ISC2 Governance, Risk and Compliance (CGRC) Practice Question
While retiring a database server containing highly sensitive personal data, your team plans to redeploy its self-encrypting solid-state drives (SEDs) in the internal development lab. To satisfy secure data disposition requirements under NIST SP 800-88, which sanitization technique should you implement before redeployment?
Overwrite each drive once with pseudo-random data using a software wiping utility.
Perform a cryptographic erase by deleting and regenerating the SEDs' encryption keys.
Expose the drives to a certified degausser rated for current coercivity levels.
Send the drives for shredding and procure new hardware for the development lab.
NIST SP 800-88 Rev. 1 states that self-encrypting drives can be securely purged for reuse by performing a cryptographic erase, which destroys the media encryption key and renders all previously stored data unrecoverable while leaving the drive intact for later use. A single-pass software overwrite is unreliable on SSDs because wear-leveling may leave residual data. Physical destruction (shredding) would indeed sanitize the drives but is unnecessary and wasteful when the organization intends to reuse the hardware. Degaussing is ineffective on solid-state media, which lack magnetic platters. Therefore, cryptographic erase is the appropriate, standards-based method when redeploying SEDs internally.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why is cryptographic erase recommended for SEDs under NIST SP 800-88?
Open an interactive chat with Bash
Why is software overwriting unreliable on SSDs?
Open an interactive chat with Bash
Why does degaussing not work on solid-state drives?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Compliance Maintenance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .