ISC2 CC Security Operations Practice Question
A security awareness trainer is developing material on USB drop attacks. Which TWO messages should be included in the training? (Choose two.)
⚠ Common exam trap
CC often tests the misconception that scanning or formatting a found USB drive makes it safe; candidates may choose these options because they seem like reasonable precautions, but the only safe action is to not plug it in and report it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Never plug in a USB drive that you found lying around.
Option B is correct because the core defense against USB drop attacks (such as BadUSB or HID-spoofing devices that emulate keyboards) is simply never inserting an unknown drive into any system, since malicious firmware can execute before any OS-level controls apply. Option D is correct because reporting found drives to the security team allows them to be safely collected and analyzed as potential threat indicators, and it removes the drive from the environment so others are not tempted to plug it in. Options A, C, and E do not belong: using the drive on a non-networked computer still exposes that host to malicious firmware or autorun payloads, antivirus scanning cannot detect firmware-level or HID-emulation attacks and may itself trigger the payload, and formatting a drive does not neutralize malicious controller firmware and requires plugging it in first.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the USB drive only on a non-networked computer.
Why it's wrong here
A non-networked computer still executes malicious firmware or autorun payloads, and the drive can later be moved to a networked host. Air-gapping suits malware analysis labs, not everyday users; the correct message is never to plug in found drives.
- ✓
Never plug in a USB drive that you found lying around.
Why this is correct
Refusing to plug in found drives removes the attack vector entirely, since the malicious payload executes only on connection. This satisfies the stem's training-message requirement by targeting the physical action the USB drop attack depends upon, before any autorun or HID emulation can trigger.
- ✗
Always scan a found USB drive with antivirus before using.
Why it's wrong here
Scanning a found drive still requires plugging it into a machine, where firmware or zero-day payloads can execute before antivirus reacts. Scanning suits known malware on trusted media; the correct message is never plug in unknown drives.
- ✓
Report any discovered USB drives to the security team.
Why this is correct
Reporting found drives to the security team lets specialists analyse and neutralise the device safely, and warns colleagues if a campaign is underway. This satisfies the stem's training-message requirement by giving staff a concrete, safe action instead of handling the hardware themselves.
- ✗
Format the USB drive before using it.
Why it's wrong here
Formatting does not neutralise hardware-level attacks such as BadUSB, which reflash firmware and present as a keyboard before any format occurs. Formatting is tempting because it removes files, but the correct guidance is to hand found drives to security.
Go deeper
Related to this question
Learn chapter
Security Awareness and Training
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
Key term
Security awareness
Security awareness is the ongoing practice of educating people within an organization about cybersecurity risks, safe behaviors, and their individual responsibilities to protect information assets.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.