Best Data Handling Steps When Reissuing a Former Employee Laptop
A security administrator is reissuing a former employee's laptop. Which of the following is the best combination of data handling activities for the administrator to perform? (Choose two.)
Community Votes
55% of anonymous learners picked answer BE. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
It tests the critical difference between hardware disposal and hardware repurposing, trapping test-takers who select irreversible methods instead of verification-focused secure erasure.
This question evaluates secure data lifecycle procedures when repurposing hardware, emphasizing how to legally and technically remove residual information from reused devices. While candidates debate between retention and certification, the exam framework prioritizes verified secure erasure to maintain compliance and prevent data leakage.
Many candidates choose Destruction and Sanitization, incorrectly assuming that sensitive data always requires physical or logical obliteration, failing to recognize that destruction permanently disables the asset and contradicts the goal of reissuance.
Community Discussion (32 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept: Secure Data Handling for Reusable Assets
When preparing a former employee’s laptop for reassignment, administrators must follow standardized data lifecycle controls. The primary goal is to eliminate unauthorized access risks while ensuring the hardware remains fully operational.Why Certification and Sanitization are Correct
Sanitization involves using software tools to overwrite, clear, or purge storage media so that data cannot be recovered through standard means. Because the laptop is being reissued, the drive must remain intact, making sanitization the appropriate technical action. Certification is the formal documentation or verification process that confirms sanitization (or destruction) was successfully completed. As noted by experienced candidates, certification serves as the audit trail proving the device is clean and compliant before it leaves IT custody. CompTIA consistently pairs these two actions to represent a complete, auditable secure-handling workflow.Why Other Options Fall Short
- Data retention focuses on policy-driven preservation of records for legal or business purposes. While backups may occur before wiping, retention itself is not a direct hardware preparation step for reissuance.
- Destruction permanently renders storage media unreadable or physically damages it. As multiple community members pointed out, destroying the drive would make the laptop unusable, directly conflicting with the “reissuing” scenario.
- Classification occurs during data creation or collection to determine sensitivity levels and handling requirements. It is irrelevant to post-departure device preparation.
Official Reference
- NIST Special Publication 800-88 Rev. 1: Guidelines for Media Sanitization
- CompTIA Security+ SY0-701 Official Study Guide: Chapter 1 - General Security Concepts
Exam Strategy
Always anchor your answer to the device’s end state in the prompt. If the hardware is being reused, recycled, or redeployed, immediately eliminate any option implying permanent damage or unavailability. Pair technical removal steps with their corresponding verification or documentation controls to satisfy CompTIA’s emphasis on auditable security practices.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →