SY0-701 General Security Concepts Practice Question
A company is enhancing its network security posture. The security team deploys a system that passively monitors network traffic, analyzes packets for signs of malicious activity, and generates alerts when suspicious patterns are detected. This system does not actively block or modify any traffic. Which type of security control does this system BEST represent?
⚠ Common exam trap
Many candidates confuse an Intrusion Detection System (IDS) with an Intrusion Prevention System (IPS), mistakenly selecting 'preventive control' because they think any security tool that detects threats also blocks them, but the question explicitly states the system does not block or modify traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Detective control
This system is a detective control because it passively monitors network traffic, analyzes packets for signs of malicious activity, and generates alerts without actively blocking or modifying traffic. Detective controls are designed to identify and report security incidents after they occur or as they happen, which aligns with the described behavior of an Intrusion Detection System (IDS). Unlike preventive controls, it does not enforce policy or stop threats in real time.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Preventive control
Why it's wrong here
Preventive controls are designed to stop a security incident before it can succeed by enforcing policy in real time, typically through inline mechanisms such as firewalls, access control lists, or authentication barriers that block unauthorized access. An intrusion detection system (IDS) is deliberately not an inline device; it receives a copy of traffic or log data and analyzes it passively, and it has no capability to drop sessions, deny requests, or halt malicious activity on its own. Because the system described only 'passively monitors and generates alerts,' it cannot be a preventive control; it lacks the enforcement mechanism required to actually block an attack.
When this WOULD be correct
A firewall configured with rules to block unauthorized inbound traffic, or an intrusion prevention system (IPS) that automatically drops malicious packets, would be a preventive control.
- ✓
Detective control
Why this is correct
Correct. A detective control identifies and logs security events after they happen or in real time. The described system passively monitors and generates alerts, which is the hallmark of a detective control like an IDS.
- ✗
Corrective control
Why it's wrong here
Corrective controls are reactive measures that execute after an incident has occurred, focusing on restoring a system to its secure state, repairing damage, or remediating the underlying vulnerability—for example, patching software, restoring from backup, or containing a compromised host. An IDS, including the one described, plays a role in the detection phase by logging events and raising alerts, but it does not take any automated or manual action to fix or recover from the security event. Since the system does not perform restoration or remediation, it cannot be considered a corrective control; it is the spark that triggers the corrective process, not the corrective process itself.
When this WOULD be correct
A question describing a system that automatically quarantines infected endpoints, restores clean backups, or patches vulnerabilities after detecting an intrusion would make corrective control the correct answer.
- ✗
Deterrent control
Why it's wrong here
A deterrent control is intended to influence an adversary's cost-benefit analysis before an attack ever occurs, using visible security measures or warnings to make an intrusion seem too risky or unprofitable. While an IDS might be visible on the network or include a banner, its core function is to passively observe traffic and generate alerts when suspicious activity is detected. The classification of a control is based on its primary functional purpose, and because the described system does not actively dissuade or discourage an attacker—it simply watches and reports—it falls outside the deterrent category.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.
✓Detective controlCorrect answer▾
Why this is correct
Correct. A detective control identifies and logs security events after they happen or in real time. The described system passively monitors and generates alerts, which is the hallmark of a detective control like an IDS.
✗Preventive controlWrong answer — click to see why▾
Why this is wrong here
The system described only monitors and alerts; it does not actively block or prevent malicious activity, so it is not a preventive control.
★ When this WOULD be the correct answer
A firewall configured with rules to block unauthorized inbound traffic, or an intrusion prevention system (IPS) that automatically drops malicious packets, would be a preventive control.
Why candidates choose this
Candidates may confuse detection with prevention, thinking that generating alerts helps prevent attacks, but prevention requires active blocking.
✗Corrective controlWrong answer — click to see why▾
Why this is wrong here
The system described is passive and only monitors traffic without taking action to remediate or reverse damage, which is the purpose of corrective controls. Corrective controls are applied after an incident to restore systems, not to detect ongoing threats.
★ When this WOULD be the correct answer
A question describing a system that automatically quarantines infected endpoints, restores clean backups, or patches vulnerabilities after detecting an intrusion would make corrective control the correct answer.
Why candidates choose this
Candidates may confuse detective and corrective controls because both involve response to incidents; however, corrective controls actively fix or mitigate damage, whereas detective controls only identify and alert.
Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Security Controls
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Security posture
An organization's overall cybersecurity strength, including policies, controls, and readiness to defend against and respond to threats.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.