ISC2 CC Security Operations Practice Question
A company wants to reduce the risk of malware spreading from employee workstations to critical servers. The security team proposes placing firewalls between network segments and restricting traffic to only required ports and protocols. Which security control category does this approach primarily represent?
⚠ Common exam trap
The trap here is assuming segmentation is administrative because a policy may mandate it, when the actual enforcement mechanism is a technical device applying rules to traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Technical control
Network segmentation enforced by firewalls and port restrictions is implemented through technology, making it a technical control. It limits how malware can move laterally from workstations to critical servers by permitting only required traffic. Unlike administrative controls that depend on policies and training, or physical controls that restrict access to facilities, this approach enforces boundaries automatically. Segmenting systems and minimizing allowed protocols reduces the attack surface and contains incidents.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Administrative control
Why it's wrong here
Administrative controls are policies, procedures, and training that guide human behavior, such as acceptable use policies or security awareness programs. Segmenting a network with firewalls and port restrictions is a technical implementation, not a written rule or process. While policies may require segmentation, the control itself operates through technology that enforces traffic rules automatically rather than relying on people following instructions.
- ✗
Physical control
Why it's wrong here
Physical controls protect facilities and hardware, such as locks, guards, and badge readers. Network segmentation uses firewall rules and switch configuration to limit logical communication between systems, not to restrict physical access. The proposed approach affects how data flows between segments regardless of where the equipment sits, so it does not fall under physical safeguards even though both reduce overall risk.
- ✓
Technical control
Why this is correct
Technical controls are implemented through systems and devices, such as firewalls, intrusion prevention systems, and access control lists. Placing firewalls between segments and permitting only necessary ports and protocols is a technical enforcement mechanism. It limits lateral movement automatically based on configured rules, which is characteristic of a technical rather than administrative or physical safeguard, and it directly reduces the blast radius of an infected workstation.
- ✗
Compensating control
Why it's wrong here
A compensating control substitutes for a primary control that cannot be implemented as intended. Network segmentation here is a deliberate, primary design choice to limit malware spread, not a workaround for some unavailable safeguard. Labeling it compensating mischaracterizes its role. While segmentation could serve as a compensating measure in a specific scenario, nothing in this situation indicates an alternative control is being replaced.
Go deeper
Related to this question
Learn chapter
Network Security Components and Controls
Key term
Technical control
A technical control is a security mechanism implemented through hardware, software, or firmware that protects the confidentiality, integrity, and availability of IT systems and data.
Key term
Network segmentation
Network segmentation is the practice of dividing a computer network into smaller, isolated parts to improve performance, contain security threats, and simplify management.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.