Courseiva
easyMultiple Select

ISC2 CC Practice Question: Which TWO of the following are examples of…

Which TWO of the following are examples of preventive security controls?

⚠ Common exam trap

The trap is that encryption is often assumed to be preventive, but the exam expects you to distinguish controls that block an event (firewall, antivirus) from those that protect data or detect/restore after the fact.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Antivirus software

Antivirus software (C) is a preventive control because it actively blocks, quarantines, or removes malicious code before it can execute or spread, stopping an incident from occurring. A firewall (D) is likewise preventive: it enforces ACL rules on ports, protocols, and IP addresses to deny unauthorized traffic at the network perimeter before it reaches protected hosts. By contrast, encryption (A) is primarily a protective/confidentiality mechanism that renders data unreadable rather than stopping an event, backup (B) is a corrective/recovery control used after data loss, and an intrusion detection system (E) is a detective control that only alerts on suspicious activity rather than blocking it.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Encryption

    Why it's wrong here

    Encryption protects data confidentiality but does not stop an action from occurring, so it is a protective rather than preventive control. It is tempting because it blocks unauthorised reading, yet preventive controls such as access control or firewalls actively deny the attempt itself.

  • ✗

    Backup

    Why it's wrong here

    Backups allow recovery after an incident but do not stop the incident occurring, making them corrective rather than preventive. It is tempting because backups are a core security safeguard, yet preventive controls such as security awareness training or separation of duties stop the event beforehand.

  • ✓

    Antivirus software

    Why this is correct

    Antivirus software is preventive because it blocks or quarantines malicious code before execution, stopping threats at the endpoint. This contrasts with detective controls such as logging or IDS, which only identify activity after it occurs.

  • ✓

    Firewall

    Why this is correct

    A firewall enforces access rules that block malicious traffic before it reaches protected systems, satisfying the stem's requirement for a preventive control. Unlike detective controls, which identify incidents after they occur, it proactively denies unauthorised connections at the network perimeter, stopping attacks rather than merely recording them.

  • ✗

    Intrusion detection system

    Why it's wrong here

    An IDS detects and alerts on malicious activity after it occurs, so it is detective, not preventive. It is tempting because it is a security control that monitors network traffic, but it would be the correct choice when the requirement is to identify and log intrusions rather than stop them before they happen.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.