A company has drafted an insider-threat policy that prohibits the use of external storage devices.
Which of the following would BEST protect the company from data exfiltration via removable media?
A.
Monitoring large data transfer transactions in the firewall logs B.
Developing mandatory training to educate employees about the removable media policy C.
Implementing a group policy to block user access to system files D.
Blocking removable-media devices and write capabilities using a host-based security tool.
D.
A company has drafted an insider-threat policy that prohibits the use of external storage devices.
Which of the following would BEST protect the company from data exfiltration via removable media?
A.
Monitoring large data transfer transactions in the firewall logs
B.
Developing mandatory training to educate employees about the removable media policy
C.
Implementing a group policy to block user access to system files
D.
Blocking removable-media devices and write capabilities using a host-based security tool.
D.
The company's insider-threat policy prohibits the use of external storage devices to protect against data exfiltration. The best way to enforce this policy is to implement a solution that blocks removable-media devices and write capabilities. Option D, "Blocking removable-media devices and write capabilities using a host-based security tool," is the correct answer.
Option A, "Monitoring large data transfer transactions in the firewall logs," may help detect data exfiltration, but it does not prevent the use of removable media to transfer data. Additionally, it may not be a reliable method, as some data exfiltration may occur in small amounts over a long period of time.
Option B, "Developing mandatory training to educate employees about the removable media policy," is important, but it is not sufficient to prevent data exfiltration via removable media. Employees may still make mistakes or intentionally violate the policy.
Option C, "Implementing a group policy to block user access to system files," may prevent users from accessing system files, but it does not prevent them from using removable media to exfiltrate data.
Therefore, the best solution to prevent data exfiltration via removable media is to block the use of removable-media devices and write capabilities using a host-based security tool. This solution ensures that employees cannot transfer sensitive data using external storage devices, and provides a robust layer of protection against insider threats.