CompTIA Security+ SY0-701 Security Controls Practice Test 2

 

Topic 01 Practice Test 2 covers Security Controls for CompTIA Security+ SY0-701 and maps to objective 1.1: Compare and contrast various types of security controls. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.

Question 1

Which governance-oriented safeguard directs security through policies, risk decisions, oversight, and management processes?

  1. Managerial control
  2. Compensating control
  3. Physical control
  4. Detective control

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Managerial control means a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes. That makes it the best answer here; Detective control addresses a control designed to discover or alert on suspicious activity that has occurred or is occurring, not the function requested in the stem.

Incorrect Answers

 

Answer B is incorrect because Compensating control refers to an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required. The concept is valid, but it does not match this stem. The required function is a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes, which maps to Managerial control.

Answer C is incorrect because Physical control refers to a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures. The scenario instead requires a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes, which is why Managerial control is the better answer; this option serves the different function defined above.

Answer D is incorrect because Detective control refers to a control designed to discover or alert on suspicious activity that has occurred or is occurring. The scenario instead requires a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes, which is why Managerial control is the better answer; this option serves the different function defined above.

 

Question 2

Which control designed to discover or alert on suspicious activity has occurred or is occurring?

  1. Deterrent control
  2. Directive control
  3. Detective control
  4. Technical control

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Detective control means a control designed to discover or alert on suspicious activity that has occurred or is occurring. That is the function the question is testing. Technical control would instead be used for a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism. This question specifically tests the requirement represented by Detective control.

Incorrect Answers

 

Answer A is incorrect because Deterrent control refers to a control intended to discourage an attacker or policy violation by increasing perceived risk or consequence. The key mismatch is functional: Detective control addresses a control designed to discover or alert on suspicious activity that has occurred or is occurring, the need stated by the question.

Answer B is incorrect because Directive control refers to a control that tells people or systems what behavior is required, commonly through policies, standards, signs, or instructions. This could be appropriate elsewhere, but the required function is a control designed to discover or alert on suspicious activity that has occurred or is occurring; that makes Detective control the precise choice.

Answer D is incorrect because Technical control refers to a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism. The key mismatch is functional: Detective control addresses a control designed to discover or alert on suspicious activity that has occurred or is occurring, the need stated by the question.

 

Question 3

A review during a security-control classification review identifies two gaps. One requires safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism. The other requires safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures. Which TWO options should be included in the remediation plan? Choose TWO.

  1. Preventive control
  2. Technical control
  3. Physical control
  4. Deterrent control
  5. Directive control

Correct Answers: B, C

Correct Answers

 

 

Answer B is correct because Technical control means a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism. It belongs in the fixed-count answer set because it covers one of the stated requirements. Preventive control instead serves a control intended to stop an unwanted event before it occurs and cannot replace this function.

Answer C is correct because Physical control means a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures. This selection maps directly to one of the named needs. Directive control addresses a control that tells people or systems what behavior is required, commonly through policies, standards, signs, or instructions, so it does not satisfy the same slot.

Incorrect Answers

 

Answer A is incorrect because Preventive control means a control intended to stop an unwanted event before it occurs. The question requires exactly 2 selections: Technical control, Physical control. This option falls outside that required set. For example, Physical control is required for a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures.

Answer D is incorrect because Deterrent control means a control intended to discourage an attacker or policy violation by increasing perceived risk or consequence. Every answer slot must map to a stated requirement. The correct set is Technical control, Physical control, so this option cannot replace one of those selections.

Answer E is incorrect because Directive control means a control that tells people or systems what behavior is required, commonly through policies, standards, signs, or instructions. The question requires exactly 2 selections: Technical control, Physical control. This option falls outside that required set.

 

Question 4

Which control tells people or systems what behavior is required, commonly through policies, standards, signs, or instructions?

  1. Technical control
  2. Managerial control
  3. Directive control
  4. Preventive control

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Directive control means a control that tells people or systems what behavior is required, commonly through policies, standards, signs, or instructions. The requirement maps directly to this function, whereas Technical control is aimed at a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism.

Incorrect Answers

 

Answer A is incorrect because Technical control refers to a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism. The concept is valid, but it does not match this stem. The required function is a control that tells people or systems what behavior is required, commonly through policies, standards, signs, or instructions, which maps to Directive control.

Answer B is incorrect because Managerial control refers to a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes. The question is not asking for this function. It is testing a control that tells people or systems what behavior is required, commonly through policies, standards, signs, or instructions, so Directive control is the stronger fit.

Answer D is incorrect because Preventive control refers to a control intended to stop an unwanted event before it occurs. The concept is valid, but it does not match this stem. The required function is a control that tells people or systems what behavior is required, commonly through policies, standards, signs, or instructions, which maps to Directive control.

 

Question 5

During a security-control classification review, the team needs control intended to stop an unwanted event before it occurs. Which option best meets this requirement?

  1. Deterrent control
  2. Preventive control
  3. Detective control
  4. Physical control

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Preventive control means a control intended to stop an unwanted event before it occurs. This is the precise fit for the scenario. Detective control serves the different purpose of a control designed to discover or alert on suspicious activity that has occurred or is occurring.

Incorrect Answers

 

Answer A is incorrect because Deterrent control means a control intended to discourage an attacker or policy violation by increasing perceived risk or consequence. This could be appropriate elsewhere, but the required function is a control intended to stop an unwanted event before it occurs; that makes Preventive control the precise choice.

Answer C is incorrect because Detective control means a control designed to discover or alert on suspicious activity that has occurred or is occurring. The key mismatch is functional: Preventive control addresses a control intended to stop an unwanted event before it occurs, the need stated by the question.

Answer D is incorrect because Physical control means a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures. That concept can be valid in another scenario, but this question is testing a control intended to stop an unwanted event before it occurs; Preventive control therefore fits the requirement more directly.

 

Question 6

During a security-control classification review, the team needs control that tells people or systems what behavior is required, commonly through policies, standards, signs, or instructions. Which option best meets this requirement?

  1. Directive control
  2. Preventive control
  3. Corrective control
  4. Technical control

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Directive control means a control that tells people or systems what behavior is required, commonly through policies, standards, signs, or instructions. This matches the requirement as written. Preventive control can be valid in another context, but it is used for a control intended to stop an unwanted event before it occurs.

Incorrect Answers

 

Answer B is incorrect because Preventive control means a control intended to stop an unwanted event before it occurs. That concept can be valid in another scenario, but this question is testing a control that tells people or systems what behavior is required, commonly through policies, standards, signs, or instructions; Directive control therefore fits the requirement more directly.

Answer C is incorrect because Corrective control means a control used to repair, restore, or reduce damage after an undesirable event. This could be appropriate elsewhere, but the required function is a control that tells people or systems what behavior is required, commonly through policies, standards, signs, or instructions; that makes Directive control the precise choice.

Answer D is incorrect because Technical control means a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism. That concept can be valid in another scenario, but this question is testing a control that tells people or systems what behavior is required, commonly through policies, standards, signs, or instructions; Directive control therefore fits the requirement more directly.

 

Question 7

To return systems or processes to an acceptable state after an incident, which security approach should be selected?

  1. Operational control
  2. Compensating control
  3. Corrective control
  4. Deterrent control

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Corrective control means a control used to repair, restore, or reduce damage after an undesirable event. The requirement maps directly to this function, whereas Operational control is aimed at a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism.

Incorrect Answers

 

Answer A is incorrect because Operational control refers to a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism. This could be appropriate elsewhere, but the required function is a control used to repair, restore, or reduce damage after an undesirable event; that makes Corrective control the precise choice.

Answer B is incorrect because Compensating control refers to an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required. That concept can be valid in another scenario, but this question is testing a control used to repair, restore, or reduce damage after an undesirable event; Corrective control therefore fits the requirement more directly.

Answer D is incorrect because Deterrent control refers to a control intended to discourage an attacker or policy violation by increasing perceived risk or consequence. The key mismatch is functional: Corrective control addresses a control used to repair, restore, or reduce damage after an undesirable event, the need stated by the question.

 

Question 8

Two requirements remain open in a security-control classification review: safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism; control used to repair, restore, or reduce damage after an undesirable event. Which TWO options close those specific gaps? Choose TWO.

  1. Preventive control
  2. Detective control
  3. Corrective control
  4. Physical control
  5. Operational control

Correct Answers: C, E

Correct Answers

 

 

Answer C is correct because Corrective control means a control used to repair, restore, or reduce damage after an undesirable event. It belongs in the fixed-count answer set because it covers one of the stated requirements. Detective control instead serves a control designed to discover or alert on suspicious activity that has occurred or is occurring and cannot replace this function.

Answer E is correct because Operational control means a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism. This option satisfies a specific requirement in the stem; Preventive control serves a control intended to stop an unwanted event before it occurs and therefore is not interchangeable with it.

Incorrect Answers

 

Answer A is incorrect because Preventive control means a control intended to stop an unwanted event before it occurs. The fixed-count answer set is Corrective control, Operational control; this option does not fill one of those named functions. For example, Corrective control is required for a control used to repair, restore, or reduce damage after an undesirable event.

Answer B is incorrect because Detective control means a control designed to discover or alert on suspicious activity that has occurred or is occurring. The question requires exactly 2 selections: Corrective control, Operational control. This option falls outside that required set.

Answer D is incorrect because Physical control means a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures. The required choices are Corrective control, Operational control. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

 

Question 9

A security engineer is working through a security-control classification review. The immediate requirement is safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism. Which choice is the best fit?

  1. Managerial control
  2. Compensating control
  3. Technical control
  4. Operational control

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Operational control means a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism. The deciding point is functional fit: this option covers the stated need, while Managerial control addresses a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes.

Incorrect Answers

 

Answer A is incorrect because Managerial control means a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes. The scenario instead requires a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism, which is why Operational control is the better answer; this option serves the different function defined above.

Answer B is incorrect because Compensating control means an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required. The concept is valid, but it does not match this stem. The required function is a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism, which maps to Operational control.

Answer C is incorrect because Technical control means a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism. The key mismatch is functional: Operational control addresses a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism, the need stated by the question.

 

Question 10

A design decision in a security-control classification review must provide safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism. Which choice most directly satisfies that requirement?

  1. Technical control
  2. Managerial control
  3. Operational control
  4. Detective control

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Technical control means a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism. This matches the requirement as written. Managerial control can be valid in another context, but it is used for a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes. This question specifically tests the requirement represented by Technical control.

Incorrect Answers

 

Answer B is incorrect because Managerial control means a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes. The question is not asking for this function. It is testing a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism, so Technical control is the stronger fit.

Answer C is incorrect because Operational control means a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism. The concept is valid, but it does not match this stem. The required function is a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism, which maps to Technical control.

Answer D is incorrect because Detective control means a control designed to discover or alert on suspicious activity that has occurred or is occurring. The question is not asking for this function. It is testing a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism, so Technical control is the stronger fit.

 

Question 11

The control set for a security-control classification review must address both control intended to stop an unwanted event before it occurs and control intended to discourage an attacker or policy violation by increasing perceived risk or consequence. Which TWO choices map directly to those needs? Choose TWO.

  1. Physical control
  2. Directive control
  3. Deterrent control
  4. Preventive control
  5. Detective control

Correct Answers: C, D

Correct Answers

 

 

Answer C is correct because Deterrent control means a control intended to discourage an attacker or policy violation by increasing perceived risk or consequence. It belongs in the fixed-count answer set because it covers one of the stated requirements. Physical control instead serves a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures and cannot replace this function.

Answer D is correct because Preventive control means a control intended to stop an unwanted event before it occurs. It belongs in the fixed-count answer set because it covers one of the stated requirements. Physical control instead serves a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures and cannot replace this function.

Incorrect Answers

 

Answer A is incorrect because Physical control means a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures. The question requires exactly 2 selections: Preventive control, Deterrent control. This option falls outside that required set.

Answer B is incorrect because Directive control means a control that tells people or systems what behavior is required, commonly through policies, standards, signs, or instructions. The required choices are Preventive control, Deterrent control. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer E is incorrect because Detective control means a control designed to discover or alert on suspicious activity that has occurred or is occurring. The question requires exactly 2 selections: Preventive control, Deterrent control. This option falls outside that required set.

 

Question 12

During a security-control classification review, the team needs alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required. Which option best meets this requirement?

  1. Directive control
  2. Corrective control
  3. Preventive control
  4. Compensating control

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Compensating control means an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required. The deciding point is functional fit: this option covers the stated need, while Corrective control addresses a control used to repair, restore, or reduce damage after an undesirable event.

Incorrect Answers

 

Answer A is incorrect because Directive control means a control that tells people or systems what behavior is required, commonly through policies, standards, signs, or instructions. That concept can be valid in another scenario, but this question is testing an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required; Compensating control therefore fits the requirement more directly.

Answer B is incorrect because Corrective control means a control used to repair, restore, or reduce damage after an undesirable event. The key mismatch is functional: Compensating control addresses an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required, the need stated by the question.

Answer C is incorrect because Preventive control means a control intended to stop an unwanted event before it occurs. The key mismatch is functional: Compensating control addresses an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required, the need stated by the question.

 

Question 13

To use repeatable human procedures such as security operations, training, or manual review, which security approach should be selected?

  1. Technical control
  2. Directive control
  3. Deterrent control
  4. Operational control

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Operational control means a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism. The deciding point is functional fit: this option covers the stated need, while Technical control addresses a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism.

Incorrect Answers

 

Answer A is incorrect because Technical control refers to a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism. The key mismatch is functional: Operational control addresses a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism, the need stated by the question.

Answer B is incorrect because Directive control refers to a control that tells people or systems what behavior is required, commonly through policies, standards, signs, or instructions. The question is not asking for this function. It is testing a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism, so Operational control is the stronger fit.

Answer C is incorrect because Deterrent control refers to a control intended to discourage an attacker or policy violation by increasing perceived risk or consequence. The concept is valid, but it does not match this stem. The required function is a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism, which maps to Operational control.

 

Question 14

Two requirements remain open in a security-control classification review: control designed to discover or alert on suspicious activity that has occurred or is occurring; control used to repair, restore, or reduce damage after an undesirable event. Which TWO options close those specific gaps? Choose TWO.

  1. Corrective control
  2. Detective control
  3. Preventive control
  4. Physical control
  5. Managerial control

Correct Answers: A, B

Correct Answers

 

 

Answer A is correct because Corrective control means a control used to repair, restore, or reduce damage after an undesirable event. This selection maps directly to one of the named needs. Preventive control addresses a control intended to stop an unwanted event before it occurs, so it does not satisfy the same slot.

Answer B is correct because Detective control means a control designed to discover or alert on suspicious activity that has occurred or is occurring. One required function is exactly what this option provides. Preventive control may be useful elsewhere, but it is used for a control intended to stop an unwanted event before it occurs.

Incorrect Answers

 

Answer C is incorrect because Preventive control means a control intended to stop an unwanted event before it occurs. The scenario calls for Detective control, Corrective control. Selecting this option would leave one of those required functions uncovered. For example, Detective control is required for a control designed to discover or alert on suspicious activity that has occurred or is occurring.

Answer D is incorrect because Physical control means a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures. The question requires exactly 2 selections: Detective control, Corrective control. This option falls outside that required set.

Answer E is incorrect because Managerial control means a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes. The fixed-count answer set is Detective control, Corrective control; this option does not fill one of those named functions.

 

Question 15

A review during a security-control classification review identifies two gaps. One requires safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism. The other requires safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism. Which TWO options should be included in the remediation plan? Choose TWO.

  1. Compensating control
  2. Directive control
  3. Technical control
  4. Managerial control
  5. Operational control

Correct Answers: C, E

Correct Answers

 

 

Answer C is correct because Technical control means a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism. The fixed-count item needs this function in the answer set. Compensating control covers an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required, a different requirement.

Answer E is correct because Operational control means a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism. This option satisfies a specific requirement in the stem; Compensating control serves an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required and therefore is not interchangeable with it.

Incorrect Answers

 

Answer A is incorrect because Compensating control means an alternative safeguard used when the preferred control cannot be implemented but equivalent risk reduction is still required. The required choices are Technical control, Operational control. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer B is incorrect because Directive control means a control that tells people or systems what behavior is required, commonly through policies, standards, signs, or instructions. The required choices are Technical control, Operational control. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer D is incorrect because Managerial control means a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes. The question requires exactly 2 selections: Technical control, Operational control. This option falls outside that required set.

 

Question 16

During a security-control classification review, three requirements must be addressed: (1) governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes; (2) control intended to stop an unwanted event before it occurs; and (3) control designed to discover or alert on suspicious activity that has occurred or is occurring. Which THREE choices best satisfy them? Choose THREE.

  1. Corrective control
  2. Detective control
  3. Technical control
  4. Preventive control
  5. Managerial control
  6. Physical control

Correct Answers: B, D, E

Correct Answers

 

 

Answer B is correct because Detective control means a control designed to discover or alert on suspicious activity that has occurred or is occurring. This selection maps directly to one of the named needs. Corrective control addresses a control used to repair, restore, or reduce damage after an undesirable event, so it does not satisfy the same slot.

Answer D is correct because Preventive control means a control intended to stop an unwanted event before it occurs. This option satisfies a specific requirement in the stem; Technical control serves a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism and therefore is not interchangeable with it.

Answer E is correct because Managerial control means a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes. It belongs in the fixed-count answer set because it covers one of the stated requirements. Physical control instead serves a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures and cannot replace this function.

Incorrect Answers

 

Answer A is incorrect because Corrective control means a control used to repair, restore, or reduce damage after an undesirable event. The question requires exactly 3 selections: Preventive control, Managerial control, Detective control. This option falls outside that required set.

Answer C is incorrect because Technical control means a safeguard implemented through technology, such as a firewall rule, endpoint protection setting, or access-control mechanism. The required choices are Preventive control, Managerial control, Detective control. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer F is incorrect because Physical control means a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures. Every answer slot must map to a stated requirement. The correct set is Preventive control, Managerial control, Detective control, so this option cannot replace one of those selections.

