Courseiva
mediumMultiple Select

CISSP Practice Question: Which THREE of the following are valid methods to…

Which THREE of the following are valid methods to reduce the risk of data exfiltration via removable media in a high-security environment?

⚠ Common exam trap

Test-takers frequently confuse full disk encryption (a data-at-rest protection) with a data exfiltration prevention control, failing to recognize that encryption does not block the copy operation itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Disable USB ports via group policy and physically lock cases

Option A is correct because disabling USB mass-storage via Group Policy (e.g., the 'All Removable Storage classes: Deny all access' setting under Computer Configuration\Administrative Templates\System\Removable Storage Access) blocks the technical channel for copying data, and physically locking cases prevents an attacker or insider from bypassing the control by attaching drives to internal ports. Option D is correct because endpoint DLP agents inspect file content and context (e.g., regex/EDM fingerprints for PII, PCI, or classified markings) and enforce block or audit rules specifically on write/copy operations to removable media, which directly mitigates exfiltration even when ports remain enabled for legitimate use. Option E is correct because data classification and labeling (e.g., Public/Internal/Confidential/Secret tags) establishes handling rules that DLP and access controls can enforce, and it raises user awareness so staff recognize which data must never leave on removable media. Option B is not among the marked answers because annual training alone is a weak, periodic awareness measure that does not technically prevent or block exfiltration. Option C is not among the marked answers because full disk encryption protects data at rest on a lost or stolen endpoint; it does not stop an authorized user from copying plaintext files onto a removable drive.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Disable USB ports via group policy and physically lock cases

    Why this is correct

    Disabling USB ports via Group Policy establishes a robust logical control, preventing unauthorized mounting of removable storage devices across an organization's endpoints. Concurrently, physically locking computer cases adds a crucial physical security layer, thwarting attempts to bypass software controls or access internal ports for data transfer. This dual-layered approach effectively eliminates the primary vector for data exfiltration using portable media, making it a highly enforceable preventative measure.

  • ✗

    Require annual security awareness training on data handling

    Why it's wrong here

    While essential for fostering a security-conscious culture, annual security awareness training primarily educates users on best practices and policies regarding data handling. It does not, however, implement technical controls that physically or logically prevent a user, whether malicious or accidental, from copying sensitive data to removable media. Training alone relies on human adherence and cannot automatically block exfiltration attempts, making it insufficient as a sole preventative measure.

  • ✗

    Use full disk encryption on all endpoints

    Why it's wrong here

    Full disk encryption (FDE) primarily protects data at rest by rendering the entire storage device unreadable without the correct decryption key, safeguarding information if a device is lost or stolen. Its purpose is to prevent unauthorized access to the stored data when the system is powered off or compromised externally. However, FDE does not prevent an authorized user from actively copying decrypted data from the live operating system to an unencrypted removable storage device, as the data is accessible once the system is logged in.

  • ✓

    Deploy endpoint DLP agents that block copy operations to removable media based on content

    Why this is correct

    Deploying endpoint Data Loss Prevention (DLP) agents provides a proactive and automated technical control against data exfiltration. These agents continuously monitor data flows, inspecting content against predefined policies and classification tags to identify sensitive information in real-time. Upon detection, DLP can automatically block copy operations to removable media, preventing unauthorized transfers based on the data's sensitivity and organizational rules.

  • ✓

    Implement data classification and labeling policies to raise awareness

    Why this is correct

    Implementing comprehensive data classification and labeling policies is a foundational administrative control that empowers users to understand the sensitivity of information they handle. By clearly marking data, these policies raise awareness and guide employees in handling sensitive assets appropriately, reducing accidental exfiltration. While not a technical enforcement mechanism, it fosters a culture of responsible data stewardship, making users more likely to avoid unauthorized copying to removable media.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.