Which Should Be the First Consideration in Data Sanitization Method Selection?
Which of the following should be the FIRST consideration when selecting a data sanitization method?
Community Votes
50% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests whether you distinguish between primary risk-based decisions and later implementation details—storage type informs the method, but risk tolerance drives the sanitization level and standard.
In CDPSE exam context, the first consideration when selecting a data sanitization method is the organization's risk tolerance, not storage type or cost. Community consensus favors risk tolerance as it determines the required level of sanitization based on data sensitivity and regulatory compliance.
Selecting D (Storage type) is the most common mistake because storage type indeed determines which sanitization techniques are physically possible, but it is not the first consideration; risk tolerance should be evaluated first to define the necessary data protection outcome.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The correct answer is A. Risk tolerance. Data sanitization selection begins with assessing the risk to the organization if data is improperly recovered or disclosed. This risk tolerance is influenced by regulatory requirements, data classification, and the potential impact of a breach, and it establishes the minimum sanitization level required.
As one community comment notes, understanding risk tolerance is crucial because it determines the level of sanitization required to mitigate risks associated with data breaches or unauthorized access. The method chosen must align with the organization's acceptable risk level and the sensitivity of the data being sanitized.
Risk tolerance is also the primary driver in highly regulated industries, which should opt for complete sanitization to achieve compliance with data privacy and security regulations, as another comment highlights.
Why the Other Options Are Wrong
Option D (Storage type) is a practical constraint that affects which method can be used (e.g., degaussing works on magnetic media, not SSDs), but it is secondary to the risk assessment. Option B (Implementation cost) matters, but cost should not override the need to reduce risk to an acceptable level. Option C (Industry standards) provides guidance and control baselines, yet selecting a standard still presupposes a risk tolerance decision.
The first step in any security control decision is risk assessment; cost, standard, and media type are all considered after the desired risk posture is defined. Therefore, while those options are relevant, they are not the first consideration.
Community Comment Notes
Multiple comments consistently select A and explain that risk tolerance is the first question to ask. One comment specifically highlights the importance for highly regulated industries, where complete sanitization is necessary for compliance and breach mitigation. Another comment correctly notes that storage type determines the actual method, but that connection does not make it the first consideration.
The suggested answer D in the prompt is not supported by the community reasoning; the vote tie (50/50) indicates confusion, but the explanatory comments overwhelmingly favor A. In CDPSE, privacy risk assessment is foundational, so answer A is the best fit.
Official Reference
Exam Strategy
When a CDPSE question asks for the 'FIRST' consideration, look for the option that begins with a risk assessment or policy decision. Eliminate practical or cost-related choices first, because privacy and data protection frameworks require evaluating risk tolerance before selecting any method or technology.
Related Analysis
Practice All CDPSE Questions
Access 229 questions with complete answers and detailed explanations.
View Full CDPSE Practice Test →