An organization uses full disk encryption on all laptops containing sensitive data. A laptop is to be decommissioned, and the data must be sanitized. The laptop's SSD cannot be overwritten reliably due to wear-leveling. Which method is most appropriate?
Cryptographic erasure is the most appropriate and highly effective method for sanitizing data on encrypted Solid State Drives (SSDs). When full disk encryption (FDE) is employed, all data on the drive is rendered unreadable without the correct encryption key. By securely destroying or invalidating this master encryption key, all data on the drive becomes cryptographically inaccessible and irrecoverable, effectively sanitizing the media without physically altering the drive itself. This method is fast, efficient, and allows for device reuse.
Why this answer
Cryptographic erasure by destroying the encryption key is the most appropriate method because the data is already encrypted with full disk encryption; destroying the key renders the data unrecoverable without needing to overwrite the SSD, which is unreliable due to wear-leveling. This approach is efficient and secure for decommissioning.
Exam trap
CISSP often tests the confusion between physical destruction and cryptographic erasure, leading candidates to choose shredding when the scenario specifies encryption and SSD wear-leveling.
How to eliminate wrong answers
Option A is wrong because degaussing only works on magnetic media (HDDs), not SSDs, and can damage the drive without ensuring data removal. Option B is wrong because overwriting an SSD with a 7-pass method is ineffective due to wear-leveling, which may leave data in reserve blocks. Option D is wrong because physical destruction (shredding) is a valid method but is more resource-intensive and may not be necessary when cryptographic erasure is available; the question asks for the most appropriate method given the encryption.