An organization operates a classified research network that is air-gapped from the Internet. Engineers occasionally request to connect USB flash drives to transfer configuration files. Which of the following is the BEST control to mitigate the security risks posed by portable USB storage devices in this highly sensitive environment?
Permit engineers to use personal USB drives after they sign an acceptable-use agreement acknowledging the risks.
Require users to run an antivirus scan on their USB drive and lift all restrictions if no malware is detected.
Implement USB port control that blocks all unauthorized devices and allow only organization-supplied, encrypted, whitelisted drives under a formal approval process.
Allow any USB device to be connected as long as endpoint antivirus and EDR software are kept up to date.
Restricting removable media by enforcing USB port control and allowing only organization-issued, encrypted, whitelisted drives provides defense in depth. It prevents malware-laden or unknown devices from being attached, mitigates BadUSB-style firmware attacks, and limits data exfiltration channels. Endpoint antivirus alone (B) or user agreements (C) rely on easily bypassed human and software controls, while relying solely on a malware scan after connection (D) still exposes systems to zero-day or firmware-level threats.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an air-gapped network?
Open an interactive chat with Bash
What is BadUSB-style firmware attack?
Open an interactive chat with Bash
Why are encrypted and whitelisted USB drives important in secure environments?
Open an interactive chat with Bash
ISC2 CISSP
Identity and Access Management (IAM)
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .