Courseiva
hardMultiple Choice

200-201 Practice Question: A company's security policy requires that all…

A company's security policy requires that all remote access connections be authenticated using a certificate. Which type of control is this?

⚠ Common exam trap

Cisco often tests the distinction between preventive and deterrent controls, where candidates mistakenly choose deterrent because they think a certificate requirement 'discourages' attackers, but the correct classification is preventive because it technically enforces authentication and blocks access without it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Preventive

Requiring a certificate for remote access authentication enforces a specific identity verification method before granting access. This is a preventive control because it stops unauthorized connections from being established by ensuring only devices with a valid certificate can initiate the session, directly blocking access before any data exchange occurs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Corrective

    Why it's wrong here

    Corrective controls restore systems after an incident, such as patching or restoring backups, so they do not gate remote connections at authentication time. Certificate authentication is preventive, denying access before a session forms. Corrective measures would be the right choice when remediating damage following a breach rather than enforcing entry requirements.

  • ✓

    Preventive

    Why this is correct

    Certificate-based authentication blocks connections lacking a valid certificate before access is granted, satisfying the policy's requirement that all remote access be certificate-authenticated. Preventive controls stop the event occurring, unlike detective or corrective controls that act after an attempt.

  • ✗

    Detective

    Why it's wrong here

    Detective controls identify and log events after they occur, so they cannot enforce certificate authentication during connection setup. The policy requires prevention, blocking sessions lacking valid certificates. Detective mechanisms such as IDS or audit logging would be correct where the goal is discovering and recording suspicious activity rather than denying access.

  • ✗

    Deterrent

    Why it's wrong here

    A deterrent discourages attackers through visible warnings or penalties, so it neither authenticates nor blocks a connection. Certificate-based authentication is preventive: it stops unauthenticated sessions from being established. Deterrent controls suit scenarios such as signage or login banners that reduce casual intrusion attempts, not enforced access decisions.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.