 

Question 17

A security engineer is working through a security-control classification review. The immediate requirement is control designed to discover or alert on suspicious activity that has occurred or is occurring. Which choice is the best fit?

  1. Operational control
  2. Deterrent control
  3. Preventive control
  4. Detective control

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Detective control means a control designed to discover or alert on suspicious activity that has occurred or is occurring. The deciding point is functional fit: this option covers the stated need, while Preventive control addresses a control intended to stop an unwanted event before it occurs.

Incorrect Answers

 

Answer A is incorrect because Operational control means a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism. This could be appropriate elsewhere, but the required function is a control designed to discover or alert on suspicious activity that has occurred or is occurring; that makes Detective control the precise choice.

Answer B is incorrect because Deterrent control means a control intended to discourage an attacker or policy violation by increasing perceived risk or consequence. That concept can be valid in another scenario, but this question is testing a control designed to discover or alert on suspicious activity that has occurred or is occurring; Detective control therefore fits the requirement more directly.

Answer C is incorrect because Preventive control means a control intended to stop an unwanted event before it occurs. The concept is valid, but it does not match this stem. The required function is a control designed to discover or alert on suspicious activity that has occurred or is occurring, which maps to Detective control.

 

Question 18

The team is resolving a gap found during a security-control classification review: it needs governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes. Which option is most appropriate?

  1. Managerial control
  2. Detective control
  3. Preventive control
  4. Operational control

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Managerial control means a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes. This matches the requirement as written. Detective control can be valid in another context, but it is used for a control designed to discover or alert on suspicious activity that has occurred or is occurring.

Incorrect Answers

 

Answer B is incorrect because Detective control means a control designed to discover or alert on suspicious activity that has occurred or is occurring. This could be appropriate elsewhere, but the required function is a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes; that makes Managerial control the precise choice.

Answer C is incorrect because Preventive control means a control intended to stop an unwanted event before it occurs. The scenario instead requires a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes, which is why Managerial control is the better answer; this option serves the different function defined above.

Answer D is incorrect because Operational control means a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism. The key mismatch is functional: Managerial control addresses a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes, the need stated by the question.

 

Question 19

A design decision in a security-control classification review must provide safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures. Which choice most directly satisfies that requirement?

  1. Preventive control
  2. Physical control
  3. Managerial control
  4. Corrective control

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Physical control means a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures. This is the precise fit for the scenario. Preventive control serves the different purpose of a control intended to stop an unwanted event before it occurs.

Incorrect Answers

 

Answer A is incorrect because Preventive control means a control intended to stop an unwanted event before it occurs. The concept is valid, but it does not match this stem. The required function is a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures, which maps to Physical control.

Answer C is incorrect because Managerial control means a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes. The scenario instead requires a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures, which is why Physical control is the better answer; this option serves the different function defined above.

Answer D is incorrect because Corrective control means a control used to repair, restore, or reduce damage after an undesirable event. The question is not asking for this function. It is testing a safeguard that protects facilities, equipment, or people through tangible barriers or environmental measures, so Physical control is the stronger fit.

 

Question 20

Which control is intended to stop an unwanted event before it occurs?

  1. Operational control
  2. Preventive control
  3. Managerial control
  4. Detective control

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Preventive control means a control intended to stop an unwanted event before it occurs. This matches the requirement as written. Operational control can be valid in another context, but it is used for a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism.

Incorrect Answers

 

Answer A is incorrect because Operational control refers to a safeguard carried out primarily by people and day-to-day processes rather than by a purely technical mechanism. The question is not asking for this function. It is testing a control intended to stop an unwanted event before it occurs, so Preventive control is the stronger fit.

Answer C is incorrect because Managerial control refers to a governance-oriented safeguard that directs security through policies, risk decisions, oversight, and management processes. The question is not asking for this function. It is testing a control intended to stop an unwanted event before it occurs, so Preventive control is the stronger fit.

Answer D is incorrect because Detective control refers to a control designed to discover or alert on suspicious activity that has occurred or is occurring. That concept can be valid in another scenario, but this question is testing a control intended to stop an unwanted event before it occurs; Preventive control therefore fits the requirement more directly.

Leave a Reply

How It Works

img
Step 1. Choose Exam
on ExamLabs
Download IT Exams Questions & Answers
img
Step 2. Open Exam with
Avanset Exam Simulator
Press here to download VCE Exam Simulator that simulates real exam environment
img
Step 3. Study
& Pass
IT Exams Anywhere, Anytime!