easyMultiple Select
200-201 Practice Question: Which TWO are examples of technical security…
Which TWO are examples of technical security controls? (Select two.)
⚠ Common exam trap
Cisco often tests the distinction between administrative, physical, and technical controls, and the trap here is that candidates confuse a security policy (a document) or training (a human process) with a technical control, because they are all part of a defense-in-depth strategy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Firewall
A firewall (A) is a technical security control because it is a hardware or software system that enforces network traffic filtering rules (e.g., ACLs, stateful inspection) to prevent unauthorized access, operating directly on the technology rather than on people or procedures. Encryption (E) is likewise a technical control since it uses cryptographic algorithms and keys (e.g., AES, TLS) to protect data confidentiality and integrity at rest or in transit. The unmarked options do not belong because a security policy (B) is an administrative/management control, while security awareness training (C) and background checks (D) are operational/personnel controls that address human behavior rather than technical mechanisms.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Firewall
Why this is correct
A firewall enforces network traffic filtering through predefined rule sets, directly implementing a preventive technical control that restricts unauthorised access. It satisfies the stem's requirement for technical controls because it operates automatically via hardware or software mechanisms, unlike administrative or physical controls such as policies or locks.
- ✗
Security policy
Why it's wrong here
A security policy is a documented administrative control expressing management intent; it enforces nothing technically until implemented by tools. It is tempting because policies underpin every control programme and are frequently listed first in frameworks, yet it would be the right answer only when administrative or managerial controls are requested.
- ✗
Security awareness training
Why it's wrong here
Security awareness training is an administrative control: it modifies human behaviour through education rather than enforcing anything in hardware or software. It is tempting because it genuinely reduces risk and is often mandated alongside technical measures, yet it would be the right answer only when the question asks for administrative or procedural controls.
- ✗
Background checks
Why it's wrong here
Background checks are an administrative control applied to personnel during hiring, not a mechanism enforced by systems. It is tempting because vetting staff genuinely mitigates insider threat and appears in security frameworks, but it would be correct only if the question asked for administrative, not technical, controls.
- ✓
Encryption
Why this is correct
Encryption directly satisfies the stem's requirement for a technical control by using cryptographic algorithms to render data unreadable without the correct key. Unlike administrative or physical safeguards, it operates within the system itself, enforcing confidentiality and integrity of data at rest or in transit, independent of user behaviour or policy.
Visual reference
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.