2.8 - Secure data destruction and drive disposal

CompTIA A+ Core 2 objective 2.8 covers destroying data and disposing of drives so information can never be recovered. When a drive is leaving the company, physically destroy it - shredding, drilling, incinerating or degaussing - and keep a certificate of destruction as proof it was properly destroyed. Before donating or reselling old PCs, the drives must be securely wiped or destroyed first. A key exam trap: degaussing works on magnetic hard drives but will not reliably erase a solid-state drive, because an SSD stores data in flash, not magnetically. If a drive will be reused internally, a certified secure multi-pass wipe removes the data while keeping the drive usable. Expect scenario questions that state whether the drive is being retired or reused and ask for the correct destruction or sanitisation method.

Memory hook
Leaving the company = physically destroy (shred/drill/incinerate/degauss) + certificate of destruction. Reused internally = certified multi-pass wipe. Trap: degaussing does NOT erase SSDs (flash, not magnetic).

Practice questions

1. A company must dispose of drives so data is UNRECOVERABLE. Which methods are appropriate for HDDs?

  • Perform a quick format only
  • Physically shred or degauss the drive (correct answer)
  • Move the files to the Recycle Bin
  • Rename all of the files

Shredding/pulverizing (physical destruction) or degaussing magnetic media renders HDD data unrecoverable. A quick format doesn't.

2. After certified destruction of drives, what proves the data was properly destroyed?

  • A screenshot of the tool
  • A certificate of destruction (correct answer)
  • A confirmation email
  • A photo of the box

A certificate of destruction documents that media was destroyed per standards — important for audits/compliance.

3. Before donating old company PCs, what must be done to the drives?

  • Nothing needs to be done
  • Securely wipe or destroy them first (correct answer)
  • Just delete the desktop icons
  • Simply hide the data files

Repurposing/donating requires a certified secure wipe (or destruction) so no recoverable company/PII data remains.

4. Why won't degaussing reliably erase a solid-state drive (SSD)?

  • SSDs are simply far too large
  • SSDs store data in flash, not magnetically (correct answer)
  • Degaussing drives is against the law
  • SSDs contain no real recoverable data

Degaussing erases magnetic media (HDD/tape). SSDs use flash — use crypto-erase, a secure ATA erase, or physical destruction.

5. Which BEST describes physical destruction methods for drives?

  • A quick high-level disk format
  • Shredding, drilling, or incinerating it (correct answer)
  • Renaming the sensitive files
  • Emptying the desktop Recycle Bin

Physical destruction (shred, drill, pulverize, incinerate) makes data unrecoverable — the surest disposal method.

6. A drive will be REUSED internally. Which method removes data while keeping the drive usable?

  • Physical mechanical shredding
  • A certified secure multi-pass wipe (correct answer)
  • Complete incineration of the drive
  • Magnetic degaussing before reuse

For reuse, a certified secure wipe/erase overwrites data while leaving the drive functional (destruction would ruin it).

Related objectives