CompTIA Security+ SY0-701 Security Controls Practice Test 1

 

Topic 01 Practice Test 1 covers Security Controls for CompTIA Security+ SY0-701 and maps to objective 1.1: Compare and contrast various types of security controls. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.

Question 1

A review during a security-control classification review identifies two gaps. One requires safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism. The other requires control used to repair, restore, or reduce damage after an undesirable event. Which TWO options should be included in the remediation plan? Choose TWO.

  1. Technical control
  2. Operational control
  3. Deterrent control
  4. Corrective control
  5. Compensating control

Correct Answers: A, D

Correct Answers

 

 

Answer A is correct because Technical control means a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism. It belongs in the fixed-count answer set because it covers one of the stated requirements. Compensating control instead serves an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required and cannot replace this function.

Answer D is correct because Corrective control means a control used to repair, restore, or reduce damage after an undesirable event. One required function is exactly what this option provides. Compensating control may be useful elsewhere, but it is used for an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required.

Incorrect Answers

 

Answer B is incorrect because Operational control means a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism. The scenario calls for Technical control, Corrective control. Selecting this option would leave one of those required functions uncovered.

Answer C is incorrect because Deterrent control means a control intended to discourage an attacker or policy violation by increasing perceived risk or consequence. The fixed-count answer set is Technical control, Corrective control; this option does not fill one of those named functions.

Answer E is incorrect because Compensating control means an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required. Every answer slot must map to a stated requirement. The correct set is Technical control, Corrective control, so this option cannot replace one of those selections.

 

Question 2

Which control is used to repair, restore, or reduce damage after an undesirable event?

  1. Physical control
  2. Preventive control
  3. Managerial control
  4. Corrective control

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Corrective control means a control used to repair, restore, or reduce damage after an undesirable event. The requirement maps directly to this function, whereas Physical control is aimed at a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures.

Incorrect Answers

 

Answer A is incorrect because Physical control refers to a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures. This could be appropriate elsewhere, but the required function is a control used to repair, restore, or reduce damage after an undesirable event; that makes Corrective control the precise choice.

Answer B is incorrect because Preventive control refers to a control intended to stop an unwanted event before it occurs. The concept is valid, but it does not match this stem. The required function is a control used to repair, restore, or reduce damage after an undesirable event, which maps to Corrective control.

Answer C is incorrect because Managerial control refers to a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes. That concept can be valid in another scenario, but this question is testing a control used to repair, restore, or reduce damage after an undesirable event; Corrective control therefore fits the requirement more directly.

 

Question 3

To identify security events so responders can investigate and act, which security approach should be selected?

  1. Technical control
  2. Directive control
  3. Detective control
  4. Managerial control

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Detective control means a control designed to discover or alert on suspicious activity that has occurred or is occurring. That is the function the question is testing. Technical control would instead be used for a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism.

Incorrect Answers

 

Answer A is incorrect because Technical control refers to a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism. That concept can be valid in another scenario, but this question is testing a control designed to discover or alert on suspicious activity that has occurred or is occurring; Detective control therefore fits the requirement more directly.

Answer B is incorrect because Directive control refers to a control that tells people or systems what behavior is required, commonly through policies, standards, signs, or instructions. The scenario instead requires a control designed to discover or alert on suspicious activity that has occurred or is occurring, which is why Detective control is the better answer; this option serves the different function defined above.

Answer D is incorrect because Managerial control refers to a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes. This could be appropriate elsewhere, but the required function is a control designed to discover or alert on suspicious activity that has occurred or is occurring; that makes Detective control the precise choice.

 

Question 4

Which control is intended to discourage an attacker or policy violation by increasing perceived risk or consequence?

  1. Technical control
  2. Detective control
  3. Deterrent control
  4. Physical control

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Deterrent control means a control intended to discourage an attacker or policy violation by increasing perceived risk or consequence. That is the function the question is testing. Physical control would instead be used for a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures.

Incorrect Answers

 

Answer A is incorrect because Technical control refers to a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism. The scenario instead requires a control intended to discourage an attacker or policy violation by increasing perceived risk or consequence, which is why Deterrent control is the better answer; this option serves the different function defined above.

Answer B is incorrect because Detective control refers to a control designed to discover or alert on suspicious activity that has occurred or is occurring. That concept can be valid in another scenario, but this question is testing a control intended to discourage an attacker or policy violation by increasing perceived risk or consequence; Deterrent control therefore fits the requirement more directly.

Answer D is incorrect because Physical control refers to a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures. The question is not asking for this function. It is testing a control intended to discourage an attacker or policy violation by increasing perceived risk or consequence, so Deterrent control is the stronger fit.

 

Question 5

Which safeguard is implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism?

  1. Corrective control
  2. Technical control
  3. Deterrent control
  4. Managerial control

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Technical control means a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism. This matches the requirement as written. Managerial control can be valid in another context, but it is used for a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes.

Incorrect Answers

 

Answer A is incorrect because Corrective control refers to a control used to repair, restore, or reduce damage after an undesirable event. The scenario instead requires a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism, which is why Technical control is the better answer; this option serves the different function defined above.

Answer C is incorrect because Deterrent control refers to a control intended to discourage an attacker or policy violation by increasing perceived risk or consequence. That concept can be valid in another scenario, but this question is testing a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism; Technical control therefore fits the requirement more directly.

Answer D is incorrect because Managerial control refers to a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes. This could be appropriate elsewhere, but the required function is a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism; that makes Technical control the precise choice.

 

Question 6

Which alternative safeguard is used when the preferred control cannot be implemented but equivalent risk reduction is still required?

  1. Managerial control
  2. Operational control
  3. Compensating control
  4. Deterrent control

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Compensating control means an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required. The deciding point is functional fit: this option covers the stated need, while Operational control addresses a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism.

Incorrect Answers

 

Answer A is incorrect because Managerial control refers to a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes. That concept can be valid in another scenario, but this question is testing an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required; Compensating control therefore fits the requirement more directly.

Answer B is incorrect because Operational control refers to a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism. The concept is valid, but it does not match this stem. The required function is an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required, which maps to Compensating control.

Answer D is incorrect because Deterrent control refers to a control intended to discourage an attacker or policy violation by increasing perceived risk or consequence. That concept can be valid in another scenario, but this question is testing an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required; Compensating control therefore fits the requirement more directly.

 

Question 7

Which safeguard is carried out primarily by people and day-to-day processes rather than by a purely technical mechanism?

  1. Technical control
  2. Operational control
  3. Compensating control
  4. Corrective control

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Operational control means a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism. This is the precise fit for the scenario. Compensating control serves the different purpose of an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required.

Incorrect Answers

 

Answer A is incorrect because Technical control refers to a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism. The concept is valid, but it does not match this stem. The required function is a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism, which maps to Operational control.

Answer C is incorrect because Compensating control refers to an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required. The concept is valid, but it does not match this stem. The required function is a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism, which maps to Operational control.

Answer D is incorrect because Corrective control refers to a control used to repair, restore, or reduce damage after an undesirable event. The concept is valid, but it does not match this stem. The required function is a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism, which maps to Operational control.

 

Question 8

To provide substitute protection when a primary requirement is impractical, which security approach should be selected?

  1. Compensating control
  2. Operational control
  3. Detective control
  4. Preventive control

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Compensating control means an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required. That is the function the question is testing. Operational control would instead be used for a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism.

Incorrect Answers

 

Answer B is incorrect because Operational control refers to a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism. The scenario instead requires an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required, which is why Compensating control is the better answer; this option serves the different function defined above.

Answer C is incorrect because Detective control refers to a control designed to discover or alert on suspicious activity that has occurred or is occurring. That concept can be valid in another scenario, but this question is testing an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required; Compensating control therefore fits the requirement more directly.

Answer D is incorrect because Preventive control refers to a control intended to stop an unwanted event before it occurs. The concept is valid, but it does not match this stem. The required function is an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required, which maps to Compensating control.

 

Question 9

A review during a security-control classification review identifies two gaps. One requires governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes. The other requires control designed to discover or alert on suspicious activity that has occurred or is occurring. Which TWO options should be included in the remediation plan? Choose TWO.

  1. Operational control
  2. Compensating control
  3. Managerial control
  4. Physical control
  5. Detective control

Correct Answers: C, E

Correct Answers

 

 

Answer C is correct because Managerial control means a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes. This selection maps directly to one of the named needs. Operational control addresses a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism, so it does not satisfy the same slot.

