Courseiva
easyMultiple Select

Examples of Administrative Controls in Information Security

Which TWO of the following are examples of administrative controls? (Select exactly 2)

Quick Answer

The answer is background checks for employees and security awareness training, as both are classic examples of administrative controls in information security. Administrative controls are the policies, procedures, and guidelines that manage human behavior and organizational processes to reduce risk, rather than relying on hardware or physical barriers. Background checks enforce personnel security policies by vetting employees before access is granted, while security awareness training educates staff on secure practices—both are documented in the security policy framework and fall under the management domain. On the CISSP exam, this question tests your ability to distinguish administrative controls from technical controls (like firewalls) and physical controls (like locks); a common trap is confusing training with a technical control, but remember that anything involving people, policy, or procedure is administrative. Memory tip: think “People and Paper”—if it involves human vetting, training, or written rules, it’s administrative.

⚠ Common exam trap

ISC2 often tests the distinction between administrative, technical, and physical controls, and the trap here is that candidates confuse security guards (physical) or firewall rules (technical) with administrative controls because they involve 'security' or 'rules,' but they are not policy-based or procedural in nature.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security awareness training

Administrative controls are management-driven policies, procedures, and practices that govern how people behave and how security is organized, rather than technical or physical mechanisms. Option B, security awareness training, is correct because it is a management-initiated program that educates users on policies and safe behavior, directly shaping human conduct. Option E, background checks for employees, is correct because it is a personnel screening procedure implemented through HR policy to reduce insider risk before granting access. Option A, firewall rules, is a technical (logical) control enforced by network devices, not an administrative one. Option C, security guards at entrances, is a physical control that deters and detects intrusion through human presence. Option D, encryption of data at rest, is a technical control that protects data confidentiality via cryptographic algorithms.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Firewall rules

    Why it's wrong here

    Firewall rules are a technical control, enforced by network devices on traffic, not by policy or procedure over people. It is tempting because rules are documented and configured by administrators, but the control's nature is technical; administrative controls include things such as security awareness training and background checks.

  • ✓

    Security awareness training

    Why this is correct

    Security awareness training is an administrative control because it governs employee behaviour through policy, procedure and education rather than through hardware or software. It satisfies the stem's requirement for a management-based safeguard, unlike technical controls such as firewalls or encryption.

  • ✗

    Security guards at entrances

    Why it's wrong here

    Guards are physical controls, enforcing access through human presence at a facility, not administrative controls such as policies, procedures or awareness training. The physical category is tempting because guards also deter and detect, but administrative controls govern behaviour through documented rules rather than on-site personnel.

  • ✗

    Encryption of data at rest

    Why it's wrong here

    Encryption of data at rest is a technical control implemented by cryptographic mechanisms, not an administrative one. It is tempting because administrators select and configure the encryption, but the control operates on data itself; administrative controls govern human behaviour through policies, procedures, and training.

  • ✓

    Background checks for employees

    Why this is correct

    Background checks are an administrative control: a personnel screening process enforced by policy and procedure before granting access. They satisfy the stem's requirement for a management-based safeguard, distinguishing them from technical controls like access lists or physical controls like locks.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CISSP

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO are examples of administrative controls in an information security program?

medium
  • ✓ A.Background checks
  • B.Encryption algorithms
  • ✓ C.Security awareness training
  • D.Firewall rules
  • E.Access control lists (ACLs)

Why A: Administrative controls are the management-oriented, people-and-policy safeguards of a security program, so option A (Background checks) is correct because screening personnel before hire is a procedural/managerial control that reduces insider risk and is mandated by policies rather than enforced by technology. Option C (Security awareness training) is also correct because it is a management-driven program that educates users on policies, phishing, and safe behavior, directly shaping human conduct through process and policy. By contrast, option B (Encryption algorithms), option D (Firewall rules), and option E (Access control lists (ACLs)) are technical (logical) controls — cryptographic mechanisms, packet-filtering rules, and permission lists enforced by systems — not administrative controls.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.