Certified in Risk and Information Systems Control (CRISC) — Question 187
Which of the following scenarios represents a threat?
Answer options
- A. Storing corporate data in unencrypted form on a laptop
- B. Visitors not signing in as per policy
- C. A virus transmitted on a USB thumb drive
- D. Connecting a laptop to a free, open, wireless access point (hotspot)
Correct answer: C
Explanation
The correct answer is C, as a virus on a USB thumb drive can directly infect systems and compromise security. While A and D also represent risks, they do not involve direct transmission of malware like option C. Option B, although a security concern, does not pose an immediate threat to data integrity or system security.