A systems administrator is preparing to repurpose several Self-Encrypting Drives (SEDs) from a decommissioned database server that previously held highly confidential patient records. The drives must be sanitized in compliance with organizational policy before being redeployed to a non-sensitive testing environment. Which of the following methods should the administrator execute to instantly render all existing data irrecoverable while keeping the drives fully operational?
- Perform a Cryptographic Erase (Crypto-Erase) using the drive vendor's management utility to erase the Media Encryption Key.Cevap
- BExpose the drives to an industrial degaussing wand to neutralize the magnetic domains across the storage media.
- CRun a standard full format within the operating system's Disk Management utility to write zeros to all sectors.
- DFeed the drives through an industrial drive shredder to reduce the physical media to uniform particles.
Cevap
Cryptographic Erase (Crypto-Erase) using the drive vendor's management utility to erase the Media Encryption Key
Performing a Cryptographic Erase (Crypto-Erase) on Self-Encrypting Drives (SEDs) erases or resets the internal Media Encryption Key (MEK). Because all data written to an SED is encrypted at the hardware level, deleting the encryption key makes the existing data instantly and permanently unrecoverable, while resetting the drive to a usable factory state for safe redeployment.
Adım Adım Çözüm
Anahtar Kavram
Cryptographic Erase (Crypto-Erase) on Self-Encrypting Drives (SEDs)