71.9k views
4 votes
A systems administrator has installed a disk wiping utility on all computers across the organization and configured it to perform a seven-pass wipe and an additional pass to overwrite the disk with zeros. The company has also instituted a policy that requires users to erase files containing sensitive information when they are no longer needed.

To ensure the process provides the intended results, an auditor reviews the following content from a randomly selected decommissioned hard disk:

00000000000000000000000000
00000000000000000000000000
00000000000000000000000000
000000000000000000000qjkehd

Which of the following should be included in the auditor's report based on the above findings?

A. The hard disk contains bad sectors
B. The disk has been degaussed.
C. The data represents part of the disk BIOS.
D. Sensitive data might still be present on the hard drives.

User Kamalav
by
7.2k points

1 Answer

6 votes

Final answer:

The presence of the string "000qjkehd" on a wiped hard disk indicates the wiping process might have failed to remove all data, suggesting that sensitive information might still be recoverable.

Step-by-step explanation:

An auditor's review of a decommissioned hard disk that was supposed to be wiped using a seven-pass technique plus an additional pass to overwrite with zeros but contains the string "000qjkehd" suggests that sensitive data might still be present on the hard drives. This is because the presence of any non-zero characters, in this case, "qjkehd", indicates that the disk wiping process may not have been fully successful. Therefore, the auditor should include in the report that there is a potential risk of sensitive data being recoverable.

User Ssokolow
by
7.6k points