Best Data Handling Steps When Reissuing a Former Employee Laptop

A security administrator is reissuing a former employee's laptop. Which of the following is the best combination of data handling activities for the administrator to perform? (Choose two.)

  1. Data retention
  2. Certification Source Reference Answer
  3. Destruction
  4. Classification
  5. Sanitization Source Reference Answer

Community Votes

BE
55%
AE
45%

55% of anonymous learners picked answer BE. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

It tests the critical difference between hardware disposal and hardware repurposing, trapping test-takers who select irreversible methods instead of verification-focused secure erasure.

This question evaluates secure data lifecycle procedures when repurposing hardware, emphasizing how to legally and technically remove residual information from reused devices. While candidates debate between retention and certification, the exam framework prioritizes verified secure erasure to maintain compliance and prevent data leakage.

Many candidates choose Destruction and Sanitization, incorrectly assuming that sensitive data always requires physical or logical obliteration, failing to recognize that destruction permanently disables the asset and contradicts the goal of reissuance.

Community Discussion (32 comments)

cf83993 👍 27 Selected: BE
Bro you don't reissue something after you destroy it do you? We're talking about a laptop here not an ex ;)
Th3irdEye 👍 18 Selected: AE
Destruction would make the device not usable again. Certification might make sense here if a third party was being used to sanitize the drive but usually third parties are used to destroy drives and certification is given for destruction. I think Data retention and Sanitization makes the most sense. You want to make sure you save any critical data before you erase the drive.
Konversation 👍 3 Selected: AE
Since the question does not refer a third-party but to the "internal" administrator and following the CompTIA theoretical questions it's A & E. E. Sanitization. This is clear. A. Data retention. The CompTIA Student Guide and WBT refer to the "Data retention" in the "Secure Data Destruction" chapter. B. Certification is used by CompTIA only for third-party "Asset Disposal". But a third-party is not mentioned in the question. "certification - An asset disposal technique that relies on a third party to use sanitization or destruction methods for data remnant removal, and provides documentary evidence that the process is complete and successful." C. Destruction - CompTIA defines this as "Physical destruction methods include shredding, crushing ..." This is also not the case for this question.
adderallpm 👍 2 Selected: AE
Destruction renders the device unusable does it no? And you only need a certification after destruction from a third-party? So in reality, you would just want to back up the data and then make sure to overwrite the hard drive a couple times so that, that data can’t be recovered. 🫶🏻
d2087a6 👍 1 Selected: CE
To safely reissue the laptop, the administrator should sanitize the device to remove all data securely. If sanitization isn’t sufficient for highly sensitive data, destruction of the storage medium may be required.
dbrowndiver 👍 2 Selected: BE
Data destruction involves securely deleting sensitive information so it cannot be recovered. Before reissuing a laptop, it is critical to ensure that any residual data from the previous user is permanently removed to prevent unauthorized access to sensitive information.
0ca8ee9 👍 3 Selected: BE
Sanitization - cleaning the laptop memory Certification - proving that the laptop is clean.
ProudFather 👍 3 Selected: CE
To ensure the security of the data, the administrator should: Destruction: Physically destroy any storage media that cannot be sanitized. Sanitization: Thoroughly erase or overwrite all data on the storage media to prevent data recovery. The other options are not relevant to the scenario: Data retention: This involves keeping data for a specific period. It's not applicable in this case as the data needs to be removed. Certification: This is a process of verifying that a system or process meets specific standards. It's not relevant to data handling in this context. Classification: This involves assigning security labels to data based on its sensitivity. It's not necessary in this case as the data is being removed. Enumeration: This involves identifying and cataloging assets. It's not relevant to data handling in this context.
AndyK2 👍 2 Selected: CE
C. Destruction > ensures physical media is rendered unrecoverable E. Sanitization > removes and overwrites sensitive data to prevent unauthorized access. Both used to protect data security when repurposing hardware.
MikelMiguel 👍 2
Its Destruction and Sanitation. This is because the laptop is been reissued and because they question did not say reissued to the "same employee" then we have to assume is been intended to be reissued for a new or another employee. therefore D&E is the answer
3dk1 👍 3 Selected: AE
Th3irdEye explains my thinking
Emmyrajj 👍 1 Selected: CE
C. Destruction E. Sanitization Explanation: 1. Destruction: This involves permanently destroying any sensitive data on the laptop that is no longer needed. This ensures that no residual data from the previous user remains on the device, reducing the risk of unauthorized data access. 2. Sanitization: This involves securely wiping the laptop’s storage to remove all data and ensure that it cannot be recovered. Sanitization is critical when reissuing devices to prevent accidental disclosure of sensitive information.
nillie 👍 2 Selected: CE
The best combination of data handling activities for the administrator to perform when reissuing a former employee's laptop are: C. Destruction and E. Sanitization Destruction: Ensures that any sensitive or personal data from the previous user is permanently removed and cannot be recovered. Sanitization: Refers to thoroughly cleaning the device by securely wiping the data to prevent unauthorized access. This prepares the laptop for safe reissue to a new user. These two activities are critical for preventing any sensitive data leakage from the former employee while ensuring that the device is clean and secure for the next user.
Ty13 👍 6 Selected: AE
Retention and Sanitize. Think about it. An employee leaves - you backup any pertinent company data (Retention) and reimage the computer (Sanitize). - You would not Certify it, because that's only if the drive needed to be destroyed. - You would not Destroy it because that's really only important for sensitive things, not Judy the Customer Service agent. - You would not Enumerate it (gathering info for vulnerabilities) - Classification is typically more important for data rather than devices.
ImpactTek 👍 2
The answer is C&E. Destruction here refers to destroying data not the laptop.
koala_lay 👍 3 Selected: BE
Agree to answer B E
baronvon 👍 5 Selected: AE
A and E Sanitization refers to the process of removing or cleaning data from a device to ensure that it cannot be recovered by unauthorized individuals. This typically includes methods such as wiping or formatting the storage media While decommissioning and disposal are important, organizations often have to retain data or systems as well. Retention may be required for legal purposes with set retention periods determined by law, or retention may be associated with a legal case due to a legal hold
tamdod 👍 1
What about any data that may need to be retained? Should we not retain the data then sanitized it for reuse?
Hayder81 👍 3
B, E it's being reused. So, you need to sanitize and certify
a4e15bd 👍 2
C. Destruction E. Sanitization
pedrwc7 👍 3
A. Data retention • retain data B. Certification • Audit log of either Sanitization, Disposal or Destruction C. Destruction •Destruction is goes beyond Sanitization ensures physical devices is unusable. It means you destroy it in pieces. D. Classification • Base on value and sensitivity of the data. E. Sanitization • Sanitization is thorough process to ensure the data is inaccessible and irretrievable, however, it can be reuse. F. Enumeration •
dbrowndiver 👍 4
When reissuing a laptop, it's crucial to ensure that all previous data is irretrievably removed, and the device is clean and secure for the next user. Destruction and Sanitization are two key processes involved in handling data securely in this context. Opt. C. Destruction: This process involves permanently destroying data so it cannot be recovered. It is often used when data is no longer needed and must be securely eliminated. Destruction is crucial to prevent data leakage or unauthorized access to old data. It provides peace of mind that the data is gone and cannot be retrieved. Opt.E. Sanitization: This process involves cleaning a device to remove data and make it safe for reuse. Techniques include overwriting, degaussing, and cryptographic erasure. Preparing for Reuse: Sanitization makes sure that all traces of previous data are removed, and the device is in a clean state, ready for new usage. Sanitization ensures that any residual data from the former employee is thoroughly erased, making the laptop safe and secure for the next user.
EfaChux 👍 1
If it is for recycling then it would be destruction and certification and for reuse, it will be sanitization and certification
Bimbo_12 👍 1 Selected: E
Saitization for sure as the Security Admin needs to get rid of the old data. Destruction is counterproductive as the Laptop is to be reissued. Enumeration makes sense because it needs to be noted for in some form of inventory.
cdsu 👍 1
Answer: C. Destruction E. Sanitization
drosas84 👍 2 Selected: BE
B/E it's being reused. So you need to sanitize and certify that it has been wiped clean.
e56400d 👍 2
I just did a large laptop resale at my company. In order to sell our old user's company laptops we had the wipe/sanitize the data and provide the certificate that the computer is wipe.
Shaman73 👍 2 Selected: BE
sanitize and certify
123456789User 👍 4 Selected: CE
C: Sanitize by removing all data from the laptop. E: Destroy the physical storage drive.
SHADTECH123 👍 2 Selected: BE
E. Sanitization: This involves removing or destroying sensitive information from the laptop to ensure that the data cannot be accessed by unauthorized individuals. B. Certification: After sanitizing the laptop, the administrator should certify that the sanitization process has been completed successfully.
e5c1bb5 👍 1 Selected: B
sanitize and certify
AutoroTink 👍 4 Selected: BE
You can't reissue a laptop if you've destroyed it. It does need to be sanitized, and then certified that the sanitization was complete and G2G.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Concept: Secure Data Handling for Reusable Assets

