Question

Difficulty: MediumSecurity Control Categories and Types

An enterprise security team is categorizing various security controls according to CompTIA Security+ framework classifications. Match each security control implementation on the left with its corresponding control category and functional type on the right.

  • Developing and enforcing an enterprise Information Security Policy that specifies mandatory data handling rules.Managerial Category / Directive Type
  • Deploying web application firewalls (WAF) to automatically block SQL injection attempts against web applications.Technical Category / Preventive Type
  • Restoring system configurations and databases from isolated backups following a malware encryption incident.Operational Category / Corrective Type
  • Installing high-visibility warning signs along the perimeter fencing of a secure data center facility.Physical Category / Deterrent Type

Answer

Developing security policies matches Managerial Category / Directive Type; Web application firewalls match Technical Category / Preventive Type; Restoring systems from backups matches Operational Category / Corrective Type; Installing perimeter warning signs matches Physical Category / Deterrent Type.
Each control is correctly classified based on CompTIA Security+ standards: Enterprise policies are governance-driven (Managerial) rules (Directive); WAFs are technology safeguards (Technical) that proactively block attacks (Preventive); data restoration is a procedural task (Operational) that remedies post-incident damage (Corrective); and physical warning signs are tangible facility measures (Physical) meant to discourage intruders (Deterrent).

Step-by-Step Solution

1
Analyze control implementation mechanisms to determine their primary category (Managerial, Technical, Operational, or Physical).
Policies reflect Managerial governance; WAFs reflect Technical software; backup restoration reflects Operational procedures; warning signs reflect Physical facility controls.
Control categories are defined by how the security control is implemented and administered.
2
Determine the functional goal of each control (Preventive, Deterrent, Detective, Corrective, Compensating, or Directive).
Policies direct behavior; WAFs prevent attacks; backups correct damage post-incident; warning signs deter potential intruders.
Functional types are classified by the control's purpose in the security incident lifecycle.
3
Combine the identified category and functional type for each security control to complete the matching pairs.
All four controls are accurately mapped to their unique dual-axis classifications.
Each control satisfies exactly one category and one functional type combination provided.

Key Concept

Dual-axis classification of security controls by category (Managerial, Technical, Operational, Physical) and functional type (Preventive, Deterrent, Detective, Corrective, Compensating, Directive).
Rate this question