easyMultiple Choice
SSCP Practice Question: Implements a new security policy requiring all…
An organization implements a new security policy requiring all portable storage devices to be encrypted. Which of the following is the MOST effective control to enforce this policy?
⚠ Common exam trap
Many candidates confuse 'encrypting the system drive' (Option D) with 'encrypting removable drives,' or they assume auditing (Option C) is a preventive control rather than a detective one.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure Group Policy to require BitLocker encryption on removable drives.
Configuring Group Policy to require BitLocker encryption on removable drives is the most effective control because it enforces the encryption policy automatically and centrally across all domain-joined systems, preventing users from bypassing the requirement. Unlike a memo or auditing, Group Policy provides a technical enforcement mechanism that blocks unencrypted removable media from being used, ensuring compliance without relying on user discretion.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Distribute a memo to all employees about the policy.
Why it's wrong here
A memo communicates intent but enforces nothing; it cannot detect or block an unencrypted USB device being written to. It is tempting because awareness campaigns are legitimate administrative controls, and a memo would be the correct choice when the requirement is to announce a policy rather than technically enforce encryption.
- ✓
Configure Group Policy to require BitLocker encryption on removable drives.
Why this is correct
Group Policy's Removable Drive Encryption settings enforce BitLocker at the point of use, blocking write access to unencrypted devices and silently encrypting them on insertion. This satisfies the policy's requirement for mandatory encryption across all portable storage, rather than relying on user compliance or post-incident detection.
- ✗
Enable auditing for removable drive usage.
Why it's wrong here
Auditing only records removable drive usage after the fact; it does not prevent unencrypted devices from being connected. Auditing is tempting because it provides visibility and evidence, and would be correct for detecting policy violations rather than enforcing encryption.
- ✗
Enable BitLocker on all laptops.
Why it's wrong here
BitLocker encrypts fixed and removable volumes on Windows endpoints, but the policy targets portable storage devices generally, including USB drives used with non-Windows or unmanaged systems. It is tempting because full-disk encryption protects data at rest on laptops, which would be the right control for a laptop-encryption mandate.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.