nerdexam
CompTIA

220-1002 · Question #469

After a virus outbreak due to USB usage, a technician must deny users access to removable hard drives via USB ports as soon as possible. The technician has been asked to avoid interrupting any…

The correct answer is B. Assign a local security policy. A local security policy applied directly on a machine takes effect immediately (or after a quick gpupdate) without requiring a system reboot, minimizing user disruption. It can block access to removable storage devices by configuring the 'Removable Disks: Deny read/write…

Hardware and network troubleshooting

Question

After a virus outbreak due to USB usage, a technician must deny users access to removable hard drives via USB ports as soon as possible. The technician has been asked to avoid interrupting any users. Which of the following is the BEST way for the technician to perform this security feature?

Options

  • APush a group policy.
  • BAssign a local security policy.
  • CCreate a network login script.
  • DUpdate the AUP

How the community answered

(40 responses)
  • A
    5% (2)
  • B
    73% (29)
  • C
    8% (3)
  • D
    15% (6)

Explanation

A local security policy applied directly on a machine takes effect immediately (or after a quick gpupdate) without requiring a system reboot, minimizing user disruption. It can block access to removable storage devices by configuring the 'Removable Disks: Deny read/write access' policy under Computer Configuration. A group policy push (A) is more appropriate for enterprise-wide deployment across a domain but involves propagation delays and may require a reboot or policy refresh cycle. A network login script (C) runs at logon and would not be effective until the next login session. Updating the Acceptable Use Policy (D) is an administrative/HR measure and has no technical enforcement effect.

Topics

#USB restriction#local security policy#group policy#endpoint control

Community Discussion

No community discussion yet for this question.

Full 220-1002 Practice