Skip to content
StudyDex
IT & Cybersecurity

Evelyn is a system administrator at her agency and wants to use a thumb drive — is her use acceptable?

Quick answer

Yes, her use is acceptable. Removable media such as a thumb drive may be used on a government system only when the device is Government-owned or Government-provided, its use is operationally necessary, and it is approved under agency policy. Evelyn's use meets all three conditions.

The answer

Evelyn's use of the thumb drive is acceptable because it satisfies the three conditions the DoD and federal cybersecurity policy require for removable media on a government system:

  1. It is Government-owned or Government-provided — not a personal or unknown device.
  2. It is operationally necessary — there is a legitimate work reason to use it.
  3. It is approved under her agency's policy and by the appropriate authority.

When all three are true, using removable media is permitted. The scenario is designed to test whether you recognize that removable media is not banned outright—it is restricted to a narrow, controlled set of circumstances. Because Evelyn is a system administrator acting within approved policy on a Government-provided device for a necessary task, her conduct is compliant.

Why the other options are wrong

The distractors in this Cyber Awareness question usually push you toward absolutist answers:

  • "Removable media is never allowed on government systems." Wrong. It is discouraged and heavily controlled, but Government-owned, approved, operationally necessary use is explicitly permitted.
  • "It's fine because she's an administrator." Wrong reasoning even if the outcome is 'acceptable'—privilege alone does not authorize it. The authorization comes from approval, ownership, and necessity, not from her job title.
  • "It's acceptable to use her personal USB drive since she is trusted." Wrong. Personal or unapproved devices are prohibited regardless of the user's trust level, because they bypass the controls that ensure the device is clean and accounted for.
  • "She may use any found or unlabeled drive if she scans it first." Wrong. Unknown media (especially found devices) must never be connected; they are a classic malware-delivery and 'baiting' vector.

The bigger picture

Removable media—thumb drives, external hard drives, SD cards, CDs—are a top cybersecurity risk because they can silently introduce malware (the infamous Stuxnet worm spread this way), enable data exfiltration, and evade network monitoring. This is why the DoD banned uncontrolled use after major incidents and now permits it only under strict conditions.

Before using any removable device, a system administrator should confirm: the device is Government-issued and inventoried, the use is documented and approved, the action is operationally necessary (no safer alternative like an approved network transfer), and the media is encrypted and scanned. If any of those fail, the correct action is to stop and not connect the device. Evelyn passes each check, so her use is authorized and correct.

Walk the decision
  1. 1

    Is the device Government-owned or Government-provided?

    If it is personal, found, or unknown media, STOP—do not connect it. Only Government-issued media may be considered.

  2. 2

    Is using it operationally necessary?

  3. 3

    Is the use approved under agency policy?

  4. 4

    Is the media encrypted and scanned for malware?

Frequently asked

When is it acceptable to use removable media on a government system?

Only when the media is Government-owned or Government-provided, its use is operationally necessary, and it has been approved under agency policy. Personal, found, or unapproved devices are never permitted, regardless of the user's role or intentions.

What is the DoD policy on thumb drives?

The DoD prohibits uncontrolled use of USB flash drives and other removable media after past malware incidents. Their use is allowed only with Government-issued, approved devices for operationally necessary tasks, and the media must typically be encrypted and scanned.

Why is removable media a cybersecurity risk?

Removable media can introduce malware directly onto a system, bypassing network defenses, and can be used to exfiltrate sensitive data. 'Baiting' attacks leave infected drives for victims to find and plug in, and lost drives can expose data if unencrypted.

What should a system administrator do before using a USB drive?

Confirm the drive is Government-issued and inventoried, verify the use is approved and operationally necessary, ensure it is encrypted, and scan it for malware before connecting. If any condition fails, do not use the device.

Start freeLog in