Lab Objective

Completed Google Cybersecurity Certificate removable-media exercise: assess a found USB drive as both a data-exposure and malware-delivery risk, without connecting it to a workstation.

Lab Environment

  • Course: Google Cybersecurity Certificate
  • Exercise type: completed scenario-based risk analysis
  • Scenario: a found removable drive containing a mix of personal and work-related documents
  • Safety boundary: no USB device was mounted, opened, or executed for this exercise

Scenario

The training scenario described a removable drive holding personal material alongside work documents that could reveal employee details, roles, and routines. The analysis had to consider what an attacker could learn from the files and what could happen if an employee connected the unknown device.

Step 1 - Identify the Information-Exposure Risk

I treated the contents as a potential source of social-engineering intelligence.

Information such as names, job details, schedules, and personal context can help an attacker write a message that sounds credible, impersonate a colleague, or choose a high-value target. This is why personal files and sensitive work information should not share an unmanaged removable device.

Step 2 - Identify the Device-Execution Risk

I then analyzed the connection itself as a separate risk.

An unknown device might carry ransomware, spyware, a keylogger, or a payload that creates unauthorized access after connection. A benign-looking filename does not prove a device is safe, and opening a file on a normal workstation is not an appropriate investigation method.

Step 3 - Choose Layered Controls

The completed exercise recommended a combination of controls:

  • train staff not to connect found or unknown devices
  • require suspicious media to be reported to the security team
  • block or restrict removable media where it is not required
  • disable automatic execution
  • scan approved media through a controlled process
  • encrypt sensitive work data and keep it separate from personal files

Step 4 - Define a Safe First Response

found_device
    β†’ do_not_connect_to_business_endpoint
    β†’ record_where_and_when_it_was_found
    β†’ report_to_security_or_authorized_handler
    β†’ preserve_device_for_controlled_analysis
    β†’ review_endpoint_telemetry_only_if_connection_already_occurred

The critical control is early: avoid creating the incident while trying to investigate it.

Security Takeaways

  1. Unknown media presents two attack paths. Data on the device can support manipulation; connecting the device can execute malicious code.
  2. Curiosity is not a safe analysis method. Use an approved reporting and analysis route instead of a normal user endpoint.
  3. Data separation reduces social-engineering value. Mixing personal and business information gives an attacker richer context.
  4. Technical and operational controls work together. Device restrictions, disabled auto-run, scanning, encryption, and user training are stronger as a set than alone.
  5. Incident response begins before malware is confirmed. Preservation and reporting protect both the environment and the evidence.

Where This Applies Beyond the Lab

This same approach applies to external hard drives, unknown charging devices, shared storage, and files delivered through unexpected channels. The question is not only β€œcould this run malware?” but also β€œwhat information could it reveal, and what unsafe action might it persuade someone to take?”