Question

Difficulty: MediumSecurity Control Categories and Types

An organization updates its enterprise defense baseline to satisfy compliance requirements. As part of this initiative, the security team deploys an inline Network Intrusion Prevention System (NIPS) to automatically drop unauthorized network traffic, and publishes an updated Acceptable Use Policy (AUP) mandating clean desk and screen lock procedures for all staff members.

Which of the following statements correctly classify these security controls according to CompTIA Security+ categories and functional types? (Select TWO.)

  1. The inline NIPS is classified as a technical category control with a preventive functional type.Answer
  2. B
    The inline NIPS is classified as an operational category control with a detective functional type.
  3. The Acceptable Use Policy is classified as a managerial category control with a directive functional type.Answer
  4. D
    The Acceptable Use Policy is classified as a physical category control with a compensating functional type.

Answer

The inline Network Intrusion Prevention System (NIPS) is a technical category control with a preventive functional type, and the Acceptable Use Policy (AUP) is a managerial category control with a directive functional type.
The inline Network Intrusion Prevention System (NIPS) relies on software and hardware mechanisms to automatically inspect and drop unauthorized traffic before it breaches the perimeter, classifying it as a technical control with a preventive functional type. The Acceptable Use Policy (AUP) is an administrative document created by leadership to mandate user behavior and compliance, classifying it as a managerial control with a directive functional type.

Step-by-Step Solution

1
Analyze the inline NIPS mechanism.
It relies on hardware/software technology to function (Technical category) and actively stops unauthorized packets before entering the network (Preventive type).
Technical controls execute via automated hardware/software logic, while preventive controls actively inhibit security policy violations.
2
Analyze the Acceptable Use Policy (AUP).
It is an administrative governance document established by leadership (Managerial category) that mandates required employee compliance and behavior (Directive type).
Managerial controls focus on policy, oversight, and governance, while directive controls instruct individuals on mandatory operational practices.

Key Concept

Classification of security mechanisms by primary category (technical, managerial, operational, physical) and functional type (preventive, detective, corrective, deterrent, compensating, directive).
Rate this question