nerdexam
CompTIA

SY0-301 · Question #761

The marketing department wants to distribute pens with embedded USB drives to clients. In the past this client has been victimized by social engineering attacks which led to a loss of sensitive…

The correct answer is A. The risks associated with the large capacity of USB drives and their concealable nature. Branded USB drives given to external clients pose a significant security risk because their large storage capacity and small, easily concealed form factor make them ideal for unintentional or intentional data exfiltration and malware introduction.

Threats, vulnerabilities, and mitigations

Question

The marketing department wants to distribute pens with embedded USB drives to clients. In the past this client has been victimized by social engineering attacks which led to a loss of sensitive data. The security administrator advises the marketing department not to distribute the USB pens due to which of the following?

Options

  • AThe risks associated with the large capacity of USB drives and their concealable nature
  • BThe security costs associated with securing the USB drives over time
  • CThe cost associated with distributing a large volume of the USB pens
  • DThe security risks associated with combining USB drives and cell phones on a network

How the community answered

(23 responses)
  • A
    74% (17)
  • B
    4% (1)
  • C
    4% (1)
  • D
    17% (4)

Why each option

Branded USB drives given to external clients pose a significant security risk because their large storage capacity and small, easily concealed form factor make them ideal for unintentional or intentional data exfiltration and malware introduction.

AThe risks associated with the large capacity of USB drives and their concealable natureCorrect

USB drives can carry malware that auto-executes when plugged in, and can be used to copy and remove large volumes of sensitive data from an organization's systems. The concealable nature of USB drives means that clients or malicious insiders can use them to exfiltrate data without detection, which is especially concerning given this client's history of social engineering attacks that resulted in data loss. Distributing them widely increases the attack surface considerably.

BThe security costs associated with securing the USB drives over time

The ongoing security costs of managing distributed USB drives are a minor operational consideration compared to the primary concern, which is the direct security risk they pose as data exfiltration or malware delivery vectors.

CThe cost associated with distributing a large volume of the USB pens

The financial cost of producing and distributing the USB pens is a marketing budget concern, not a security risk, and would not be a basis for a security administrator's advice.

DThe security risks associated with combining USB drives and cell phones on a network

Combining USB drives with cell phones on a network is not a recognized specific security threat; the actual risk is the standalone capability of USB drives to carry malware or exfiltrate data regardless of cell phone presence.

Concept tested: USB drive data exfiltration and physical security risk

Source: https://csrc.nist.gov/publications/detail/sp/800-114/rev-1/final

Topics

#USB security#social engineering#data exfiltration#removable media

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice