Question

Difficulty: MediumSecurity Control Categories and Types

A security analyst is classifying enterprise defense mechanisms according to CompTIA Security+ implementation categories (Technical, Managerial, Operational, Physical) and functional control types (Preventive, Deterrent, Detective, Corrective, Compensating, Directive). Match each security scenario on the left with its primary dual-axis security control classification on the right.

  • Deploying an automated web application firewall (WAF) to inspect and block malicious payload traffic before reaching internal web serversTechnical / Preventive
  • Posting prominent warning notices detailing legal prosecution along the perimeter fence of a secure datacenterPhysical / Deterrent
  • Performing manual data restoration procedures from clean off-site backups following a ransomware compromiseOperational / Corrective
  • Establishing a corporate security administrative policy requiring employees to sign an Acceptable Use Policy (AUP) during onboardingManagerial / Directive

Answer

Web Application Firewall (WAF) filtering maps to Technical / Preventive; Warning notices along the perimeter fence map to Physical / Deterrent; Data restoration from backups maps to Operational / Corrective; Acceptable Use Policy (AUP) onboarding requirement maps to Managerial / Directive.
Each mechanism aligns precisely with standard CompTIA Security+ SY0-701 definitions: WAF operates logically in software to prevent attacks (Technical/Preventive); perimeter signs are tangible physical measures designed to deter trespassers (Physical/Deterrent); restoring backups requires personnel operational procedures to fix post-attack damage (Operational/Corrective); and AUP requirements represent managerial policy governance that directs compliant user behavior (Managerial/Directive).

Step-by-Step Solution

1
Analyze the web application firewall (WAF) deployment.
Identified as a logic/software control (Technical) that blocks attack vectors before impact (Preventive).
Technical controls utilize hardware/software mechanisms, while preventive controls proactively halt threat execution.
2
Analyze the warning signage along the perimeter fence.
Identified as a tangible real-world control (Physical) designed to discourage intruders (Deterrent).
Physical controls exist in the physical environment, while deterrent controls aim to dissuade potential attackers through psychological disincentives.
3
Analyze the data restoration process from backups post-ransomware.
Identified as a human-driven operational procedure (Operational) that restores system state after an incident (Corrective).
Operational controls depend on day-to-day human execution and workflows, while corrective controls mitigate damage and restore operations.
4
Analyze the onboarding Acceptable Use Policy (AUP) requirement.
Identified as administrative governance (Managerial) enforcing mandatory behavior (Directive).
Managerial controls center on security governance, risk assessment, and policies, while directive controls mandate specific conduct.

Key Concept

CompTIA Security+ dual-axis classification framework categorizes security controls by implementation method (Technical, Managerial, Operational, Physical) and functional purpose (Preventive, Deterrent, Detective, Corrective, Compensating, Directive).
Rate this question