ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 349 - SY0-601 discussion

Report
Export

A company is focused on reducing risks from removable media threats. Due to certain primary applications, removable media cannot be entirely prohibited at this time. Which of the following best describes the company's approach?

A.
Compensating controls
Answers
A.
Compensating controls
B.
Directive control
Answers
B.
Directive control
C.
Mitigating controls
Answers
C.
Mitigating controls
D.
Physical security controls
Answers
D.
Physical security controls
Suggested answer: C

Explanation:

Mitigating controls are designed to reduce the impact or severity of an event that has occurred or is likely to occur. They do not prevent or detect the event, but rather limit the damage or consequences of it. For example, a backup system is a mitigating control that can help restore data after a loss or corruption.

In this case, the company is focused on reducing risks from removable media threats, which are threats that can compromise data security, introduce malware infections, or cause media failure123. Removable media threats can be used to bypass network defenses and target industrial/OT environments2. The company cannot prohibit removable media entirely because of certain primary applications that require them, so it implements mitigating controls to lessen the potential harm from these threats.

Some examples of mitigating controls for removable media threats are:

Encrypting data on removable media

Scanning removable media for malware before use

Restricting access to removable media ports

Implementing policies and procedures for removable media usage and disposal Educating users on the risks and best practices of removable media

asked 02/10/2024
Joshin Ogele
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first