When preparing a former employee’s laptop for reassignment, administrators must follow standardized data lifecycle controls. The primary goal is to eliminate unauthorized access risks while ensuring the hardware remains fully operational.

Why Certification and Sanitization are Correct

Sanitization involves using software tools to overwrite, clear, or purge storage media so that data cannot be recovered through standard means. Because the laptop is being reissued, the drive must remain intact, making sanitization the appropriate technical action. Certification is the formal documentation or verification process that confirms sanitization (or destruction) was successfully completed. As noted by experienced candidates, certification serves as the audit trail proving the device is clean and compliant before it leaves IT custody. CompTIA consistently pairs these two actions to represent a complete, auditable secure-handling workflow.

Why Other Options Fall Short

  • Data retention focuses on policy-driven preservation of records for legal or business purposes. While backups may occur before wiping, retention itself is not a direct hardware preparation step for reissuance.
  • Destruction permanently renders storage media unreadable or physically damages it. As multiple community members pointed out, destroying the drive would make the laptop unusable, directly conflicting with the “reissuing” scenario.
  • Classification occurs during data creation or collection to determine sensitivity levels and handling requirements. It is irrelevant to post-departure device preparation.
By aligning with CompTIA’s theoretical model, certification validates the sanitization process, ensuring both technical security and regulatory compliance when transitioning assets to new users.

Official Reference

  • NIST Special Publication 800-88 Rev. 1: Guidelines for Media Sanitization
  • CompTIA Security+ SY0-701 Official Study Guide: Chapter 1 - General Security Concepts

Exam Strategy

Always anchor your answer to the device’s end state in the prompt. If the hardware is being reused, recycled, or redeployed, immediately eliminate any option implying permanent damage or unavailability. Pair technical removal steps with their corresponding verification or documentation controls to satisfy CompTIA’s emphasis on auditable security practices.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide