nerdexam
CompTIA

SK0-004 · Question #226

A company has recently had sensitive data stolen by a contractor who plugged a flash drive into a server. Which of the following is the BEST method to prevent future occurrences?

The correct answer is A. Disable any unused physical ports until needed. Physically disabling unused USB and other ports at the hardware or OS level is the most effective technical control to prevent unauthorized removable media from being connected to a server.

Security and disaster recovery

Question

A company has recently had sensitive data stolen by a contractor who plugged a flash drive into a server. Which of the following is the BEST method to prevent future occurrences?

Options

  • ADisable any unused physical ports until needed
  • BImplement a BIOS password on all the servers
  • CInstall chassis locks on all the servers
  • DRestrict usage of flash drives in company policy

How the community answered

(61 responses)
  • A
    95% (58)
  • C
    3% (2)
  • D
    2% (1)

Why each option

Physically disabling unused USB and other ports at the hardware or OS level is the most effective technical control to prevent unauthorized removable media from being connected to a server.

ADisable any unused physical ports until neededCorrect

Disabling unused physical ports - either in the BIOS/UEFI, via OS-level port management, or with hardware port blockers - provides a technical enforcement control that makes it physically impossible to connect an unauthorized flash drive. This addresses the specific attack vector (physical USB access) directly and cannot be bypassed by a contractor without visible tampering, unlike policy-only controls.

BImplement a BIOS password on all the servers

A BIOS password restricts boot configuration changes but does not disable USB ports during normal system operation, so a flash drive can still be used after the system boots.

CInstall chassis locks on all the servers

Chassis locks prevent access to internal components such as expansion cards and drives, but do not block external-facing USB ports that remain accessible on the server's exterior.

DRestrict usage of flash drives in company policy

A policy-based restriction relies on user compliance and has no technical enforcement mechanism - the same contractor behavior that already occurred can still occur, just in violation of a written policy.

Concept tested: Physical port security to prevent unauthorized removable media

Source: https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final

Topics

#physical security#USB port lockdown#data theft prevention

Community Discussion

No community discussion yet for this question.

Full SK0-004 Practice