mediumMultiple Select
ISC2 CC Practice Question: Which TWO of the following are types of security…
Which TWO of the following are types of security controls?
⚠ Common exam trap
CC often tests the confusion between control categories (preventive, detective, corrective) and control domains (network, physical, administrative), causing candidates to select 'Network' as a type.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Corrective
The question asks for types of security controls, and the standard control categories by function are preventive, detective, corrective, deterrent, compensating, and physical/administrative/technical. Option B (Corrective) is correct because corrective controls are a recognized functional category that acts after an incident to restore systems and reduce impact, such as backups, patches, or disaster recovery procedures. Option D (Preventive) is correct because preventive controls are a recognized functional category designed to stop incidents before they occur, such as firewalls, encryption, access controls, and security awareness training. Option A (Network) is not a control type but rather a domain or scope where controls can be applied, so it does not fit the question. Option C (All of the above) is wrong because it would include the incorrect Network option, and Option E (None of the above) is wrong because two valid control types are listed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Network
Why it's wrong here
Network is a category of control (alongside administrative, physical and technical), not a type in the sense the question asks. It tempts because controls are commonly grouped by domain, but the stem wants the classification axis itself, not a domain label.
- ✓
Corrective
Why this is correct
Corrective controls act after an incident to restore systems and limit further damage, such as backups, patches or malware removal. They form one of the recognised control categories alongside preventive, detective, deterrent and compensating types, satisfying the question's request for a control type.
- ✗
All of the above
Why it's wrong here
'All of the above' is a meta-answer, not a security control type; it cannot be one of the two correct categories. The question asks for named control types such as preventive, detective, corrective, physical or administrative. Selecting it is tempting when every listed option appears valid, but it supplies no control category itself.
- ✓
Preventive
Why this is correct
Preventive controls stop incidents before they occur, for example firewalls, access controls and encryption. They are a recognised category alongside corrective, detective, deterrent and compensating controls, satisfying the question's requirement to identify a genuine security control type.
- ✗
None of the above
Why it's wrong here
'None of the above' is a meta-answer, not a security control type, so it cannot satisfy a question asking for two named categories. It tempts candidates who believe every listed option is invalid. The correct selections are actual control classifications, for example preventive and detective controls.
Go deeper
Related to this question
Learn chapter
Security Awareness and Training
Key term
Security awareness
Security awareness is the ongoing practice of educating people within an organization about cybersecurity risks, safe behaviors, and their individual responsibilities to protect information assets.
Key term
Anti-phishing policy
An anti-phishing policy is a set of rules and technical controls that organizations use to detect, block, and respond to email or message-based attacks that trick users into revealing sensitive information.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.