NIST CSF Practice Question: Why should removable media be controlled as part of the Protect... | CyberCertPrep
NISTNIST CSFProtect FunctionEASYFree question
Why should removable media be controlled as part of the Protect function?
A.To save money on USB drives
B.Only government agencies need to control removable media
C.Removable media is never used in modern organizations
D.Removable media (USB drives, external hard drives) can introduce malware, enable data exfiltration, and bypass network security controls, requiring policies and technical controls to manage their use
Why D is correct
Removable media bypasses network-based protections and can introduce threats or enable data theft. Controls include encryption requirements, device whitelisting, and usage policies.
Know someone studying for NIST CSF? Send them this one.
Where this fits in the NIST CSF exam
Protect Function
NIST CSF Protect function: identity management, access control, awareness and training, data security, and protective technology.
This question belongs to the "Protect" domain, which makes up about 20% of the NIST CSF exam.
CyberCertPrep gives you 20 free NIST CSF questions per day with this same answer-and-explanation depth, plus timed exam simulations and progress tracking. No card required.
NIST CSF and NIST are trademarks or registered trademarks of their respective owners. CyberCertPrep is an independent exam-preparation resource and is not affiliated with, authorized by, sponsored by, or endorsed by NIST or any other certification body. All study material is independently created; the certification name is used only to identify the exam this resource helps you prepare for.