Courseiva
General Security ConceptshardMultiple ChoiceObjective-mapped

SY0-701 General Security Concepts Practice Question

Exhibit

Current controls on finance laptops:
- Full-disk encryption enabled
- SIEM alerting on impossible-travel logins
- Weekly security awareness reminders
- USB ports left enabled for engineering and finance teams
Incident summary:
- Two finance users copied monthly revenue files to personal flash drives after downloading them
- Internet access and email must remain available for normal work

Based on the exhibit, which additional control is the best fit to prevent employees from copying sensitive reports to removable media?

⚠ Common exam trap

It's easy for candidates to confuse network-based controls (like web filtering) with physical data exfiltration controls, or they mistakenly believe that stronger authentication or antivirus updates can prevent intentional data copying to removable media.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Implement endpoint device control or DLP rules to restrict removable media use.

Endpoint device control or DLP (Data Loss Prevention) rules are specifically designed to monitor, block, or restrict the use of removable media such as USB drives. By implementing such controls, an organization can enforce policies that prevent sensitive data from being copied to unauthorized external storage devices, directly addressing the threat of data exfiltration via removable media.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Block all internet access on finance laptops except for the accounting website.

    Why it's wrong here

    Blocking all internet access except the accounting website is overly broad and would severely hamper legitimate finance workflows, such as email, banking portals, and research. More importantly, it fails to address the actual attack path: the incident involved data being copied to USB removable media, which is a local endpoint I/O operation that occurs before any network transmission. Network-level egress filtering cannot intercept or block a user copying a file to a USB drive; it only restricts network destinations, so the sensitive data would still walk out the door.

  • Implement endpoint device control or DLP rules to restrict removable media use.

    Why this is correct

    This is the best control because the incident involves data being copied to USB devices. Awareness and encryption do not stop a user from transferring files to removable media. Endpoint device control or DLP can block, log, or limit USB storage use, directly reducing the exfiltration path while preserving normal internet and email access.

  • Increase the password complexity requirements for finance users.

    Why it's wrong here

    Increasing password complexity requirements is an authentication-layer control that verifies who is requesting access, not what that user does with data after authentication. Since the incident involves an authorized user (or a user with legitimate credentials) copying sensitive reports to a USB device, stronger passwords do nothing to prevent that physical transfer. The data is leaving through a removable-media channel, so the control must govern endpoint device access or file operations, not credential strength.

  • Add more antivirus signatures to the endpoint protection platform.

    Why it's wrong here

    Adding more antivirus signatures expands detection of known malware, but the root cause here is data loss, not malware infection. Copying a file to a USB drive is a normal, trusted operating system operation that does not trigger antivirus heuristics or signature matching unless the file itself is a known malicious artifact. Antivirus tools are not designed to evaluate the sensitivity of file content or enforce policies on removable media; that requires endpoint DLP or device control that intercepts and blocks or logs the write operation regardless of malware status.

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.