Question

Difficulty: MediumData Security and Threats in Accounting Systems

A company's accounting department experienced a system compromise when an infected external flash drive was physically connected to a local database workstation. Which of the following internal control measures is most effective in preventing this specific type of security threat?

  1. Disabling external USB hardware ports and enforcing endpoint security policiesAnswer
  2. B
    Installing network firewalls to filter incoming remote traffic
  3. C
    Scheduling automated daily offsite backups of accounting records
  4. D
    Converting batch data processing to real-time online processing

Answer

Disabling external USB hardware ports and enforcing endpoint security policies
Disabling physical USB ports and restricting endpoint devices directly blocks external media from executing malicious scripts locally on accounting workstations.

Step-by-Step Solution

1
Identify the nature of the security threat described in the scenario.
The threat vector is physical intrusion via local external storage media (USB flash drive).
Control measures must target the specific vector of attack to be effective.
2
Evaluate the listed internal control mechanisms against physical hardware vectors.
Restricting physical ports and enforcing endpoint device management prevents execution of unauthorized external software.
Network firewalls, file backups, and transaction processing modes address network traffic, data recovery, and transaction execution timing respectively, rather than local media entry.

Key Concept

Physical and Endpoint Access Security in Computerized Accounting Systems
Rate this question