Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A company security policy prohibits users from connecting unauthorized USB storage devices to their workstations. Which Group Policy setting should the administrator configure to enforce this policy?

⚠ Common exam trap

Watch out — candidates often confuse 'Device Installation Restrictions' (which blocks driver installation but not use of already-installed devices) with 'Removable Storage Access' (which directly controls read/write access to storage devices), leading them to select Option A instead of the correct answer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

C

The 'Removable Storage Access' policy under Computer Configuration > Administrative Templates > System > Removable Storage Access allows administrators to set specific deny permissions for all removable storage classes, including USB devices. By configuring the 'All Removable Storage classes: Deny all access' setting, the administrator enforces the company policy that prohibits unauthorized USB storage devices from being connected to workstations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A

    Why it's wrong here

    This policy blocks installation of devices but does not prevent use of already installed USB storage devices. The question requires preventing unauthorized USB storage devices from being connected, which is more directly controlled by removable storage access policies.

  • ✗

    B

    Why it's wrong here

    This is not a standard Group Policy setting. The correct policy is under Removable Storage Access.

  • ✓

    C

    Why this is correct

    Correct. The 'Removable Storage Access' policy under Computer Configuration > Administrative Templates > System > Removable Storage Access allows setting 'All Removable Storage classes: Deny all access' to prohibit unauthorized USB storage devices.

  • ✗

    D

    Why it's wrong here

    This setting does not directly control USB storage device access.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.