Answer E is correct because Detective control means a control designed to discover or alert on suspicious activity that has occurred or is occurring. One required function is exactly what this option provides. Physical control may be useful elsewhere, but it is used for a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures.

Incorrect Answers

 

Answer A is incorrect because Operational control means a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism. The fixed-count answer set is Managerial control, Detective control; this option does not fill one of those named functions.

Answer B is incorrect because Compensating control means an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required. The fixed-count answer set is Managerial control, Detective control; this option does not fill one of those named functions.

Answer D is incorrect because Physical control means a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures. The scenario calls for Managerial control, Detective control. Selecting this option would leave one of those required functions uncovered.

 

Question 10

To communicate mandatory security behavior and expected actions, which security approach should be selected?

  1. Corrective control
  2. Physical control
  3. Preventive control
  4. Directive control

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Directive control means a control that tells people or systems what behavior is required, commonly through policies, standards, signs, or instructions. This is the precise fit for the scenario. Preventive control serves the different purpose of a control intended to stop an unwanted event before it occurs.

Incorrect Answers

 

Answer A is incorrect because Corrective control refers to a control used to repair, restore, or reduce damage after an undesirable event. The scenario instead requires a control that tells people or systems what behavior is required, commonly through policies, standards, signs, or instructions, which is why Directive control is the better answer; this option serves the different function defined above.

Answer B is incorrect because Physical control refers to a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures. This could be appropriate elsewhere, but the required function is a control that tells people or systems what behavior is required, commonly through policies, standards, signs, or instructions; that makes Directive control the precise choice.

Answer C is incorrect because Preventive control refers to a control intended to stop an unwanted event before it occurs. The question is not asking for this function. It is testing a control that tells people or systems what behavior is required, commonly through policies, standards, signs, or instructions, so Directive control is the stronger fit.

 

Question 11

A security plan created during a security-control classification review must provide safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism, safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism, and control intended to discourage an attacker or policy violation by increasing perceived risk or consequence. Which THREE options should be selected? Choose THREE.

  1. Preventive control
  2. Technical control
  3. Operational control
  4. Directive control
  5. Deterrent control
  6. Compensating control

Correct Answers: B, C, E

Correct Answers

 

 

Answer B is correct because Technical control means a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism. This option satisfies a specific requirement in the stem; Compensating control serves an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required and therefore is not interchangeable with it.

Answer C is correct because Operational control means a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism. The fixed-count item needs this function in the answer set. Preventive control covers a control intended to stop an unwanted event before it occurs, a different requirement.

Answer E is correct because Deterrent control means a control intended to discourage an attacker or policy violation by increasing perceived risk or consequence. This selection maps directly to one of the named needs. Compensating control addresses an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required, so it does not satisfy the same slot.

Incorrect Answers

 

Answer A is incorrect because Preventive control means a control intended to stop an unwanted event before it occurs. Every answer slot must map to a stated requirement. The correct set is Technical control, Operational control, Deterrent control, so this option cannot replace one of those selections.

Answer D is incorrect because Directive control means a control that tells people or systems what behavior is required, commonly through policies, standards, signs, or instructions. Every answer slot must map to a stated requirement. The correct set is Technical control, Operational control, Deterrent control, so this option cannot replace one of those selections.

Answer F is incorrect because Compensating control means an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required. Every answer slot must map to a stated requirement. The correct set is Technical control, Operational control, Deterrent control, so this option cannot replace one of those selections.

 

Question 12

To set organizational expectations, accountability, and risk direction, which security approach should be selected?

  1. Directive control
  2. Compensating control
  3. Deterrent control
  4. Managerial control

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Managerial control means a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes. The requirement maps directly to this function, whereas Compensating control is aimed at an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required.

Incorrect Answers

 

Answer A is incorrect because Directive control refers to a control that tells people or systems what behavior is required, commonly through policies, standards, signs, or instructions. That concept can be valid in another scenario, but this question is testing a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes; Managerial control therefore fits the requirement more directly.

Answer B is incorrect because Compensating control refers to an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required. The question is not asking for this function. It is testing a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes, so Managerial control is the stronger fit.

Answer C is incorrect because Deterrent control refers to a control intended to discourage an attacker or policy violation by increasing perceived risk or consequence. The key mismatch is functional: Managerial control addresses a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes, the need stated by the question.

