mediumMultiple Select
CISSP Practice Question: A security manager is selecting controls to…
A security manager is selecting controls to protect sensitive data. Which TWO are examples of administrative controls?
⚠ Common exam trap
Candidates often confuse administrative controls with technical or physical controls. Remember that administrative controls deal with people, policies, procedures, and management (such as training, background checks, and hiring practices), whereas technical controls use hardware or software (like firewalls and encryption).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security awareness training
Security awareness training (A) is an administrative control because it is a management-directed program that educates personnel on policies and procedures to reduce human error and social-engineering risk, rather than a technical mechanism. Background checks (D) are also administrative controls because they are personnel-security processes—pre-employment screening, verification of identity and history—implemented through policy and HR procedures to mitigate insider threats. Firewalls (B), access control lists (C), and encryption (E) are technical (logical) controls: firewalls filter network traffic, ACLs enforce permissions on resources, and encryption protects data confidentiality through cryptographic algorithms, so none of them are administrative in nature.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Security awareness training
Why this is correct
Security awareness training is an essential administrative control that educates employees about security policies, best practices, and common threats like phishing or social engineering. Its primary goal is to foster a security-conscious culture and empower personnel to identify and report suspicious activities, thereby reducing human-factor vulnerabilities. This control operates through policy, education, and human behavior modification, making it a foundational administrative measure.
- ✗
Firewalls
Why it's wrong here
Firewalls are network security devices or software that monitor and control incoming and outgoing network traffic based on predetermined security rules. They act as a barrier between trusted and untrusted networks, enforcing access policies by filtering packets based on source, destination, port, and protocol. Since firewalls are hardware or software components that automatically enforce rules without human intervention for each transaction, they are a quintessential technical control.
- ✗
Access control lists
Why it's wrong here
Access control lists (ACLs) are rule sets configured on network devices or operating systems to filter traffic or restrict resource access based on attributes like IP addresses, ports, or user identities. They are implemented directly by technology to enforce security policies, making them a technical control, not an administrative one. Therefore, while crucial for security, they do not fit the administrative control category implied by the question's correct answer.
- ✓
Background checks
Why this is correct
Background checks are a crucial administrative control designed to vet potential employees or contractors before granting them access to sensitive information or systems. This process involves verifying an individual's history, including criminal records, employment, and education, to assess trustworthiness and mitigate insider threats. By establishing personnel suitability through policy and procedure, background checks directly support the organization's security posture at a managerial level.
- ✗
Encryption
Why it's wrong here
Encryption is a cryptographic process that transforms data into an unreadable format to protect its confidentiality and integrity, both at rest and in transit. It relies on algorithms and keys implemented through software or hardware to secure information against unauthorized access. As a mechanism directly applied by technology to enforce data protection, encryption is unequivocally a technical control, not an administrative one.
Visual reference
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
Learn chapter
Physical Security and Environmental Controls
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
Key term
Security awareness
Security awareness is the ongoing practice of educating people within an organization about cybersecurity risks, safe behaviors, and their individual responsibilities to protect information assets.
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.