Courseiva
General Security ConceptseasyMatchingObjective-mapped

SY0-701 General Security Concepts Practice Question

Match each control type to the example that best fits it.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

MFA is required before a user can open the email system.

File integrity monitoring alerts when a protected file changes.

A compromised laptop is reimaged from a standard build.

A login banner warns that activity is monitored and audited.

A procedure tells staff to report lost devices within one hour.

Extra logging is enabled while a missing patch is being scheduled.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Preventive: A firewall that blocks unauthorized traffic

Preventive controls block incidents, detective controls identify them, corrective controls restore after incidents, deterrent controls discourage attacks, compensating controls provide alternative measures, and directive controls mandate behaviors.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Preventive: A firewall that blocks unauthorized traffic

    Why this is correct

    A firewall configured with a default-deny policy exemplifies a preventive control because it actively blocks unauthorized traffic before it can reach protected systems. By inspecting packets and enforcing rule sets at the network boundary, it stops malicious or non-compliant connections at the point of entry. This differs from other control categories because preventive controls aim to thwart incidents entirely rather than merely detect or recover from them.

  • Preventive: A warning sign that deters intruders

    Why it's wrong here

    A warning sign is a deterrent control, not a preventive one, because it relies on influencing the individual's decision-making rather than physically or technically blocking an action. Preventive controls, such as fences or access-control lists, actively stop an intrusion attempt, whereas deterrent controls only discourage it by introducing perceived risk or consequences. The sign does not create a technical barrier; it simply makes an individual less likely to attempt an attack.

  • Detective: An intrusion detection system (IDS) that alerts on suspicious activity

    Why this is correct

    An intrusion detection system (IDS) is a detective control because it passively observes network traffic or system activity and generates alerts when it matches known attack signatures or behavioral anomalies. Unlike a firewall, it has no enforcement capability and cannot block or drop packets; it only reports suspicious events so that security personnel can take action. This monitoring and alerting function provides visibility into threats that have already appeared or are ongoing, which is the essence of detective controls.

  • Corrective: Restoring data from backups after a ransomware attack

    Why this is correct

    Restoring data from backups after a ransomware attack is a corrective control because it focuses on returning the affected systems to their normal operating state after an incident has occurred. Corrective controls are executed in response to a detected compromise, with the goal of repairing damage, eliminating the malicious payload, and minimizing downtime. This action reverses the effects of the ransomware and restores business continuity, distinguishing it from detective or preventive measures.

  • Corrective: An IDS that detects an intrusion

    Why it's wrong here

    Classifying an IDS as corrective is incorrect because the IDS's role is to identify and report suspicious activity, which is a detective function. Corrective controls only come into play after a threat has been detected and are designed to remedy the situation—for example, wiping a compromised host and reinstalling the operating system. The detection itself does not restore operations or repair damage; it merely triggers the need for corrective controls.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SY0-701

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Match each control category to the best example.

easy
  • A.Preventive: Firewall
  • B.Detective: Intrusion Detection System
  • C.Preventive: Intrusion Detection System
  • D.Detective: Firewall

Why A: Control categories are matched to examples: preventive controls block, detective controls identify, corrective controls fix, deterrent controls discourage, compensating controls provide alternatives, and directive controls set rules.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.