest level of assurance for highly sensitive data decommissioning.
- ✗
Overwriting with a random pattern
Why it's wrong here
Overwriting writes random data patterns across the logical block addresses of a storage device. However, this technique is unreliable for solid-state drives because wear-leveling algorithms and over-provisioned space prevent direct access to all physical NAND cells. Consequently, residual data can remain intact in unmapped sectors, bypassing the overwrite attempt.
- ✗
Data wiping software
Why it's wrong here
Data wiping software typically utilizes standard logical block overwriting passes to sanitize storage media. Similar to basic overwriting, these software tools cannot reliably target hidden sectors, bad blocks, or wear-leveled areas managed by the SSD's internal controller. This leaves sensitive data vulnerable to recovery through specialized hardware-level forensic techniques.
Go deeper
Related to this question
Learn chapter
Asset Security: Privacy and Data Retention
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
Key term
Encryption key
An encryption key is a string of random characters used by an algorithm to lock (encrypt) and unlock (decrypt) data, ensuring only authorized parties can read it.
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.