Question

Difficulty: EasySecurity Control Categories and Types

Match each organizational security measure to its corresponding functional control type according to CompTIA Security+ standards.

  • Restoring corrupted system configurations from a known clean backup following a malware incidentCorrective Control
  • Publishing an enterprise acceptable use policy that defines mandatory employee security responsibilitiesDirective Control
  • Configuring a network firewall rule to block unauthorized inbound connection attemptsPreventive Control
  • Deploying a network intrusion detection system (NIDS) to identify anomalous traffic and generate alertsDetective Control

Answer

Restoring from backups matches Corrective Control; Publishing acceptable use policy matches Directive Control; Configuring firewall rules matches Preventive Control; Deploying NIDS alerts matches Detective Control.
Each security control implementation aligns directly with standard CompTIA Security+ functional control classifications: restoring from backups fixes damage after an incident (Corrective), policies set required conduct rules (Directive), firewalls actively block threats before entry (Preventive), and intrusion detection systems discover and alert on suspicious activity (Detective).

Step-by-Step Solution

1
Analyze the operational goal of restoring system configurations from backups after an attack.
Identified as a corrective action designed to reverse impact and restore operational capability.
Corrective controls focus on mitigation and recovery after a security incident has taken place.
2
Evaluate the administrative nature of publishing an acceptable use policy.
Identified as a policy-driven directive establishing mandatory rules and expectations.
Directive controls prescribe required behavior and compliance regulations across an organization.
3
Examine the technical enforcement of a firewall rule blocking unauthorized inbound traffic.
Identified as a preventive measure designed to stop unauthorized actions before they happen.
Preventive controls proactively block security breaches or policy violations from occurring.
4
Determine the role of a network intrusion detection system generating alerts.
Identified as a detective measure focused on observing and signaling active or historical anomalies.
Detective controls discover and flag unauthorized or unexpected activities during or post-execution.

Key Concept

Functional Types of Security Controls
Rate this question