A security administrator is reviewing controls that are designed to identify and alert on security incidents after they have already occurred. Which type of security control is being reviewed?
The correct answer is detective controls. These controls are designed to discover security events after they have happened, allowing for an appropriate response. Examples include intrusion detection systems (IDS), security camera footage, and log monitoring.
Preventive controls are proactive and aim to stop an incident from occurring in the first place.
Corrective controls are implemented after an incident is detected to limit the damage and restore systems.
Deterrent controls are meant to discourage potential attackers from attempting an intrusion.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are detective controls?
Open an interactive chat with Bash
What are preventive controls?
Open an interactive chat with Bash
How do detective controls differ from preventive controls?