Soru

Zorluk: ZorData Destruction and Disposal Methods

An IT security analyst is tasked with decommissioning a storage array that contains self-encrypting enterprise NVMe solid-state drives (SSDs) holding sensitive customer financial data. The company plans to reuse the SSDs in an internal, non-sensitive testing laboratory. According to NIST SP 800-88 guidelines for media sanitization (Purge level), which of the following actions will securely sanitize the flash storage while keeping the drives operational for reuse?

  1. Execute a cryptographic erase (CE) command utilizing the drive firmware and Physical Security ID (PSID).Cevap
  2. B
    Expose the drives to a commercial high-coercivity electromagnetic degaussing field.
  3. C
    Perform a standard full disk format using the operating system volume management console.
  4. D
    Run a multi-pass zero-fill disk wiper tool targeting logical block addresses across the file system.

Cevap

Execute a cryptographic erase (CE) command utilizing the drive firmware and Physical Security ID (PSID).
Executing a cryptographic erase (CE) via drive firmware and PSID deletes or overwrites the internal Media Encryption Key (MEK) stored on self-encrypting drives (SEDs). Without this key, all stored data becomes permanently unrecoverable cipher text, satisfying security compliance while keeping the physical NVMe SSD functional for redeployment.

Adım Adım Çözüm

1
Identify media type and disposition goals
The target drives are flash-based solid-state drives (NVMe SSDs) with built-in hardware encryption (SEDs) intended for hardware reuse.
Selection of data destruction techniques depends directly on physical storage architecture and whether the hardware will be destroyed or redeployed.
2
Evaluate sanitization methods for solid-state drive reuse
Physical destruction prevents reuse. Degaussing is ineffective on flash memory. OS formatting and basic logical overwriting leave inaccessible data remnants due to SSD wear-leveling and over-provisioning.
SSD controllers abstract physical flash blocks, requiring firmware-level sanitization methods.
3
Select the appropriate NIST SP 800-88 Purge method
Cryptographic erase (CE) / Sanitize Block Erase securely destroys the Media Encryption Key (MEK), rendering all stored data permanently unreadable while leaving the drive usable.
Cryptographic Erase fulfills Purge-level sanitization requirements for self-encrypting SSDs prior to redeployment.

Anahtar Kavram

Cryptographic Erase and Solid-State Drive (SSD) Sanitization
Tahmini Süre:1m 30s
Bu soruyu puanla