An enterprise security team is auditing organizational controls against the CompTIA Security+ framework. Match each implemented security control on the left to its corresponding dual-axis classification (Control Category / Functional Type) on the right.
- Deploying an inline Web Application Firewall (WAF) to drop malicious HTTP payloadsTechnical / Preventive
- Conducting enterprise risk assessments and updating corporate information security policiesManagerial / Directive
Answer
The controls are correctly matched as follows: Inline Web Application Firewall matches Technical / Preventive; Enterprise risk assessments and security policy updates match Managerial / Directive; Automated endpoint re-imaging scripts match Technical / Corrective; Biometric retina scanners on facility doors match Physical / Preventive.
Each security mechanism aligns with its specific framework classification: Technical controls utilize hardware/software technologies, Managerial controls establish administrative policies and risk frameworks, and Physical controls protect facilities and tangible assets. Functionally, Preventive controls impede security events, Directive controls specify mandatory actions, and Corrective controls repair damage or restore functionality.
Step-by-Step Solution
Key Concept
Security Control Categories and Types