An IT support technician is deploying a shared workstation in a financial service firm's reception area. To protect sensitive client financial records from unauthorized exfiltration, company policy requires that standard users be restricted from reading or writing data to external flash drives, while essential USB peripherals such as keyboards and mice remain fully functional. Which of the following is the most effective workstation hardening action to fulfill this requirement?
- Configure Removable Storage Access policies in the Local Group Policy Editor to deny access to removable disks.Answer
- BDisable the main USB Root Hub device within Device Manager.
- CDisable the default local Guest account and enforce account lockout thresholds.
- DConfigure Task Scheduler to terminate the Windows File Explorer process when a new volume is detected.
Answer
Configure Removable Storage Access policies in the Local Group Policy Editor to deny access to removable disks.
Configuring Removable Storage Access policies in the Local Group Policy Editor allows administrators to block read and write permissions specifically for USB flash drives and external disks while permitting USB Human Interface Devices (such as keyboards and mice) to operate normally.
Step-by-Step Solution
Key Concept
Removable Storage Restriction via Local Group Policy
Estimated Time:1m 15s