Which Should Be the First Consideration in Data Sanitization Method Selection?

Which of the following should be the FIRST consideration when selecting a data sanitization method?

  1. Risk tolerance
  2. Implementation cost
  3. Industry standards
  4. Storage type Source Reference Answer

Community Votes

D
50%
A
50%

50% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests whether you distinguish between primary risk-based decisions and later implementation details—storage type informs the method, but risk tolerance drives the sanitization level and standard.

In CDPSE exam context, the first consideration when selecting a data sanitization method is the organization's risk tolerance, not storage type or cost. Community consensus favors risk tolerance as it determines the required level of sanitization based on data sensitivity and regulatory compliance.

Selecting D (Storage type) is the most common mistake because storage type indeed determines which sanitization techniques are physically possible, but it is not the first consideration; risk tolerance should be evaluated first to define the necessary data protection outcome.

Community Discussion (4 comments)

4dfe785 👍 1 Selected: A
Understanding the organization's risk tolerance is crucial because it determines the level of data sanitization required to mitigate risks associated with data breaches or unauthorized access. The chosen method should align with the organization's acceptable level of risk and the sensitivity of the data being sanitized.
ARaghunanan 👍 1 Selected: D
The storage type determines the data sanitization METHOD!
Danford25 👍 1
A. Risk tolerance. This is particularly important for highly-regulated industries, which should opt for complete data sanitization to achieve compliance with data privacy and security regulations and mitigate the impact of a security breach. Other factors like implementation cost, industry standards, and storage type are also important, but risk tolerance is the primary consideration.
shiowbah 👍 1
A. Risk tolerance

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The correct answer is A. Risk tolerance. Data sanitization selection begins with assessing the risk to the organization if data is improperly recovered or disclosed. This risk tolerance is influenced by regulatory requirements, data classification, and the potential impact of a breach, and it establishes the minimum sanitization level required.

As one community comment notes, understanding risk tolerance is crucial because it determines the level of sanitization required to mitigate risks associated with data breaches or unauthorized access. The method chosen must align with the organization's acceptable risk level and the sensitivity of the data being sanitized.

Risk tolerance is also the primary driver in highly regulated industries, which should opt for complete sanitization to achieve compliance with data privacy and security regulations, as another comment highlights.

Why the Other Options Are Wrong

Option D (Storage type) is a practical constraint that affects which method can be used (e.g., degaussing works on magnetic media, not SSDs), but it is secondary to the risk assessment. Option B (Implementation cost) matters, but cost should not override the need to reduce risk to an acceptable level. Option C (Industry standards) provides guidance and control baselines, yet selecting a standard still presupposes a risk tolerance decision.

The first step in any security control decision is risk assessment; cost, standard, and media type are all considered after the desired risk posture is defined. Therefore, while those options are relevant, they are not the first consideration.

Community Comment Notes

Multiple comments consistently select A and explain that risk tolerance is the first question to ask. One comment specifically highlights the importance for highly regulated industries, where complete sanitization is necessary for compliance and breach mitigation. Another comment correctly notes that storage type determines the actual method, but that connection does not make it the first consideration.

The suggested answer D in the prompt is not supported by the community reasoning; the vote tie (50/50) indicates confusion, but the explanatory comments overwhelmingly favor A. In CDPSE, privacy risk assessment is foundational, so answer A is the best fit.

Official Reference

Exam Strategy

When a CDPSE question asks for the 'FIRST' consideration, look for the option that begins with a risk assessment or policy decision. Eliminate practical or cost-related choices first, because privacy and data protection frameworks require evaluating risk tolerance before selecting any method or technology.

Related Analysis

Practice All CDPSE Questions

Access 229 questions with complete answers and detailed explanations.

View Full CDPSE Practice Test →

← Back to CDPSE Study Guide