Courseiva
easyMultiple Select

ISC2 CC Practice Question: Which TWO of the following are types of security…

Which TWO of the following are types of security controls used in defense in depth? (Select TWO.)

⚠ Common exam trap

ISC2 often tests the distinction between control categories by including 'Administrative controls' as a distractor, leading candidates to confuse governance-level controls (policies, awareness training) with the operational control types (preventive, detective, corrective) that form the core of defense in depth.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Detective controls

Detective controls are a core type of security control in a defense-in-depth strategy, designed to identify and alert on ongoing or past security incidents. Examples include intrusion detection systems (IDS) like Snort or Suricata, which analyze network traffic for malicious patterns, and security information and event management (SIEM) systems that correlate logs to detect anomalies. These controls provide visibility into the security posture, enabling timely response to threats that bypass preventive measures.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Detective controls

    Why this is correct

    Detective controls identify attacks, e.g., IDS.

  • ✗

    Corrective controls

    Why it's wrong here

    Corrective controls restore after an incident, not a primary layer.

  • ✗

    Compensating controls

    Why it's wrong here

    Compensating controls are alternatives, not a primary layer.

  • ✗

    Administrative controls

    Why it's wrong here

    Administrative controls are policies, but not a distinct layer in defense in depth.

  • ✓

    Preventive controls

    Why this is correct

    Preventive controls block attacks, e.g., firewalls.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CC

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO of the following are types of security controls?

medium
  • A.Network
  • ✓ B.Corrective
  • C.All of the above
  • ✓ D.Preventive
  • E.None of the above

Why B: The question asks for types of security controls, and the standard control categories by function are preventive, detective, corrective, deterrent, compensating, and physical/administrative/technical. Option B (Corrective) is correct because corrective controls are a recognized functional category that acts after an incident to restore systems and reduce impact, such as backups, patches, or disaster recovery procedures. Option D (Preventive) is correct because preventive controls are a recognized functional category designed to stop incidents before they occur, such as firewalls, encryption, access controls, and security awareness training. Option A (Network) is not a control type but rather a domain or scope where controls can be applied, so it does not fit the question. Option C (All of the above) is wrong because it would include the incorrect Network option, and Option E (None of the above) is wrong because two valid control types are listed.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.