CompTIA Server+ (SK0-005)Security and Disaster RecoveryHard

A server administrator is tasked with securely decommissioning a server containing highly confidential health records. The server has multiple solid-state drives (SSDs). Simply deleting files or reformatting the drives is insufficient due to forensic recovery risks. Which of the following data destruction methods is MOST appropriate for these SSDs to ensure data irrecoverability?

  1. ADegaussing the SSDs.
  2. BPhysically incinerating the entire server.
  3. CPerforming a secure erase using the drive's built-in functionality.
  4. DOverwriting the SSDs with a single pass of random data.
Show answer & explanation

Correct answer: C. Performing a secure erase using the drive's built-in functionality.

SSDs use flash memory, which is not magnetic, so degaussing is ineffective. Overwriting is problematic due to wear leveling and over-provisioning. A secure erase command leverages the SSD's firmware to permanently delete data across all memory blocks, rendering it irrecoverable without physically destroying the drive.

Why the other options are wrong

  • A. Degaussing is for magnetic media (HDDs, tapes) and is ineffective on solid-state drives (SSDs).
  • B. While incineration would destroy the data, it's an extreme and often impractical method for just the drives, and 'secure erase' is a more appropriate and widely accepted operational procedure for SSDs prior to physical destruction if needed.
  • D. Overwriting SSDs is less reliable than secure erase due to wear leveling spreading data across blocks, potentially leaving remnants.

SSD Secure Erase

A firmware command for solid-state drives (SSDs) that permanently erases all data blocks, making data irrecoverable.

  • Specific to flash-based storage.
  • Overcomes wear-leveling complexities.
  • Different from traditional HDD wiping.

Memory trick: SSDs need a 'secure' wipe, magnets don't work right.

More Security and Disaster Recovery questions