200-201 Security Policies and Procedures Practice Question
A security manager is updating the organization's security awareness program after several incidents caused by employees inserting found USB drives. The manager wants a control that both reduces the likelihood of this behavior and provides a measurable metric for the awareness program. Which approach best meets both goals?
⚠ Common exam trap
The trap here is accepting a distribution or completion metric, such as emails delivered or policies signed, as proof that awareness training changed risky behavior.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run periodic simulated USB drop tests and track the click or insertion rate over time as a key performance indicator.
Simulated USB drop tests both reduce risk through reinforced training and produce a quantitative metric, the insertion or click rate, that reflects real behavior. Technical blocks and policy acknowledgments may reduce exposure but do not measure whether employees have internalized the lesson. Quarterly reminders measured by delivery count track activity rather than effectiveness, so they fail the measurement requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Require employees to sign an annual acceptable use policy acknowledgment stating they will not insert found USB drives.
Why it's wrong here
Policy acknowledgment creates a compliance record but is a weak behavior-change mechanism on its own. Employees may sign without internalizing the risk, and the acknowledgment provides only a binary metric of completion rather than evidence of reduced risky behavior. The scenario calls for measurable impact on the behavior itself, which signature tracking does not demonstrate, making this approach insufficient despite being a reasonable policy component.
- ✗
Disable all USB mass storage through endpoint policy and rely solely on the technical control to prevent incidents.
Why it's wrong here
Disabling USB storage is a strong technical control that reduces risk, but relying solely on it provides no measurable awareness metric and does not change employee behavior or judgment. Users may find workarounds or fail to recognize similar social engineering tactics delivered by other means. The scenario explicitly asks for both risk reduction and a measurable metric for the awareness program, so a purely technical approach is incomplete.
- ✓
Run periodic simulated USB drop tests and track the click or insertion rate over time as a key performance indicator.
Why this is correct
Simulated USB drop tests directly measure whether employees exhibit the risky behavior in a controlled, ethical manner, and the insertion rate becomes a quantitative metric that can be trended across quarters. Combined with targeted training after each test, this approach reduces likelihood by reinforcing awareness. It satisfies both requirements: behavior change through education and a measurable indicator of program effectiveness that management can review.
- ✗
Send a quarterly email reminding staff about the dangers of found USB drives and count the number of emails delivered.
Why it's wrong here
Email reminders are a common awareness tactic, but counting deliveries measures distribution, not comprehension or behavior change. There is no evidence that recipients read or acted on the message, and the metric says nothing about whether risky insertions decreased. Because the scenario requires a metric tied to the actual behavior, delivery counts are a vanity metric and do not meet the stated goal.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.