How Do Air-Gapped Networks Typically Experience Data Loss?
Which of the following is the most common data loss path for an air-gapped network?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests your understanding that network isolation does not equal physical isolation, making human-facilitated physical transfers the weakest link in air-gapped security architectures.
This question explores how physically isolated systems can still be compromised, with the community unanimously agreeing that removable storage media represent the primary data exfiltration vector. Understanding physical transfer risks is critical for securing high-assurance environments.
Candidates often select Unsecured Bluetooth or Unpatched OS, mistakenly assuming that wireless or software vulnerabilities remain viable attack paths despite the physical network disconnection, overlooking that air-gaps specifically mitigate remote digital threats.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept: Air-Gap Limitations
An air-gapped network is intentionally isolated from unsecured networks, such as the public internet, to protect sensitive data or critical infrastructure. However, physical isolation does not eliminate all data exfiltration pathways. As noted by community members, removable devices like USB drives and external hard drives provide a direct, physical conduit that bypasses logical network controls entirely. These media can be introduced by insiders, contractors, or malicious actors to either extract classified information or introduce sophisticated malware into the protected environment.Why Removable Devices Are the Primary Threat Vector
Option D (Removable devices) is correct because they exploit the human element and physical access, which are inherently difficult to fully control in any operational environment. Even with strict policies, unauthorized copying via portable storage remains the most frequent and successful method for breaching air-gapped systems. Community consensus strongly reinforces this, emphasizing that physical media circumvents network segmentation by directly connecting to internal endpoints.Evaluating Incorrect Options
- Bastion host (Option A): A bastion host is a hardened server designed to face external networks, typically used in demilitarized zones (DMZs). It relies on active network connectivity, making it irrelevant to a physically isolated air gap.
- Unsecured Bluetooth (Option B): While wireless transmission can theoretically bridge air gaps, Bluetooth requires proximity and active pairing. It is significantly less common than removable media due to stricter physical handling requirements and lower data throughput for large-scale exfiltration.
- Unpatched OS (Option C): Operating system vulnerabilities are a major risk in connected environments, but without a network interface or physical media connection, remote exploitation via unpatched flaws is impossible. The air gap specifically neutralizes this threat unless combined with another vector like removable drives.
Official Reference
Exam Strategy
When encountering questions about isolated or restricted networks, always evaluate both logical and physical attack vectors first. If a network is explicitly described as "air-gapped" or "physically isolated," immediately rule out remote exploitation methods and prioritize human-factor or physical transfer risks like removable media, side-channel attacks, or insider threats.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →