Courseiva
mediumMultiple Choice

CISA Practice Question: Is the MOST effective control to prevent…

Which of the following is the MOST effective control to prevent unauthorized USB devices from connecting to corporate workstations?

⚠ Common exam trap

Test-takers frequently confuse encryption (which protects data confidentiality) with access control (which prevents connection), or overestimate the effectiveness of training and physical security against a technical bypass like USB autorun or BadUSB.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Device control software that blocks non-approved USB devices.

Device control software (e.g., endpoint DLP or USB whitelisting tools) operates at the OS kernel or driver level to enforce a hardware ID or vendor ID allowlist, blocking any USB device not explicitly approved. This is the only option that provides a preventive, automated, and continuous control against unauthorized USB connections, regardless of user behavior or physical access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Device control software that blocks non-approved USB devices.

    Why this is correct

    Device control software enforces an allow-list at the endpoint, blocking non-approved USB devices by class or serial before they mount. This directly satisfies the stem's prevention requirement, unlike policy or awareness measures that cannot technically stop a device connecting.

  • ✗

    User awareness training.

    Why it's wrong here

    Awareness training changes user behaviour but cannot block a device: it relies on voluntary compliance and fails against malicious or careless insiders. Tempting because training is a genuine administrative control within a defence-in-depth programme, yet endpoint port control or device-control policy enforces the restriction technically.

  • ✗

    Physical security guards.

    Why it's wrong here

    Guards control physical access to premises, not individual workstation ports; a visitor or employee with legitimate building access can still plug in a USB device unobserved. Tempting because physical security is a real control layer, but it does not enforce per-port device authorisation on each workstation.

  • ✗

    Encrypting all USB devices.

    Why it's wrong here

    Encrypting USB devices protects data confidentiality if a device is lost; it does nothing to stop an unauthorised device from connecting and reading or writing data. Tempting because encryption is a recognised endpoint control, but the requirement is blocking connection, which needs port or device control.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.