Courseiva

CRISC Risk Response and Reporting Practice Question

An organization has implemented a new firewall rule to block malicious IP addresses. This is an example of which type of control?

⚠ Common exam trap

Many candidates confuse preventive controls with detective controls, as candidates often think of firewalls as 'detecting' threats, but the key distinction is that a firewall rule actively blocks (prevents) traffic, not merely logs or alerts on it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Preventive control

A firewall rule that blocks malicious IP addresses is a preventive control because it proactively stops unauthorized traffic before it can reach the internal network. By filtering packets based on source IP addresses, the firewall enforces access control policies at the network layer, preventing potential attacks from ever being initiated. This aligns with the CRISC definition of preventive controls, which are designed to avoid or deter undesirable events.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Directive control

    Why it's wrong here

    A directive control establishes policy, procedures or guidance that steers behaviour, such as an acceptable-use policy; it does not itself block traffic. It is tempting because rules encode intent, and it would be correct for mandating security requirements, but the firewall rule enforces prevention technically.

  • ✓

    Preventive control

    Why this is correct

    Blocking malicious IP addresses stops the traffic before it reaches the target, so the control acts on the threat event itself rather than detecting it afterwards or repairing damage. Prevention is the defining characteristic, distinguishing it from detective controls such as logging and corrective controls such as restoration.

  • ✗

    Corrective control

    Why it's wrong here

    Blocking malicious IP addresses prevents an event from occurring, which is preventive, not corrective. Corrective controls restore systems after an incident, such as backups or patch rollback. The rule acts before impact, so it belongs to the preventive category.

  • ✗

    Detective control

    Why it's wrong here

    A detective control identifies or records events after they occur, such as logging or monitoring; blocking traffic prevents the action outright. It is tempting because firewall logs do detect activity, and it would be correct for intrusion detection or log review, but the rule itself is preventive.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.