easyMultiple ChoiceObjective-mapped
CISSP Practice Question: A company's security policy requires that all…
A company's security policy requires that all removable media be encrypted. An employee plugs in a USB drive and is prompted to format it before use. After formatting, the drive is not encrypted. What is the most likely reason?
⚠ Common exam trap
It's easy for candidates to assume formatting a drive automatically applies encryption (e.g., thinking BitLocker is enabled by default), when in fact encryption must be explicitly activated after formatting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The employee did not enable encryption (e.g., BitLocker To Go) after formatting
BitLocker To Go, the native encryption feature for removable drives in Windows, is not automatically enabled when a USB drive is formatted. The employee must explicitly enable encryption (e.g., via BitLocker To Go in Control Panel or by right-clicking the drive and selecting 'Turn on BitLocker') after formatting. Without this step, the drive remains unencrypted, violating the security policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The employee did not enable encryption (e.g., BitLocker To Go) after formatting
Why this is correct
Formatting a removable drive prepares it for data storage by creating a file system, but this process does not automatically encrypt the data written to it. Encryption, such as using Windows' BitLocker To Go, is a distinct security measure that must be explicitly enabled by the user after formatting. This separate step involves generating and managing cryptographic keys to protect the data at rest, ensuring confidentiality even if the physical device is compromised.
- ✗
The USB drive hardware does not support encryption
Why it's wrong here
The absence of hardware-based encryption support on a USB drive does not preclude the use of encryption. Software-based encryption solutions, like BitLocker or VeraCrypt, operate independently of the drive's internal hardware capabilities. These solutions encrypt data at the operating system level before it is written to the storage device, providing robust data protection regardless of whether the USB drive itself has a dedicated encryption chip.
- ✗
The operating system does not support encryption of removable media
Why it's wrong here
Most contemporary operating systems offer native and robust support for encrypting removable media. For instance, Windows includes BitLocker To Go, macOS provides FileVault for external drives, and Linux distributions commonly utilize LUKS (Linux Unified Key Setup). These integrated features allow users to easily secure their portable data, making the claim that the OS lacks support generally incorrect for modern environments.
- ✗
The employee used the wrong file system (FAT32 vs NTFS)
Why it's wrong here
The choice of file system, such as FAT32 or NTFS, dictates how data is organized, stored, and retrieved on a storage device, along with features like file size limits and permissions. However, file systems themselves do not provide cryptographic encryption of the data content. Encryption is a separate security layer applied on top of the file system to protect the confidentiality of the information, regardless of the underlying file system structure.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Security policy
A security policy is a formal set of rules and guidelines that an organization establishes to protect its information assets and technology resources.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.