hardMultiple Select
ISC2 CC Practice Question: Which TWO of the following are examples of…
Which TWO of the following are examples of detective security controls? (Choose two.)
⚠ Common exam trap
CC often tests the distinction between preventive and detective controls — candidates misclassify encryption or firewalls as detective because they 'protect' data, when in fact they prevent rather than detect.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security logging and monitoring.
Detective controls are designed to identify and record security events after or while they occur, and both B and C fit that definition. B (Security logging and monitoring) is correct because collecting and analyzing logs (e.g., via SIEM correlation of Windows Event Logs, syslog, or audit trails) detects anomalous or unauthorized activity. C (Intrusion detection system (IDS) alerts) is correct because an IDS inspects network or host traffic (signature- or anomaly-based) and raises alerts when malicious or suspicious patterns are detected. The unmarked options are preventive or corrective rather than detective: A (Data backup and restoration procedures) is primarily corrective/recovery, D (Encryption of sensitive data) is preventive by protecting confidentiality, and E (Firewall rules that block certain traffic) is preventive by denying traffic before it reaches systems.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data backup and restoration procedures.
Why it's wrong here
Backup and restoration procedures are corrective controls: they recover data after an incident rather than identifying that one is occurring. They are tempting because they are essential resilience measures, and would be the right answer if the question asked for corrective or recovery controls instead of detective ones.
- ✓
Security logging and monitoring.
Why this is correct
Security logging and monitoring records and analyses activity to identify incidents after or during their occurrence, satisfying the stem's requirement for detective controls. Unlike preventive controls, which block actions, logging detects and alerts on suspicious events, enabling timely response. This makes it a recognised example of a detective security control.
- ✓
Intrusion detection system (IDS) alerts.
Why this is correct
An IDS monitors network or host activity and generates alerts when it matches known attack signatures or anomalous behaviour, satisfying the stem's requirement for a detective control. Unlike preventive controls, which block events before they occur, detection identifies and reports incidents already in progress, enabling timely response.
- ✗
Encryption of sensitive data.
Why it's wrong here
Encryption is a preventive control that renders data unreadable to unauthorised parties; it detects nothing. It is tempting because it is a core data-protection safeguard, and would be correct if the question asked for preventive controls rather than detective ones.
- ✗
Firewall rules that block certain traffic.
Why it's wrong here
Firewall rules that block traffic are preventive controls, stopping connections before they occur rather than identifying activity already underway. They are tempting because firewalls also generate logs, but the blocking rule itself is the control, and logging is a separate detective mechanism.
Go deeper
Related to this question
Learn chapter
Business Continuity and Disaster Recovery
Key term
IDS
An IDS is a security system that monitors network or system traffic for suspicious activity and alerts administrators to potential threats, but does not actively block them.
Key term
SIEM
SIEM (Security Information and Event Management) is a system that collects and analyzes log data from across an IT environment to detect and respond to security threats in real time.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.