Courseiva
Question 356 of 1,013
General Security ConceptseasyMatchingObjective-mapped

SY0-701 General Security Concepts Practice Question

Match each security control type to the best example in a small office environment.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

A firewall blocks inbound remote desktop traffic from the internet.

A SIEM alert notifies analysts after multiple failed logins occur.

A clean backup is restored after malware is removed from a laptop.

A visible warning sign says the area is under video surveillance.

A policy requires users to lock their screens when stepping away.

A jump host is used temporarily until direct administration is safely allowed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Administrative: Security awareness training policy

These matches classify security controls by type: administrative involves policies, technical uses technology, physical secures premises, deterrent discourages violations, preventive stops incidents, and detective identifies occurrences.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Administrative: Security awareness training policy

    Why this is correct

    Security awareness training policy is an administrative control because it governs human behavior through formal organizational rules, procedures, and education. Unlike technical safeguards, it does not directly enforce a rule in software or hardware; instead, it reduces risk by teaching employees to recognize phishing, handle data properly, and follow incident reporting protocols. Administrative controls such as this are the foundation for ensuring that the other control types are used correctly.

  • Technical: Firewall

    Why this is correct

    A firewall is a technical control because it relies on software or hardware mechanisms to inspect and filter network traffic based on predetermined security rules. It actively blocks or permits packets at the network or host level, enforcing access control without requiring human action after it is configured. This distinguishes it from administrative controls like policy documents that depend on people to read and follow them.

  • Physical: Locked server room door

    Why this is correct

    A locked server room door is a physical control because it provides a tangible, real-world barrier that restricts unauthorized access to the facility housing critical systems. Physical controls such as locks, biometric readers, and mantraps are designed to prevent direct contact with hardware, reducing risks like theft, tampering, and environmental damage. They operate independently of user conduct or network settings.

  • Deterrent: Visible security cameras

    Why this is correct

    Visible security cameras are a deterrent control because their primary function is to discourage potential intruders from attempting unauthorized actions by increasing the perceived likelihood of detection. While cameras also serve a detective function by recording incidents, the distinguishing intent of a visible camera is to influence the decision-making of people before they act. Deterrent controls rely on psychological deterrence rather than physically blocking or immediately alerting.

  • Administrative: Firewall

    Why it's wrong here

    Classifying a firewall as an administrative control is incorrect because administrative controls consist of policies, procedures, and training that shape human behavior, not technology. A firewall is a technical control that automates network traffic filtering, whereas an administrative control would be the organization's firewall change-management policy that dictates how rules are approved and reviewed. Confusing the two could lead to overlooking the need for both a properly configured technical device and the human-governance process that oversees it.

  • Physical: Security awareness training policy

    Why it's wrong here

    A security awareness training policy is not a physical control because it has no tangible, material presence and does not protect assets by restricting physical access. Physical controls are hardware or environmental mechanisms such as locks, bollards, and security guards that secure facilities and equipment. Policies and training are administrative controls that mitigate risk through rules and education, not through interaction with the physical world.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: May 17, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.