 

Question 13

To restrict or deter physical access to systems and facilities, which security approach should be selected?

  1. Physical control
  2. Technical control
  3. Compensating control
  4. Preventive control

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Physical control means a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures. That makes it the best answer here; Preventive control addresses a control intended to stop an unwanted event before it occurs, not the function requested in the stem.

Incorrect Answers

 

Answer B is incorrect because Technical control refers to a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism. The concept is valid, but it does not match this stem. The required function is a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures, which maps to Physical control.

Answer C is incorrect because Compensating control refers to an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required. The key mismatch is functional: Physical control addresses a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures, the need stated by the question.

Answer D is incorrect because Preventive control refers to a control intended to stop an unwanted event before it occurs. That concept can be valid in another scenario, but this question is testing a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures; Physical control therefore fits the requirement more directly.

 

Question 14

During a security-control classification review, the team has two independent requirements: (1) safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism; and (2) control that tells people or systems what behavior is required, commonly through policies, standards, signs, or instructions. Which TWO choices best satisfy those requirements? Choose TWO.

  1. Compensating control
  2. Technical control
  3. Directive control
  4. Preventive control
  5. Managerial control

Correct Answers: B, C

Correct Answers

 

 

Answer B is correct because Technical control means a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism. This selection maps directly to one of the named needs. Compensating control addresses an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required, so it does not satisfy the same slot.

Answer C is correct because Directive control means a control that tells people or systems what behavior is required, commonly through policies, standards, signs, or instructions. One required function is exactly what this option provides. Managerial control may be useful elsewhere, but it is used for a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes.

Incorrect Answers

 

Answer A is incorrect because Compensating control means an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required. The required choices are Technical control, Directive control. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer D is incorrect because Preventive control means a control intended to stop an unwanted event before it occurs. The question requires exactly 2 selections: Technical control, Directive control. This option falls outside that required set. For example, Directive control is required for a control that tells people or systems what behavior is required, commonly through policies, standards, signs, or instructions.

Answer E is incorrect because Managerial control means a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes. The scenario calls for Technical control, Directive control. Selecting this option would leave one of those required functions uncovered.

 

Question 15

Which safeguard protects facilities, equipment, or people through tangible barriers or environmental measures?

  1. Physical control
  2. Operational control
  3. Compensating control
  4. Managerial control

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Physical control means a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures. The requirement maps directly to this function, whereas Compensating control is aimed at an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required.

Incorrect Answers

 

Answer B is incorrect because Operational control refers to a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism. The scenario instead requires a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures, which is why Physical control is the better answer; this option serves the different function defined above.

Answer C is incorrect because Compensating control refers to an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required. The question is not asking for this function. It is testing a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures, so Physical control is the stronger fit.

Answer D is incorrect because Managerial control refers to a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes. This could be appropriate elsewhere, but the required function is a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures; that makes Physical control the precise choice.

 

Question 16

An architect working on a security-control classification review needs one capability that provides safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures and another that provides control intended to stop an unwanted event before it occurs. Which TWO selections are the best match? Choose TWO.

  1. Directive control
  2. Physical control
  3. Preventive control
  4. Managerial control
  5. Technical control

Correct Answers: B, C

Correct Answers

 

 

Answer B is correct because Physical control means a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures. One required function is exactly what this option provides. Managerial control may be useful elsewhere, but it is used for a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes.

Answer C is correct because Preventive control means a control intended to stop an unwanted event before it occurs. The fixed-count item needs this function in the answer set. Directive control covers a control that tells people or systems what behavior is required, commonly through policies, standards, signs, or instructions, a different requirement.

Incorrect Answers

 

Answer A is incorrect because Directive control means a control that tells people or systems what behavior is required, commonly through policies, standards, signs, or instructions. Every answer slot must map to a stated requirement. The correct set is Preventive control, Physical control, so this option cannot replace one of those selections.

Answer D is incorrect because Managerial control means a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes. Every answer slot must map to a stated requirement. The correct set is Preventive control, Physical control, so this option cannot replace one of those selections.

Answer E is incorrect because Technical control means a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism. The scenario calls for Preventive control, Physical control. Selecting this option would leave one of those required functions uncovered.

 

Question 17

During a security-control classification review, the team has two independent requirements: (1) control intended to stop an unwanted event before it occurs; and (2) control designed to discover or alert on suspicious activity that has occurred or is occurring. Which TWO choices best satisfy those requirements? Choose TWO.

