mediumMultiple Select
CISSP Practice Question: Which THREE of the following are valid methods to…
Which THREE of the following are valid methods to reduce the risk of data exfiltration via removable media in a high-security environment?
⚠ Common exam trap
Test-takers frequently confuse full disk encryption (a data-at-rest protection) with a data exfiltration prevention control, failing to recognize that encryption does not block the copy operation itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disable USB ports via group policy and physically lock cases
Option A is correct because disabling USB mass-storage via Group Policy (e.g., the 'All Removable Storage classes: Deny all access' setting under Computer Configuration\Administrative Templates\System\Removable Storage Access) blocks the technical channel for copying data, and physically locking cases prevents an attacker or insider from bypassing the control by attaching drives to internal ports. Option D is correct because endpoint DLP agents inspect file content and context (e.g., regex/EDM fingerprints for PII, PCI, or classified markings) and enforce block or audit rules specifically on write/copy operations to removable media, which directly mitigates exfiltration even when ports remain enabled for legitimate use. Option E is correct because data classification and labeling (e.g., Public/Internal/Confidential/Secret tags) establishes handling rules that DLP and access controls can enforce, and it raises user awareness so staff recognize which data must never leave on removable media. Option B is not among the marked answers because annual training alone is a weak, periodic awareness measure that does not technically prevent or block exfiltration. Option C is not among the marked answers because full disk encryption protects data at rest on a lost or stolen endpoint; it does not stop an authorized user from copying plaintext files onto a removable drive.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Disable USB ports via group policy and physically lock cases
Why this is correct
Disabling USB ports via Group Policy establishes a robust logical control, preventing unauthorized mounting of removable storage devices across an organization's endpoints. Concurrently, physically locking computer cases adds a crucial physical security layer, thwarting attempts to bypass software controls or access internal ports for data transfer. This dual-layered approach effectively eliminates the primary vector for data exfiltration using portable media, making it a highly enforceable preventative measure.
- ✗
Require annual security awareness training on data handling
Why it's wrong here
While essential for fostering a security-conscious culture, annual security awareness training primarily educates users on best practices and policies regarding data handling. It does not, however, implement technical controls that physically or logically prevent a user, whether malicious or accidental, from copying sensitive data to removable media. Training alone relies on human adherence and cannot automatically block exfiltration attempts, making it insufficient as a sole preventative measure.
- ✗
Use full disk encryption on all endpoints
Why it's wrong here
Full disk encryption (FDE) primarily protects data at rest by rendering the entire storage device unreadable without the correct decryption key, safeguarding information if a device is lost or stolen. Its purpose is to prevent unauthorized access to the stored data when the system is powered off or compromised externally. However, FDE does not prevent an authorized user from actively copying decrypted data from the live operating system to an unencrypted removable storage device, as the data is accessible once the system is logged in.
- ✓
Deploy endpoint DLP agents that block copy operations to removable media based on content
Why this is correct
Deploying endpoint Data Loss Prevention (DLP) agents provides a proactive and automated technical control against data exfiltration. These agents continuously monitor data flows, inspecting content against predefined policies and classification tags to identify sensitive information in real-time. Upon detection, DLP can automatically block copy operations to removable media, preventing unauthorized transfers based on the data's sensitivity and organizational rules.
- ✓
Implement data classification and labeling policies to raise awareness
Why this is correct
Implementing comprehensive data classification and labeling policies is a foundational administrative control that empowers users to understand the sensitivity of information they handle. By clearly marking data, these policies raise awareness and guide employees in handling sensitive assets appropriately, reducing accidental exfiltration. While not a technical enforcement mechanism, it fosters a culture of responsible data stewardship, making users more likely to avoid unauthorized copying to removable media.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
Learn chapter
Access Control Models and Mechanisms
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
Disk encryption
Disk encryption is the process of converting data on a storage device into a coded form that can only be read with the correct decryption key, protecting it from unauthorized access.
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.