easyMultiple Choice
200-201 Practice Question: An organization's security policy mandates that…
An organization's security policy mandates that all external media (USB drives, external hard drives) must be scanned for malware before use. An employee inserts a USB drive to transfer a presentation for a meeting. The employee runs the antivirus scan, but it fails to complete because the USB drive has a hardware write-protect switch. The employee is in a hurry. What should the employee do?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Remove the USB drive and use a different approved method of file transfer.
The security policy mandates scanning all external media before use. Because the USB drive has hardware write-protect, the antivirus scan cannot complete. Therefore, the employee should not use this USB drive and should instead use an alternative approved method (e.g., network share, email, or cloud storage) to transfer the file. This ensures compliance with the policy. Option A is incorrect because manually checking file extensions does not replace a proper malware scan. Option C is incorrect because disabling write protection may compromise security and the scan still might not be reliable. Option D is incorrect because bypassing the scan violates the policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Manually check each file for suspicious extensions.
Why it's wrong here
Manually inspecting filenames for suspicious extensions is not a malware scan and cannot detect malicious content hidden in documents or renamed files, so the policy requirement stays unmet. It tempts as a quick workaround when automated scanning fails, yet only a completed antivirus scan satisfies the mandate.
- ✓
Remove the USB drive and use a different approved method of file transfer.
Why this is correct
A write-protected USB drive cannot be scanned, so the malware-check policy cannot be satisfied. Using an approved alternative transfer method maintains compliance and avoids introducing unscanned media, satisfying the mandate that all external media be scanned before use.
- ✗
Disable write protection and rescan.
Why it's wrong here
Disabling the write-protect switch alters the media's hardware state and permits writes, but the mandated scan still has not completed, so policy is unmet. It tempts because removing the obstruction appears to unblock the scan, yet the correct action is to scan the drive on a system where the antivirus can complete before any transfer.
- ✗
Proceed with the file transfer since the scan failed due to hardware issue.
Why it's wrong here
Proceeding transfers unscanned media, directly violating the policy that requires a completed malware scan before use; a hardware fault is not an exemption. It tempts because the write-protect switch itself prevents malware writing to the drive, yet the presentation files remain uninspected and could carry malware onto the destination host.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.