Answer:
Enable the supervisor password in the BIOS/UEFI setup.
Step-by-step explanation:
Since each computer is required to have the USB ports disabled in the firmware, the most likely option is that some employees attempt to circumvent the restriction thereby affecting the Boot Order.
A supervisor password is used to restrict access to the BIOS. Users without a correct BIOS supervisor password cannot make changes to system settings.
However, if the Supervisor Password is enabled, they will not be able to make changes to the BIOS Setup.
All other options are not relevant to this particular ticket.