SY0-301 · Question #761
The marketing department wants to distribute pens with embedded USB drives to clients. In the past this client has been victimized by social engineering attacks which led to a loss of sensitive…
The correct answer is A. The risks associated with the large capacity of USB drives and their concealable nature. Branded USB drives given to external clients pose a significant security risk because their large storage capacity and small, easily concealed form factor make them ideal for unintentional or intentional data exfiltration and malware introduction.
Question
The marketing department wants to distribute pens with embedded USB drives to clients. In the past this client has been victimized by social engineering attacks which led to a loss of sensitive data. The security administrator advises the marketing department not to distribute the USB pens due to which of the following?
Options
- AThe risks associated with the large capacity of USB drives and their concealable nature
- BThe security costs associated with securing the USB drives over time
- CThe cost associated with distributing a large volume of the USB pens
- DThe security risks associated with combining USB drives and cell phones on a network
How the community answered
(23 responses)- A74% (17)
- B4% (1)
- C4% (1)
- D17% (4)
Why each option
Branded USB drives given to external clients pose a significant security risk because their large storage capacity and small, easily concealed form factor make them ideal for unintentional or intentional data exfiltration and malware introduction.
USB drives can carry malware that auto-executes when plugged in, and can be used to copy and remove large volumes of sensitive data from an organization's systems. The concealable nature of USB drives means that clients or malicious insiders can use them to exfiltrate data without detection, which is especially concerning given this client's history of social engineering attacks that resulted in data loss. Distributing them widely increases the attack surface considerably.
The ongoing security costs of managing distributed USB drives are a minor operational consideration compared to the primary concern, which is the direct security risk they pose as data exfiltration or malware delivery vectors.
The financial cost of producing and distributing the USB pens is a marketing budget concern, not a security risk, and would not be a basis for a security administrator's advice.
Combining USB drives with cell phones on a network is not a recognized specific security threat; the actual risk is the standalone capability of USB drives to carry malware or exfiltrate data regardless of cell phone presence.
Concept tested: USB drive data exfiltration and physical security risk
Source: https://csrc.nist.gov/publications/detail/sp/800-114/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.