Study. uk . com
  1. Home
  2. All questions
  3. Question 166

CISSP study material · question 166 of 500

A product datasheet says its cryptographic erase destroys the wrapping key rather than the data encryption key. What follows from this, under NIST SP 800-88 Rev. 2?

  1. The security strength of that wrapping key becomes part of the assurance the erase provides.
  2. The erase is invalid, since only destroying the data encryption key qualifies.
  3. The erase becomes a clear rather than a purge technique.
  4. The data encryption key must additionally be overwritten in place.
Show the answer

Answer: A. The security strength of that wrapping key becomes part of the assurance the erase provides.

SP 800-88 notes the key being sanitized may be a wrapping key rather than the data encryption key itself, in which case that key's security strength is what matters.

Source: NIST SP 800-88 Rev. 2 (NIST) — SP 800-88 Rev. 2 > Table 1, Key Level and Wrapping

Challenge yourself on this topic → Study as cards