Courseiva
mediumMultiple Select

CISSP Practice Question: A security manager is selecting controls to…

A security manager is selecting controls to protect sensitive data. Which TWO are examples of administrative controls?

⚠ Common exam trap

Candidates often confuse administrative controls with technical or physical controls. Remember that administrative controls deal with people, policies, procedures, and management (such as training, background checks, and hiring practices), whereas technical controls use hardware or software (like firewalls and encryption).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security awareness training

Security awareness training (A) is an administrative control because it is a management-directed program that educates personnel on policies and procedures to reduce human error and social-engineering risk, rather than a technical mechanism. Background checks (D) are also administrative controls because they are personnel-security processes—pre-employment screening, verification of identity and history—implemented through policy and HR procedures to mitigate insider threats. Firewalls (B), access control lists (C), and encryption (E) are technical (logical) controls: firewalls filter network traffic, ACLs enforce permissions on resources, and encryption protects data confidentiality through cryptographic algorithms, so none of them are administrative in nature.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Security awareness training

    Why this is correct

    Security awareness training is an essential administrative control that educates employees about security policies, best practices, and common threats like phishing or social engineering. Its primary goal is to foster a security-conscious culture and empower personnel to identify and report suspicious activities, thereby reducing human-factor vulnerabilities. This control operates through policy, education, and human behavior modification, making it a foundational administrative measure.

  • ✗

    Firewalls

    Why it's wrong here

    Firewalls are network security devices or software that monitor and control incoming and outgoing network traffic based on predetermined security rules. They act as a barrier between trusted and untrusted networks, enforcing access policies by filtering packets based on source, destination, port, and protocol. Since firewalls are hardware or software components that automatically enforce rules without human intervention for each transaction, they are a quintessential technical control.

  • ✗

    Access control lists

    Why it's wrong here

    Access control lists (ACLs) are rule sets configured on network devices or operating systems to filter traffic or restrict resource access based on attributes like IP addresses, ports, or user identities. They are implemented directly by technology to enforce security policies, making them a technical control, not an administrative one. Therefore, while crucial for security, they do not fit the administrative control category implied by the question's correct answer.

  • ✓

    Background checks

    Why this is correct

    Background checks are a crucial administrative control designed to vet potential employees or contractors before granting them access to sensitive information or systems. This process involves verifying an individual's history, including criminal records, employment, and education, to assess trustworthiness and mitigate insider threats. By establishing personnel suitability through policy and procedure, background checks directly support the organization's security posture at a managerial level.

  • ✗

    Encryption

    Why it's wrong here

    Encryption is a cryptographic process that transforms data into an unreadable format to protect its confidentiality and integrity, both at rest and in transit. It relies on algorithms and keys implemented through software or hardware to secure information against unauthorized access. As a mechanism directly applied by technology to enforce data protection, encryption is unequivocally a technical control, not an administrative one.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.