A security administrator is tasked with protecting the confidentiality of data stored on company laptops. The administrator decides to implement full-disk encryption. Which of the following control types BEST describes this implementation?
The correct answer is preventive. Encryption is a technical control that functions as a preventive measure. It actively blocks unauthorized access by rendering data unreadable without the proper key, thereby preventing a data breach. Detective controls, such as log monitoring or intrusion detection systems, are used to identify incidents as they happen or after the fact. Corrective controls, like restoring from a backup, are used to limit the impact of an incident after it has occurred. Deterrent controls, such as warning banners, are intended to discourage potential attackers but do not technically block an action.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are technical controls in cybersecurity?
Open an interactive chat with Bash
What is the difference between preventive and detective controls?
Open an interactive chat with Bash
Can you explain what encryption is and how it works?