A Data Domain appliance is being decommissioned because it reached end of life. A reseller offers to buy it “as is, for parts.” Local data-retention policy requires proof that all customer data is unrecoverable before custody leaves the site. What should you do first?
Select an answer to reveal the explanation.
Short Explanation
Think of disposal like shredding paper: if you just delete the folder, you still have the paper. You need a documented erase and a signed record before anyone else touches the appliance. The trap is treating encryption or account cleanup as proof that the data is gone.
Full Explanation
Data Domain decommissioning is a data-security control, not an asset-disposal convenience. A supported exit path is a documented sanitization method that renders stored information unrecoverable: cryptographic erase when the system’s encryption model allows key destruction, or physical destruction when organizational policy or media condition requires it. The critical control is evidence: a destruction certificate, log, or signed record proving the method was completed before custody changes. Encryption at rest protects data while the appliance remains under administrative control, but it does not by itself prove the data cannot be recovered after handover, especially if keys are not destroyed or the buyer can access the system. Deleting MTrees and disabling accounts is lifecycle hygiene, not secure destruction, because filesystem metadata and backup data may persist. Formatting or letting a reseller wipe the appliance shifts responsibility to an unverified third party and provides no compliant evidence chain. Exam caveat: choose the answer that pairs a recognized sanitization method with retained proof, not a convenience disposal step. Operational check: complete the supported erase, export or print the completion record, and attach it to the decommission ticket before shipping the asset.