How Do Air-Gapped Networks Typically Experience Data Loss?

Which of the following is the most common data loss path for an air-gapped network?

  1. Bastion host
  2. Unsecured Bluetooth
  3. Unpatched OS
  4. Removable devices Source Reference Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests your understanding that network isolation does not equal physical isolation, making human-facilitated physical transfers the weakest link in air-gapped security architectures.

This question explores how physically isolated systems can still be compromised, with the community unanimously agreeing that removable storage media represent the primary data exfiltration vector. Understanding physical transfer risks is critical for securing high-assurance environments.

Candidates often select Unsecured Bluetooth or Unpatched OS, mistakenly assuming that wireless or software vulnerabilities remain viable attack paths despite the physical network disconnection, overlooking that air-gaps specifically mitigate remote digital threats.

Community Discussion (3 comments)

Yoez 👍 8 Selected: D
In an air-gapped network, which is physically isolated from other networks, the most common data loss path would typically be through removable devices (option D). These can include USB drives, external hard drives, or other storage devices that could be introduced into the network, intentionally or unintentionally, by users or external entities. This is because such devices can bypass the physical isolation of the air gap and introduce potential security vulnerabilities.
jennyka76 👍 1 Selected: D
The most common data loss path in an air-gapped network is through removable storage devices like USB drives, as they can be used to introduce malware or leak data by unauthorized individuals.
dbrowndiver 👍 1 Selected: D
Removable devices is the correct answer because they provide a direct, physical means to transfer data to and from an air-gapped network, making them the most common path for data loss. Removable devices circumvent the network's isolation by physically connecting it to other systems, posing a significant risk of data exfiltration.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Concept: Air-Gap Limitations

An air-gapped network is intentionally isolated from unsecured networks, such as the public internet, to protect sensitive data or critical infrastructure. However, physical isolation does not eliminate all data exfiltration pathways. As noted by community members, removable devices like USB drives and external hard drives provide a direct, physical conduit that bypasses logical network controls entirely. These media can be introduced by insiders, contractors, or malicious actors to either extract classified information or introduce sophisticated malware into the protected environment.

Why Removable Devices Are the Primary Threat Vector

Option D (Removable devices) is correct because they exploit the human element and physical access, which are inherently difficult to fully control in any operational environment. Even with strict policies, unauthorized copying via portable storage remains the most frequent and successful method for breaching air-gapped systems. Community consensus strongly reinforces this, emphasizing that physical media circumvents network segmentation by directly connecting to internal endpoints.

Evaluating Incorrect Options

  • Bastion host (Option A): A bastion host is a hardened server designed to face external networks, typically used in demilitarized zones (DMZs). It relies on active network connectivity, making it irrelevant to a physically isolated air gap.
  • Unsecured Bluetooth (Option B): While wireless transmission can theoretically bridge air gaps, Bluetooth requires proximity and active pairing. It is significantly less common than removable media due to stricter physical handling requirements and lower data throughput for large-scale exfiltration.
  • Unpatched OS (Option C): Operating system vulnerabilities are a major risk in connected environments, but without a network interface or physical media connection, remote exploitation via unpatched flaws is impossible. The air gap specifically neutralizes this threat unless combined with another vector like removable drives.

Official Reference

Exam Strategy

When encountering questions about isolated or restricted networks, always evaluate both logical and physical attack vectors first. If a network is explicitly described as "air-gapped" or "physically isolated," immediately rule out remote exploitation methods and prioritize human-factor or physical transfer risks like removable media, side-channel attacks, or insider threats.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide