Courseiva
easyMultiple Select

ISC2 CC Practice Question: Which TWO of the following are examples of…

Which TWO of the following are examples of administrative security controls?

⚠ Common exam trap

The trap is misclassifying biometrics as administrative because it involves a 'system'; biometrics are physical controls, and only policies/procedures and training are administrative here.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security policies and procedures

Administrative security controls are the management-oriented, people-and-process controls that govern how an organization operates, so D (Security policies and procedures) is correct because written policies, standards, and procedures define required behavior and are classic administrative controls. E (Security awareness training) is also correct because it is a management-driven program that educates personnel on policy and safe practices, which is administrative in nature. By contrast, A (Firewall rule sets) is a technical/logical control implemented in network devices, B (Data encryption) is a technical control that protects data confidentiality via cryptographic algorithms, and C (Biometric access controls) is a physical control using physiological characteristics for authentication, so none of these belong to the administrative category.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Firewall rule sets

    Why it's wrong here

    Firewall rule sets are technical (logical) controls implemented in hardware or software, not administrative ones, which are policy, procedure and personnel based. The option tempts because rules are configured by administrators, but the control's nature is technical, so it fails the administrative classification.

  • ✗

    Data encryption

    Why it's wrong here

    Encryption is a technical control applied to data at rest or in transit, not an administrative control, which covers policies, standards, procedures and training. It tempts because encryption is mandated by policy, but the mechanism itself is technical, so it does not satisfy the administrative category.

  • ✗

    Biometric access controls

    Why it's wrong here

    Biometric access controls are physical controls, verifying identity through fingerprints or iris scans at a reader. The option tempts because biometrics can enforce administrative access policy, but the mechanism is physical, so it fails the administrative classification the question requires.

  • ✓

    Security policies and procedures

    Why this is correct

    Policies and procedures are administrative controls because they govern behaviour through documented rules rather than technical enforcement or physical barriers. They satisfy the stem's requirement by directing personnel actions, defining acceptable use and mandating compliance across the organisation.

  • ✓

    Security awareness training

    Why this is correct

    Security awareness training is administrative because it modifies human behaviour through education rather than technical or physical means. It satisfies the stem by reducing risk from user error and social engineering, complementing documented policies within the administrative control category.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

Go deeper

Related to this question

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CC

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO of the following are examples of administrative security controls? (Choose two.)

medium
  • A.Intrusion detection system
  • ✓ B.Security awareness training
  • C.Firewall
  • D.Encryption
  • ✓ E.Background checks for employees
JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.