hardMultiple Choice
220-1202 Practice Question: A company's security policy requires that all USB…
A company's security policy requires that all USB storage devices be blocked on company workstations to prevent data exfiltration. A manager needs to temporarily use a USB drive for a presentation. What is the best way to remediate this while maintaining security?
⚠ Common exam trap
Many exam-takers choose Option A or D because they think disabling the block domain-wide or using a local admin account is simpler, but CompTIA A+ tests the principle of least privilege and maintaining centralized security controls through Group Policy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a Group Policy to allow only the specific USB device by hardware ID, then remove the allowance after use
It uses Group Policy to enforce a device installation restriction by hardware ID, allowing only the specific USB device while blocking all others. This maintains the security policy's intent by preventing unauthorized devices while granting temporary, auditable access. After use, removing the allowance restores the full block without domain-wide disruption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable the USB blocking Group Policy for the entire domain
Why it's wrong here
Disabling the Group Policy domain-wide removes the block from every workstation, so any user can attach any USB storage device indefinitely — the opposite of maintaining security. It is tempting as a fast fix for one manager's deadline, but scoped exceptions or endpoint device control are the correct mechanism when a single user needs temporary access.
- ✓
Use a Group Policy to allow only the specific USB device by hardware ID, then remove the allowance after use
Why this is correct
Group Policy can target a device by its hardware ID, so the block remains enforced for all other USB storage while the manager's specific drive is permitted. Removing the allowance afterwards restores the original security posture, satisfying both the temporary need and the exfiltration policy.
- ✗
Give the manager a company-approved USB drive and tell them to use it only once
Why it's wrong here
A one-off exemption still leaves the drive's controller and firmware unvetted, so data can be copied off it before or after the presentation; the policy exists precisely because any removable device is an exfiltration path. It is tempting because it appears to limit exposure to a single use, but endpoint control or an approved encrypted drive is what actually enforces the restriction.
- ✗
Create a local admin account on the manager's workstation and disable the USB block locally
Why it's wrong here
A local admin account bypasses the centrally enforced USB block on one workstation, breaking the security policy and leaving no audit trail. It is tempting because it grants immediate local control, but it is correct only for legitimate administrative troubleshooting, not policy exceptions.
Go deeper
Related to this question
About these practice questions
One of 687 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.