hardMultiple ChoiceObjective-mapped
CAS-004 Practice Question: Needs to design a solution to detect and respond…
A security engineer needs to design a solution to detect and respond to insider threats involving unauthorized data exfiltration via USB devices. Which of the following is the MOST effective approach?
⚠ Common exam trap
A common mix-up: candidates choose EDR (Option B) because they associate it with endpoint security, but EDR is designed for threat detection (e.g., malware, lateral movement), not for granular data exfiltration control via USB, which requires DLP's content-aware inspection and device control capabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement a data loss prevention (DLP) solution with device control and content inspection.
The most effective because a DLP solution with device control and content inspection can monitor, block, or alert on unauthorized data transfers to USB devices by inspecting the content being written (e.g., file types, keywords, patterns) and enforcing policies at the endpoint or network level. This directly addresses the specific threat of data exfiltration via USB, unlike other options that either lack detection or are too restrictive.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Conduct regular security awareness training on data handling policies.
Why it's wrong here
Training is important but does not provide technical enforcement.
- ✗
Deploy endpoint detection and response (EDR) agents on all workstations.
Why it's wrong here
EDR is reactive and may not prevent exfiltration.
- ✗
Disable all USB ports via group policy.
Why it's wrong here
Disabling USB ports entirely may hinder legitimate business needs.
- ✓
Implement a data loss prevention (DLP) solution with device control and content inspection.
Why this is correct
DLP can block, log, and alert on unauthorized USB transfers.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.