nerdexam
(ISC)2

CISSP · Question #850

Which of the following is the MOST effective method of mitigating data theft from an active user workstation?

The correct answer is D. Disable use of portable devices. Data Theft from Active Workstations Disabling portable devices (USB drives, external hard drives, etc.) directly prevents the most common physical exfiltration method from a currently logged-in, active workstation - where the user session is already authenticated and data is…

Submitted by kwame.gh· Mar 5, 2026Asset Security

Question

Which of the following is the MOST effective method of mitigating data theft from an active user workstation?

Options

  • AImplement full-disk encryption
  • BEnable multifactor authentication
  • CDeploy file integrity checkers
  • DDisable use of portable devices

How the community answered

(35 responses)
  • A
    6% (2)
  • B
    14% (5)
  • C
    3% (1)
  • D
    77% (27)

Explanation

Data Theft from Active Workstations

Disabling portable devices (USB drives, external hard drives, etc.) directly prevents the most common physical exfiltration method from a currently logged-in, active workstation - where the user session is already authenticated and data is accessible. Since the workstation is active, the primary threat is someone physically copying data out, making port/device control the most targeted countermeasure.

Why the distractors fall short:

  • A (Full-disk encryption) protects data when the device is off or stolen, but offers no protection while the system is actively running and the drive is already decrypted.
  • B (Multifactor authentication) strengthens login security but does nothing once a user is already authenticated and working - the session is already open.
  • C (File integrity checkers) detect unauthorized changes to files, not copying or exfiltration of data to external devices.

Memory Tip: Think of the word "active" as your key - the system is already unlocked, so encryption and authentication are bypassed. The only remaining door to close is the physical exit route for data, which is the portable device port. "Active = already in, so block the exits."

Topics

#Data Exfiltration#Device Control#Endpoint Security#Data Loss Prevention

Community Discussion

No community discussion yet for this question.

Full CISSP Practice