An organization is evaluating its security architecture following a comprehensive risk assessment. Match each enterprise security measure to its correct dual-axis classification (Category and Functional Type) according to CompTIA Security+ standards.
- Mandatory annual security awareness training enforcing mandatory employee compliance with acceptable use policiesManagerial Category / Directive Type
- An automated endpoint script that isolates a compromised workstation from the subnet upon detecting command-and-control beaconingTechnical Category / Corrective Type
- A biometric access-controlled mantrap entry system protecting the perimeter of a primary data centerPhysical Category / Preventive Type
- A segmented jump server with heightened logging deployed temporarily for administrative access while legacy servers undergo MFA retrofittingTechnical Category / Compensating Type
Cevap
1. Annual awareness training maps to Managerial Category / Directive Type. 2. Automated host isolation script maps to Technical Category / Corrective Type. 3. Biometric mantrap system maps to Physical Category / Preventive Type. 4. Segmented jump server fallback maps to Technical Category / Compensating Type.
Each security control is accurately categorized by implementation method (Managerial, Technical, Physical) and functional purpose (Directive, Corrective, Preventive, Compensating). Policy sign-offs direct behavior (Managerial/Directive); host isolation mitigates ongoing attack damage (Technical/Corrective); physical mantraps prevent unauthorized entry (Physical/Preventive); and jump boxes act as substitute technical measures for legacy systems (Technical/Compensating).
Adım Adım Çözüm
Anahtar Kavram
Security Control Categories and Functional Types