easyMultiple Select
ISC2 CC Practice Question: Which TWO of the following are examples of…
Which TWO of the following are examples of administrative security controls?
⚠ Common exam trap
The trap is misclassifying biometrics as administrative because it involves a 'system'; biometrics are physical controls, and only policies/procedures and training are administrative here.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security policies and procedures
Administrative security controls are the management-oriented, people-and-process controls that govern how an organization operates, so D (Security policies and procedures) is correct because written policies, standards, and procedures define required behavior and are classic administrative controls. E (Security awareness training) is also correct because it is a management-driven program that educates personnel on policy and safe practices, which is administrative in nature. By contrast, A (Firewall rule sets) is a technical/logical control implemented in network devices, B (Data encryption) is a technical control that protects data confidentiality via cryptographic algorithms, and C (Biometric access controls) is a physical control using physiological characteristics for authentication, so none of these belong to the administrative category.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Firewall rule sets
Why it's wrong here
Firewall rule sets are technical (logical) controls implemented in hardware or software, not administrative ones, which are policy, procedure and personnel based. The option tempts because rules are configured by administrators, but the control's nature is technical, so it fails the administrative classification.
- ✗
Data encryption
Why it's wrong here
Encryption is a technical control applied to data at rest or in transit, not an administrative control, which covers policies, standards, procedures and training. It tempts because encryption is mandated by policy, but the mechanism itself is technical, so it does not satisfy the administrative category.
- ✗
Biometric access controls
Why it's wrong here
Biometric access controls are physical controls, verifying identity through fingerprints or iris scans at a reader. The option tempts because biometrics can enforce administrative access policy, but the mechanism is physical, so it fails the administrative classification the question requires.
- ✓
Security policies and procedures
Why this is correct
Policies and procedures are administrative controls because they govern behaviour through documented rules rather than technical enforcement or physical barriers. They satisfy the stem's requirement by directing personnel actions, defining acceptable use and mandating compliance across the organisation.
- ✓
Security awareness training
Why this is correct
Security awareness training is administrative because it modifies human behaviour through education rather than technical or physical means. It satisfies the stem by reducing risk from user error and social engineering, complementing documented policies within the administrative control category.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
Learn chapter
Security Awareness and Training
Key term
Technical control
A technical control is a security mechanism implemented through hardware, software, or firmware that protects the confidentiality, integrity, and availability of IT systems and data.
Key term
Firewall
A firewall is a network security system that monitors and controls incoming and outgoing traffic based on predetermined security rules to protect trusted internal networks from untrusted external networks.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CC
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO of the following are examples of administrative security controls? (Choose two.)
medium- A.Intrusion detection system
- ✓ B.Security awareness training
- C.Firewall
- D.Encryption
- ✓ E.Background checks for employees
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.