Courseiva
hardMultiple ChoiceObjective-mapped

CAS-004 Practice Question: Needs to design a solution to detect and respond…

A security engineer needs to design a solution to detect and respond to insider threats involving unauthorized data exfiltration via USB devices. Which of the following is the MOST effective approach?

⚠ Common exam trap

A common mix-up: candidates choose EDR (Option B) because they associate it with endpoint security, but EDR is designed for threat detection (e.g., malware, lateral movement), not for granular data exfiltration control via USB, which requires DLP's content-aware inspection and device control capabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Implement a data loss prevention (DLP) solution with device control and content inspection.

The most effective because a DLP solution with device control and content inspection can monitor, block, or alert on unauthorized data transfers to USB devices by inspecting the content being written (e.g., file types, keywords, patterns) and enforcing policies at the endpoint or network level. This directly addresses the specific threat of data exfiltration via USB, unlike other options that either lack detection or are too restrictive.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Conduct regular security awareness training on data handling policies.

    Why it's wrong here

    Training is important but does not provide technical enforcement.

  • Deploy endpoint detection and response (EDR) agents on all workstations.

    Why it's wrong here

    EDR is reactive and may not prevent exfiltration.

  • Disable all USB ports via group policy.

    Why it's wrong here

    Disabling USB ports entirely may hinder legitimate business needs.

  • Implement a data loss prevention (DLP) solution with device control and content inspection.

    Why this is correct

    DLP can block, log, and alert on unauthorized USB transfers.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.