Skip to content
StudyDex
IT & Cybersecurity

Which of the following is true of removable media and portable electronic devices (PEDs)?

Quick answer

The same rules and protections apply to both, and both pose real risks such as malicious code and data spillage. Use only organization-owned, authorized media, never personal devices, and follow any organizational restrictions or prohibitions on their use.

The answer

The true statement is that the same rules and protections apply to removable media and portable electronic devices (PEDs), and both carry real security risks. In practice this means: use only organization-owned and authorized media, never connect personal USB drives or personal devices to government or work systems, and comply with any policy that restricts or prohibits their use.

Removable media (USB flash drives, external hard drives, SD cards, CDs/DVDs) and PEDs (smartphones, tablets, wearables, portable storage) are grouped together in cyber-awareness guidance precisely because they share the same weaknesses: they are small, easily lost, easily infected, and easily used to move large amounts of data quickly.

Why this is true

Two dominant risks drive the rules:

  1. Malicious code. An unknown USB drive can carry malware that executes the moment it is connected. This is a classic attack vector: attackers deliberately leave infected drives for curious people to plug in.
  2. Data spillage / loss. These devices can copy sensitive information off a network and then be lost, stolen, or taken home, exposing classified or protected data. Because they are portable, a single misplaced drive can be a major breach.

Because the threats are identical in nature, the protections are identical too: authorization, encryption, scanning, and strict limits on personal devices. That is why the correct answer treats them as one category with one rule set.

Why the other options are wrong

  • "You can use your personal USB drive as long as you scan it": false, personal media is not authorized on government/organizational systems; scanning does not make it permitted.
  • "Removable media pose no risk if the files look normal": false, malicious code can hide in ordinary-looking files and autorun on connection.
  • "PEDs and removable media follow different, unrelated rules": false, they are governed by the same protections and policies.
  • "Organizations cannot restrict removable media": false, organizations may restrict or fully prohibit their use, and many do.

The bigger picture

The safe-handling checklist that flows from the correct answer is worth memorizing for the Cyber Awareness Challenge and for real work:

  • Use only authorized, organization-issued media and devices.
  • Never plug in personal or found devices.
  • Encrypt sensitive data at rest on portable media.
  • Scan authorized media for malware before use.
  • Label and handle media at the highest classification of data it has ever held.
  • Store and transport devices securely, and report loss immediately.

The underlying principle is that convenience is exactly what makes these devices dangerous: the same portability that helps you carry files helps an attacker carry malware in or data out. Treating removable media and PEDs as one tightly controlled category is how organizations keep that convenience from becoming a breach.

Practice question

Which of the following is true of removable media and portable electronic devices (PEDs)?

Frequently asked

What are the risks of using removable media?

The two main risks are malicious code, where malware on a drive executes when connected, and data spillage or loss, where sensitive data is copied off and then the device is lost or stolen. Their small size and portability make both risks easy to realize.

Can you use personal USB drives on government computers?

No. Personal or unauthorized removable media must never be connected to government or organizational systems. Only organization-owned, approved media may be used, and even then only in accordance with policy. Scanning a personal drive does not make it authorized.

What is a PED in cyber awareness?

A PED is a portable electronic device, such as a smartphone, tablet, smartwatch, or portable storage device. In cyber-awareness guidance, PEDs are grouped with removable media because they share the same risks and are governed by the same protection rules.

What rules apply to removable media in cyber awareness?

Use only authorized, organization-issued media; never use personal or found devices; encrypt sensitive data; scan media for malware before use; handle it at the highest classification of data it has held; and follow any organizational restriction or prohibition. Report lost devices immediately.

How should sensitive data on portable devices be protected?

Encrypt the data at rest, store and transport the device securely, restrict access, and use only authorized, organization-owned hardware. Label media at the highest classification it has held, avoid personal devices entirely, and report any loss or theft right away.

Start freeLog in