SY0-701 exam dumps

SY0-701 practice question 68 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 68

Single answerRemovable device

A security administrator discovers that several employees have been copying sensitive engineering files to personal USB flash drives so they can work from home. Company policy allows only approved removable media for business use, and leadership wants to reduce the risk of data loss without preventing legitimate file transfers to company-issued drives. Which control would BEST address this requirement?

  1. A

    Implement a data loss prevention (DLP) solution with device control policies that allow only approved removable media

  2. B

    Disable full-disk encryption on company laptops so files can be scanned before being copied to USB devices

  3. C

    Require employees to compress files into password-protected ZIP archives before copying them to any removable media

  4. D

    Increase network firewall logging for outbound traffic from employee workstations

Show answer and explanation

Correct answer: A

Explanation

The best answer is to implement DLP with removable media/device control because the organization needs a compensating and preventive control that both restricts unauthorized USB devices and still allows approved business use. This aligns with common enterprise security practices for controlling removable media, reducing the risk of data exfiltration, and supporting audit requirements. In practice, organizations often combine this with endpoint management, acceptable use policies, and encryption requirements for company-issued removable drives. Guidance from standards and best practices such as NIST SP 800-53 Media Protection (MP) controls and CIS Controls supports limiting use of removable media, enforcing authorization, and monitoring data transfers to removable devices.

  • A. Correct.

    Correct. A DLP solution with device control is designed to monitor and restrict data transfers to removable media based on policy. In this scenario, it can enforce allowlists for authorized USB devices, block personal flash drives, and log or prevent copying of sensitive files. This directly addresses the requirement to permit legitimate transfers only to company-issued removable media while reducing data exfiltration risk.

  • B. Incorrect.

    Incorrect. Disabling full-disk encryption weakens endpoint security and does not solve the removable media control problem. Full-disk encryption protects data at rest on the laptop if the device is lost or stolen. It does not provide granular policy enforcement for which USB devices may receive copied files.

  • C. Incorrect.

    Incorrect. Password-protected ZIP files may add a layer of protection, but they do not prevent employees from using unauthorized personal USB drives. In some environments, encrypted archives can also make inspection by security tools more difficult. This option addresses file packaging, not device authorization and control.

  • D. Incorrect.

    Incorrect. Firewall logging focuses on network traffic, not local file transfers to USB flash drives. While outbound logging can help detect some exfiltration over the network, it does not control or prevent copying files to removable media attached directly to a workstation.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam