Courseiva
Question 1,011 of 1,013
General Security ConceptseasyMatchingObjective-mapped

SY0-701 General Security Concepts Practice Question

Match each control type to the best description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Stops a threat before it succeeds.

Identifies an event after or while it is happening.

Fixes a problem after it has occurred.

Discourages an attacker from trying.

Provides an alternate safeguard when the preferred control is not possible.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Administrative: Policies, procedures, and rules

Control types are categorized by nature: administrative involves rules, technical involves technology, physical involves tangible barriers, logical involves software-based access, operational involves processes, and legal/regulatory involves compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Administrative: Policies, procedures, and rules

    Why this is correct

    Administrative controls are management-driven policies, procedures, and rules that define expected behavior and establish the governance framework for security. They are often called directive controls because they guide human conduct rather than enforce it through hardware or software mechanisms. Examples include security awareness training, access control policies, incident response plans, and background checks. These controls form the foundation upon which technical and physical controls are selected and implemented.

  • Technical: Physical locks and fences

    Why it's wrong here

    Technical controls are implemented through technology components such as firewalls, encryption, intrusion detection systems, or access control lists. Physical locks and fences are tangible barriers that restrict physical access to a facility or asset, so they fall under physical controls, not technical. While both types enforce access restriction, technical controls operate in the digital domain (data, networks, software), whereas locks and fences work in the physical environment. This misclassification is common because both are implemented to prevent unauthorized access but through different mechanisms.

  • Physical: Tangible barriers like fences

    Why this is correct

    Physical controls are tangible, hardware-based measures designed to protect assets from physical harm or unauthorized physical access. Examples include fences, bollards, guards, locks, and closed-circuit television systems. Their primary purpose is to deter, delay, or deny direct contact with protected resources, often serving as the first layer in a defense-in-depth strategy. Unlike technical controls, they do not rely on software or network logic; they operate entirely in the physical world.

  • Logical: Hardware security modules

    Why it's wrong here

    Logical controls are implemented in software, data, or abstract rules, such as user access permissions, encryption algorithms, and database schemas. Hardware security modules (HSMs) are specialized physical devices that securely generate, store, and manage cryptographic keys; they are categorized as technical or physical controls because they involve tamper-resistant hardware. While HSMs support logical functions like key management, calling them 'logical' overlooks the dedicated hardware component and the physical security they provide. The best classification for an HSM is technical (or sometimes physical), not logical, owing to its tangible architecture.

  • Operational: Software-based authentication

    Why it's wrong here

    Operational controls are the day-to-day processes and human activities that keep security functioning, such as incident response procedures, log monitoring, and patch management. Software-based authentication, such as a password prompt or a software token for multi-factor authentication, relies on algorithmic verification and is a logical/technical control. The distinction lies in the mechanism: operational controls depend on human behavior and routines, whereas software-based authentication executes via code. Mislabeling it as operational confuses the 'how' (technology) with the 'who' (people performing ongoing tasks).

  • Legal/Regulatory: Compliance with laws

    Why this is correct

    Legal/regulatory controls are externally imposed requirements that organizations must satisfy to meet statutory, regulatory, or contractual obligations. Examples include compliance with GDPR, HIPAA, PCI-DSS, and SOX, which are enforced by government bodies or industry auditors. Unlike administrative controls, which are internally chosen policies, legal/regulatory controls carry the force of law and failure to comply can result in fines, legal action, or revocation of operating privileges. They shape administrative policies but are distinct because their mandate originates outside the organization.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SY0-701

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Match each security control type to the best example in a small office environment.

easy
  • A.Administrative: Security awareness training policy
  • B.Technical: Firewall
  • C.Physical: Locked server room door
  • D.Deterrent: Visible security cameras
  • E.Administrative: Firewall
  • F.Physical: Security awareness training policy

Why A: These matches classify security controls by type: administrative involves policies, technical uses technology, physical secures premises, deterrent discourages violations, preventive stops incidents, and detective identifies occurrences.

Last reviewed: May 2, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.