SY0-701 exam dumps

SY0-701 practice question 67 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 67

Single answerRemovable device

A security administrator discovers that several employees have been copying sensitive project files to personal USB flash drives so they can work from home. The organization wants to reduce the risk of data loss from removable media without completely preventing the use of approved encrypted USB devices issued by IT. Which control would BEST address this requirement?

  1. A

    Implement a removable media policy and configure endpoint protection to block unauthorized USB storage while allowing only approved encrypted devices

  2. B

    Disable all workstation antivirus services so users can access USB drives without file scanning delays

  3. C

    Require employees to rename confidential files before copying them to USB drives

  4. D

    Allow any USB device, but require users to sign an acceptable use policy each quarter

Show answer and explanation

Correct answer: A

Explanation

The best answer is to enforce removable media restrictions through both policy and technical controls. In Security+ terms, removable media represents both a data exfiltration risk and a malware introduction risk. A strong solution includes a removable media policy, device control/USB allowlisting, and the use of organization-issued encrypted media for approved business needs. This aligns with common best practices from enterprise endpoint management, data loss prevention strategies, and guidance such as NIST SP 800-53 controls related to media protection and access enforcement. Administrative controls alone, such as policies and user acknowledgments, are not sufficient unless backed by technical enforcement.

  • A. Correct.

    Correct. This combines administrative and technical controls to manage removable device risk. A removable media policy defines acceptable use, while endpoint security or device control software can enforce allowlisting so that only approved encrypted USB storage devices are usable. This approach directly addresses the requirement to reduce data loss risk without banning all removable media.

  • B. Incorrect.

    Incorrect. Disabling antivirus weakens endpoint security and does nothing to control unauthorized data copying. In fact, USB devices are a common malware delivery method, so antivirus and related endpoint protections remain important when removable media is used.

  • C. Incorrect.

    Incorrect. Renaming files does not provide any real security control. Sensitive data would still be exposed if copied to an unauthorized device, and this option does not address encryption, device authorization, or data loss prevention.

  • D. Incorrect.

    Incorrect. An acceptable use policy is useful as an administrative control, but by itself it does not technically prevent users from connecting personal USB drives or copying sensitive data to them. The scenario requires a control that reduces risk in practice, not just one that documents expectations.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam