SY0-701 Question 483
Single answerA company has shifted to a hybrid work model. Several recent incidents have occurred: employees have plugged personal USB drives into corporate laptops to transfer files while working from home, one employee posted a photo of a home workspace on social media that exposed a customer contact list on a monitor, and help desk staff reported an increase in callers asking for password resets while refusing standard identity verification because they are "traveling." Management wants the MOST effective single action to reduce the likelihood of these issues recurring across the workforce.
- A
Deploy a company-wide user guidance and training program that updates the security handbook and reinforces operational security, removable media rules, password reset verification procedures, insider threat awareness, and social engineering reporting for hybrid workers
- B
Block all USB ports on every corporate endpoint and disable remote password resets for all users
- C
Require employees to sign an acknowledgment that they have read the acceptable use policy, without changing current training or procedures
- D
Increase endpoint logging for remote users and review alerts weekly for suspicious behavior
Show answer and explanation
Correct answer: A
Explanation
The best answer is the comprehensive user guidance and training program because the incidents span several Security+ user-awareness domains: password management and password reset procedures, removable media controls, social engineering resistance, situational awareness, insider threat awareness, and operational security in hybrid or remote work environments. Administrative controls such as policies, handbooks, standard operating procedures, and recurring training are specifically intended to shape secure behavior and establish expected practices. Best practice is to pair clear documentation with role-based security awareness training and reporting procedures, especially for help desk personnel who are common social engineering targets. Relevant guidance aligns with standard security awareness and training practices such as those described in NIST SP 800-50 and NIST SP 800-61/800-53 families for awareness, acceptable use, media protection, and incident reporting. Technical controls like USB blocking and logging can complement the program, but they do not replace the need for workforce education and policy reinforcement in a hybrid-work setting.
- A. Correct.
Correct. This is the most effective single action because the scenario reflects multiple human-centered control failures: unsafe removable media use, poor situational awareness and operational security in a home environment, and social engineering attempts targeting help desk password resets. Updating the security handbook and delivering targeted training addresses the root cause across the workforce. It also supports insider threat awareness by clarifying acceptable behavior, reporting expectations, and consequences. In hybrid environments, policy plus recurring training is a foundational administrative control that reduces repeated risky behavior.
- B. Incorrect.
Incorrect. Blocking USB ports and disabling remote password resets may reduce some technical risk, but this is too narrow and disruptive as a single broad response. It does not address oversharing on social media, weak situational awareness, or help desk susceptibility to social engineering. It could also hinder legitimate business operations. Security+ emphasizes layered controls; technical restrictions alone are not sufficient when the underlying issue is user behavior and guidance.
- C. Incorrect.
Incorrect. A policy acknowledgment by itself is weaker than active training and procedural reinforcement. Employees may sign a document without understanding how to apply it in realistic hybrid-work scenarios. This option also does not improve help desk verification steps or teach staff how to recognize social engineering and operational security risks. A signed policy is useful for governance, but it is not the most effective standalone action here.
- D. Incorrect.
Incorrect. Additional logging is a detective control, not a preventive measure for the broad set of issues described. Weekly review may help identify suspicious activity after the fact, but it does not educate employees on removable media restrictions, password management practices, or secure behavior in remote workspaces. Since the goal is to reduce recurrence, stronger user guidance and training is the better primary action.