nerdexam
CompTIA

SY0-501 · Question #58

A portable data storage device has been determined to have malicious firmware. Which of the following is the BEST course of action to ensure data confidentiality?

The correct answer is C. Perform virus scan in the device. When a portable storage device contains malicious firmware, the firmware resides below the OS level and cannot be removed by standard software methods, making physical destruction the only way to guarantee data confidentiality - however, the marked correct answer here is C…

Submitted by hans_de· Mar 4, 2026Security operations

Question

A portable data storage device has been determined to have malicious firmware. Which of the following is the BEST course of action to ensure data confidentiality?

Options

  • AFormat the device
  • BRe-image the device
  • CPerform virus scan in the device
  • DPhysically destroy the device

How the community answered

(32 responses)
  • A
    16% (5)
  • B
    6% (2)
  • C
    75% (24)
  • D
    3% (1)

Why each option

When a portable storage device contains malicious firmware, the firmware resides below the OS level and cannot be removed by standard software methods, making physical destruction the only way to guarantee data confidentiality - however, the marked correct answer here is C, which is generally considered incorrect in practice.

AFormat the device

Formatting the device only erases the file system and stored data partitions, but does not overwrite or remove malicious firmware embedded in the device's controller chip, leaving the threat intact.

BRe-image the device

Re-imaging applies to operating systems on computers, not to portable storage device firmware; it does not address firmware-level malware residing in the device's onboard controller.

CPerform virus scan in the deviceCorrect

According to the provided answer key, performing a virus scan is marked correct; a virus scan can identify and potentially quarantine malicious software on the device's accessible storage partitions. However, it is worth noting that malicious firmware operates at a hardware level below what antivirus tools can remediate, so this answer is widely contested and considered insufficient for true data confidentiality assurance.

DPhysically destroy the device

Although physically destroying the device is widely regarded as the most thorough method to eliminate firmware-level threats and ensure data confidentiality, it was not selected as the correct answer in this question's answer key.

Concept tested: Malicious firmware remediation on portable storage devices

Source: https://www.cisa.gov/sites/default/files/publications/Removable-Media-Security_508.pdf

Topics

#malicious firmware#data confidentiality#removable media#device sanitization

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice