A decommissioned expansion shelf is leaving the building for a vendor warranty return, and legal wants assurance that no recoverable customer data leaves custody. What is the sanctioned fast path for that assurance?
Select an answer to reveal the explanation.
Short Explanation
When encryption is running, you don't erase the data - you erase the keys. Destroy the key material and the leftover bits are just very expensive confetti. That's cryptographic erase: fast, provable, and exactly why encrypted hardware leaving custody has a proper exit path instead of a truck full of shredding bills.
Full Explanation
On encrypted systems, recoverability is a property of the keys, so destroying the key hierarchy makes all wrapped data unrecoverable almost instantly - the recognized secure-disposal mechanism where supported, completing in minutes with an auditable event instead of weeks of drive handling. Encryption planning is thus disposal planning: media leaving custody already has a fast, provable erasure path on the day it must go. A single overwrite pass is slow at large scale, and wear-leveling plus reduction layers make proof-of-coverage difficult; overwrite suits unencrypted media, and where crypto erase exists it is the cleaner instrument. Unplug-and-hope is a serious misconception: shelf media is readable in a compatible enclosure, and separation from a head unit is no erasure mechanism. Degaussing and destruction remain valid for unencrypted media, but on encrypted systems key destruction gives the same assurance without dockside labor, custody mess, or destroying hardware the vendor will take back. Exam caveat: crypto-erase scope varies by platform - confirm what is erased on the removed component and route the operation through the same sensitive-task approvals as key management. Operational check: perform the erase, capture the audit record, and confirm the vendor's RMA process accepts the evidence before shipping.