Courseiva
General Security ConceptseasyMatchingObjective-mapped

SY0-701 General Security Concepts Practice Question

Match each control category to the best example.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

A firewall blocks unauthorized inbound traffic.

A written policy requires manager approval before access is granted.

A badge reader controls entry to a server room.

A SIEM alert notifies the SOC about a failed login pattern.

Restoring a system from a known-good backup after a failure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Preventive: Firewall

Control categories are matched to examples: preventive controls block, detective controls identify, corrective controls fix, deterrent controls discourage, compensating controls provide alternatives, and directive controls set rules.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Preventive: Firewall

    Why this is correct

    A firewall is a preventive control because it actively enforces a security policy at the network boundary, filtering traffic based on rules (source/destination IP, port, and protocol) and dropping unauthorized packets before they can reach internal hosts. This proactive blocking is the essence of prevention—stopping attacks from succeeding—rather than merely observing or recording them. Firewalls can also be stateful, tracking connection states to allow only legitimate return traffic, further cementing their role as a barrier rather than a sensor.

  • Detective: Intrusion Detection System

    Why this is correct

    An Intrusion Detection System (IDS) is a detective control because it passively monitors network traffic or host activity, compares it against signatures or behavioral baselines, and generates alerts when suspicious activity is detected. It does not take direct action to block or mitigate the threat; instead, it provides visibility and forensic data that allow security analysts to identify and respond to intrusions after they have been detected. This monitoring-and-alerting function is characteristic of detective controls, enabling post-hoc awareness rather than anticipatory prevention.

  • Preventive: Intrusion Detection System

    Why it's wrong here

    Classifying an IDS as preventive is a common misconception because, unlike an IPS, an IDS is deployed passively (e.g., via a SPAN port or network tap) and lacks the ability to drop or reject malicious traffic in real time. Even when it identifies an attack, the IDS can only raise an alert, leaving the actual blocking to other mechanisms such as a firewall or an IPS. Since its primary function is observation and detection—not enforcement—it does not satisfy the definition of a preventive control, which must actively impede unauthorized access or actions before they occur.

  • Detective: Firewall

    Why it's wrong here

    A firewall is not a detective control because its core operation is to permit or deny traffic at the perimeter based on static or dynamic rule sets, acting as an access enforcement mechanism rather than an analysis tool. While firewalls do generate logs that can later be examined for security incidents, that logging is secondary to their purpose of preventing unauthorized communication; they do not analyze traffic payloads or independently detect attack patterns like an IDS does. Thus, labeling a firewall as detective conflates its primary preventive function with the ancillary, forensic value of its logs, which does not align with the intent of a detective control.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on SY0-701

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Match each control type to the example that best fits it.

easy
  • A.Preventive: A firewall that blocks unauthorized traffic
  • B.Preventive: A warning sign that deters intruders
  • C.Detective: An intrusion detection system (IDS) that alerts on suspicious activity
  • D.Corrective: Restoring data from backups after a ransomware attack
  • E.Corrective: An IDS that detects an intrusion

Why A: Preventive controls block incidents, detective controls identify them, corrective controls restore after incidents, deterrent controls discourage attacks, compensating controls provide alternative measures, and directive controls mandate behaviors.

Variation 2. Match each security control type to the best example in a small office environment.

easy
  • A.Administrative: Security awareness training policy
  • B.Technical: Firewall
  • C.Physical: Locked server room door
  • D.Deterrent: Visible security cameras
  • E.Administrative: Firewall
  • F.Physical: Security awareness training policy

Why A: These matches classify security controls by type: administrative involves policies, technical uses technology, physical secures premises, deterrent discourages violations, preventive stops incidents, and detective identifies occurrences.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.