hardMultiple Choice
200-201 Practice Question: A company's security policy requires that all…
A company's security policy requires that all remote access connections be authenticated using a certificate. Which type of control is this?
⚠ Common exam trap
Cisco often tests the distinction between preventive and deterrent controls, where candidates mistakenly choose deterrent because they think a certificate requirement 'discourages' attackers, but the correct classification is preventive because it technically enforces authentication and blocks access without it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Preventive
Requiring a certificate for remote access authentication enforces a specific identity verification method before granting access. This is a preventive control because it stops unauthorized connections from being established by ensuring only devices with a valid certificate can initiate the session, directly blocking access before any data exchange occurs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Corrective
Why it's wrong here
Corrective controls restore systems after an incident, such as patching or restoring backups, so they do not gate remote connections at authentication time. Certificate authentication is preventive, denying access before a session forms. Corrective measures would be the right choice when remediating damage following a breach rather than enforcing entry requirements.
- ✓
Preventive
Why this is correct
Certificate-based authentication blocks connections lacking a valid certificate before access is granted, satisfying the policy's requirement that all remote access be certificate-authenticated. Preventive controls stop the event occurring, unlike detective or corrective controls that act after an attempt.
- ✗
Detective
Why it's wrong here
Detective controls identify and log events after they occur, so they cannot enforce certificate authentication during connection setup. The policy requires prevention, blocking sessions lacking valid certificates. Detective mechanisms such as IDS or audit logging would be correct where the goal is discovering and recording suspicious activity rather than denying access.
- ✗
Deterrent
Why it's wrong here
A deterrent discourages attackers through visible warnings or penalties, so it neither authenticates nor blocks a connection. Certificate-based authentication is preventive: it stops unauthenticated sessions from being established. Deterrent controls suit scenarios such as signage or login banners that reduce casual intrusion attempts, not enforced access decisions.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.