SY0-701 General Security Concepts Practice Question
The security team configures the badge system so employees must present both a badge and a PIN before entering the data center. The access logs are reviewed weekly for failed attempts. Which pair of control types best describes these measures?
⚠ Common exam trap
Many candidates confuse detective controls (which identify past events) with corrective controls (which fix issues), or misclassifying administrative controls (like policy reviews) as physical controls, leading candidates to pick option D.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Preventive and detective, because one measure blocks access and the other identifies suspicious activity.
The badge and PIN requirement is a preventive control that blocks unauthorized access to the data center, while the weekly review of access logs is a detective control that identifies suspicious activity after the fact. Preventive controls stop incidents before they occur, and detective controls discover violations that have already happened, making this pair the best fit for the described measures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Preventive and detective, because one measure blocks access and the other identifies suspicious activity.
Why this is correct
Requiring a badge and PIN is preventive because it attempts to stop unauthorized entry before it happens. Reviewing access logs is detective because it helps identify misuse or attempted misuse after the fact. Together, these controls reduce the likelihood of unauthorized entry while also giving the security team visibility into failed or unusual access attempts. This is a practical layered approach.
- ✗
Corrective and recovery, because the logs can restore access after a badge failure.
Why it's wrong here
Corrective and recovery controls are designed to restore the system or data to a known good state after a security incident, such as rebuilding a compromised server or restoring from backup. Merely reviewing access logs after a badge failure neither repairs damage nor returns the system to operational status; instead, log analysis is a detective function because it reveals suspicious activity or failures after they have occurred. The scenario describes a failure of authentication, not an active compromise, and logs cannot reverse or remediate that event.
- ✗
Deterrent and compensating, because the PIN discourages attackers and the logs replace the badge reader.
Why it's wrong here
A deterrent control aims to discourage an attacker through the perception of consequences, such as warning signage or visible cameras; the PIN is not primarily a deterrent because it is a knowledge-based authentication factor that directly enforces access control. A compensating control provides an alternative security measure when the primary control cannot be implemented, but access logs do not replace the function of the badge reader—they only record the events that the badge reader processes. The logs are detective, not compensating, because they provide visibility into activity rather than substituting for physical access enforcement.
- ✗
Administrative and physical, because the weekly review and the badge reader are both physical measures.
Why it's wrong here
This option confuses the type of control (administrative, physical, technical) with the function of the control (preventive, detective, corrective). The weekly review of access logs is an administrative control—a policy-driven procedure —but its function is detective because it identifies suspicious patterns or unauthorized attempts, not because it uses a physical device. The badge reader and PIN are physical/technical preventive controls that block entry; labeling both as 'physical' because the badge reader is hardware ignores the fact that the review is a managerial, log-based oversight activity.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.