Soru

Zorluk: ZorSecurity Control Categories and Types

An organization is evaluating its security architecture following a comprehensive risk assessment. Match each enterprise security measure to its correct dual-axis classification (Category and Functional Type) according to CompTIA Security+ standards.

  • Mandatory annual security awareness training enforcing mandatory employee compliance with acceptable use policiesManagerial Category / Directive Type
  • An automated endpoint script that isolates a compromised workstation from the subnet upon detecting command-and-control beaconingTechnical Category / Corrective Type
  • A biometric access-controlled mantrap entry system protecting the perimeter of a primary data centerPhysical Category / Preventive Type
  • A segmented jump server with heightened logging deployed temporarily for administrative access while legacy servers undergo MFA retrofittingTechnical Category / Compensating Type

Cevap

1. Annual awareness training maps to Managerial Category / Directive Type. 2. Automated host isolation script maps to Technical Category / Corrective Type. 3. Biometric mantrap system maps to Physical Category / Preventive Type. 4. Segmented jump server fallback maps to Technical Category / Compensating Type.
Each security control is accurately categorized by implementation method (Managerial, Technical, Physical) and functional purpose (Directive, Corrective, Preventive, Compensating). Policy sign-offs direct behavior (Managerial/Directive); host isolation mitigates ongoing attack damage (Technical/Corrective); physical mantraps prevent unauthorized entry (Physical/Preventive); and jump boxes act as substitute technical measures for legacy systems (Technical/Compensating).

Adım Adım Çözüm

1
Analyze the primary category (Managerial, Operational, Technical, Physical) for each mechanism based on its underlying operational domain.
Training/policy is Managerial; automated endpoint script is Technical; mantrap facility hardware is Physical; jump server infrastructure is Technical.
Control categories are determined by how the control is implemented—via policy/governance, physical assets, human operations, or system logic.
2
Determine the functional goal (Preventive, Deterrent, Detective, Corrective, Compensating, Directive) for each mechanism.
Training directs compliance (Directive); isolation remediates active threat impact (Corrective); mantraps block unauthorized access (Preventive); jump server replaces missing native controls (Compensating).
Functional types define the operational intent relative to security incidents (before, during, after, or in place of primary controls).
3
Pair each implementation with its corresponding dual-axis category and functional type classification.
All four pairings are established cleanly based on CompTIA Security+ SY0-701 standard taxonomy definitions.
Correct mapping requires aligning both the category axis and functional type axis simultaneously.

Anahtar Kavram

Security Control Categories and Functional Types
Bu soruyu puanla