  1. Preventive control
  2. Physical control
  3. Technical control
  4. Managerial control
  5. Detective control

Correct Answers: A, E

Correct Answers

 

 

Answer A is correct because Preventive control means a control intended to stop an unwanted event before it occurs. This option satisfies a specific requirement in the stem; Managerial control serves a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes and therefore is not interchangeable with it.

Answer E is correct because Detective control means a control designed to discover or alert on suspicious activity that has occurred or is occurring. This option satisfies a specific requirement in the stem; Managerial control serves a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes and therefore is not interchangeable with it.

Incorrect Answers

 

Answer B is incorrect because Physical control means a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures. The scenario calls for Preventive control, Detective control. Selecting this option would leave one of those required functions uncovered.

Answer C is incorrect because Technical control means a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism. The fixed-count answer set is Preventive control, Detective control; this option does not fill one of those named functions.

Answer D is incorrect because Managerial control means a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes. The question requires exactly 2 selections: Preventive control, Detective control. This option falls outside that required set.

 

Question 18

To block or reduce the likelihood of a security incident before impact, which security approach should be selected?

  1. Compensating control
  2. Managerial control
  3. Preventive control
  4. Physical control

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Preventive control means a control intended to stop an unwanted event before it occurs. That is the function the question is testing. Managerial control would instead be used for a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes.

Incorrect Answers

 

Answer A is incorrect because Compensating control refers to an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required. That concept can be valid in another scenario, but this question is testing a control intended to stop an unwanted event before it occurs; Preventive control therefore fits the requirement more directly.

Answer B is incorrect because Managerial control refers to a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes. The scenario instead requires a control intended to stop an unwanted event before it occurs, which is why Preventive control is the better answer; this option serves the different function defined above.

Answer D is incorrect because Physical control refers to a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures. This could be appropriate elsewhere, but the required function is a control intended to stop an unwanted event before it occurs; that makes Preventive control the precise choice.

 

Question 19

To enforce a security requirement automatically through hardware or software, which security approach should be selected?

  1. Operational control
  2. Technical control
  3. Managerial control
  4. Directive control

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Technical control means a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism. This is the precise fit for the scenario. Directive control serves the different purpose of a control that tells people or systems what behavior is required, commonly through policies, standards, signs, or instructions.

Incorrect Answers

 

Answer A is incorrect because Operational control refers to a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism. This could be appropriate elsewhere, but the required function is a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism; that makes Technical control the precise choice.

Answer C is incorrect because Managerial control refers to a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes. The scenario instead requires a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism, which is why Technical control is the better answer; this option serves the different function defined above.

Answer D is incorrect because Directive control refers to a control that tells people or systems what behavior is required, commonly through policies, standards, signs, or instructions. That concept can be valid in another scenario, but this question is testing a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism; Technical control therefore fits the requirement more directly.

 

Question 20

To make undesirable behavior less attractive without necessarily blocking it technically, which security approach should be selected?

  1. Compensating control
  2. Operational control
  3. Managerial control
  4. Deterrent control

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Deterrent control means a control intended to discourage an attacker or policy violation by increasing perceived risk or consequence. This matches the requirement as written. Compensating control can be valid in another context, but it is used for an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required.

Incorrect Answers

 

Answer A is incorrect because Compensating control refers to an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required. The question is not asking for this function. It is testing a control intended to discourage an attacker or policy violation by increasing perceived risk or consequence, so Deterrent control is the stronger fit.

Answer B is incorrect because Operational control refers to a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism. The scenario instead requires a control intended to discourage an attacker or policy violation by increasing perceived risk or consequence, which is why Deterrent control is the better answer; this option serves the different function defined above.

Answer C is incorrect because Managerial control refers to a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes. The key mismatch is functional: Deterrent control addresses a control intended to discourage an attacker or policy violation by increasing perceived risk or consequence, the need stated by the question.

Leave a Reply

How It Works

img
Step 1. Choose Exam
on ExamLabs
Download IT Exams Questions & Answers
img
Step 2. Open Exam with
Avanset Exam Simulator
Press here to download VCE Exam Simulator that simulates real exam environment
img
Step 3. Study
& Pass
IT Exams Anywhere, Anytime!