Courseiva
General Security ConceptshardMultiple ChoiceObjective-mapped

SY0-701 General Security Concepts Practice Question

A records application displays a mandatory notice before login that tells employees exactly which data types they may open, when to lock their screens, and that only assigned work may be processed. The notice is meant to shape behavior before misuse occurs, but it does not technically block any action. Which control type is this notice?

⚠ Common exam trap

Many exam-takers confuse a directive control with a deterrent control because both involve warnings, but a deterrent control explicitly threatens consequences or punishment to discourage action, whereas a directive control simply instructs on proper behavior without implying enforcement or penalties.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Directive control

A directive control is designed to guide or mandate behavior through policies, procedures, or notices without enforcing technical restrictions. This notice explicitly tells employees which data types they may open, when to lock screens, and that only assigned work may be processed, shaping behavior before misuse occurs without blocking any action. It aligns with the definition of a directive control as it provides rules and expectations rather than preventing or deterring actions through technical means.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Directive control

    Why this is correct

    The notice provides required guidance and expectations before users access the system. It tells them what behavior is allowed and how they should act, but it does not enforce the rule technically. That makes it a directive control because it directs user behavior through instructions and stated requirements rather than by blocking actions.

  • Preventive control

    Why it's wrong here

    A preventive control is a technical or physical mechanism that actively blocks an action before it can occur, such as an access control list denying write permissions, role-based restrictions, or an application firewall rejecting a malicious request. In this scenario, the mandatory notice does not stop or block any user behavior — if the user clicks through, they are still granted access, so the control is not enforcing a rule in real time. Because the notice itself has no enforcement capability, classifying it as preventive would overstate its function.

  • Deterrent control

    Why it's wrong here

    A deterrent control discourages users from performing an action by communicating the risk of consequences, such as a warning that all activity is logged or that violations will result in prosecution or termination. Although a mandatory notice may have some deterrent flavor if it mentions sanctions, the question's notice is primarily designed to establish expected behavior and usage policies, not to create fear of punishment. In this context, the notice is not structured as a threat or consequence-based warning; it is a set of rules and guidance, which aligns with directive control rather than deterrent.

  • Detective control

    Why it's wrong here

    Detective controls are reactive measures that identify and report on events after they have occurred, such as security information and event management alerts, audit logs, or file integrity monitoring. A notice displayed before access cannot detect anything because it has no sensor mechanism and operates prior to any user action — it does not record, analyze, or generate alerts. Since the mandatory notice is a pre-access statement, it lacks the after-the-fact observation and analysis characteristic of detective controls.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.