easyMultiple Select
Examples of Administrative Controls in Information Security
Which TWO of the following are examples of administrative controls? (Select exactly 2)
Quick Answer
The answer is background checks for employees and security awareness training, as both are classic examples of administrative controls in information security. Administrative controls are the policies, procedures, and guidelines that manage human behavior and organizational processes to reduce risk, rather than relying on hardware or physical barriers. Background checks enforce personnel security policies by vetting employees before access is granted, while security awareness training educates staff on secure practices—both are documented in the security policy framework and fall under the management domain. On the CISSP exam, this question tests your ability to distinguish administrative controls from technical controls (like firewalls) and physical controls (like locks); a common trap is confusing training with a technical control, but remember that anything involving people, policy, or procedure is administrative. Memory tip: think “People and Paper”—if it involves human vetting, training, or written rules, it’s administrative.
⚠ Common exam trap
ISC2 often tests the distinction between administrative, technical, and physical controls, and the trap here is that candidates confuse security guards (physical) or firewall rules (technical) with administrative controls because they involve 'security' or 'rules,' but they are not policy-based or procedural in nature.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security awareness training
Administrative controls are management-driven policies, procedures, and practices that govern how people behave and how security is organized, rather than technical or physical mechanisms. Option B, security awareness training, is correct because it is a management-initiated program that educates users on policies and safe behavior, directly shaping human conduct. Option E, background checks for employees, is correct because it is a personnel screening procedure implemented through HR policy to reduce insider risk before granting access. Option A, firewall rules, is a technical (logical) control enforced by network devices, not an administrative one. Option C, security guards at entrances, is a physical control that deters and detects intrusion through human presence. Option D, encryption of data at rest, is a technical control that protects data confidentiality via cryptographic algorithms.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Firewall rules
Why it's wrong here
Firewall rules are a technical control, enforced by network devices on traffic, not by policy or procedure over people. It is tempting because rules are documented and configured by administrators, but the control's nature is technical; administrative controls include things such as security awareness training and background checks.
- ✓
Security awareness training
Why this is correct
Security awareness training is an administrative control because it governs employee behaviour through policy, procedure and education rather than through hardware or software. It satisfies the stem's requirement for a management-based safeguard, unlike technical controls such as firewalls or encryption.
- ✗
Security guards at entrances
Why it's wrong here
Guards are physical controls, enforcing access through human presence at a facility, not administrative controls such as policies, procedures or awareness training. The physical category is tempting because guards also deter and detect, but administrative controls govern behaviour through documented rules rather than on-site personnel.
- ✗
Encryption of data at rest
Why it's wrong here
Encryption of data at rest is a technical control implemented by cryptographic mechanisms, not an administrative one. It is tempting because administrators select and configure the encryption, but the control operates on data itself; administrative controls govern human behaviour through policies, procedures, and training.
- ✓
Background checks for employees
Why this is correct
Background checks are an administrative control: a personnel screening process enforced by policy and procedure before granting access. They satisfy the stem's requirement for a management-based safeguard, distinguishing them from technical controls like access lists or physical controls like locks.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
Learn chapter
Identity and Access Management (IAM)
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CISSP
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO are examples of administrative controls in an information security program?
medium- ✓ A.Background checks
- B.Encryption algorithms
- ✓ C.Security awareness training
- D.Firewall rules
- E.Access control lists (ACLs)
Why A: Administrative controls are the management-oriented, people-and-policy safeguards of a security program, so option A (Background checks) is correct because screening personnel before hire is a procedural/managerial control that reduces insider risk and is mandated by policies rather than enforced by technology. Option C (Security awareness training) is also correct because it is a management-driven program that educates users on policies, phishing, and safe behavior, directly shaping human conduct through process and policy. By contrast, option B (Encryption algorithms), option D (Firewall rules), and option E (Access control lists (ACLs)) are technical (logical) controls — cryptographic mechanisms, packet-filtering rules, and permission lists enforced by systems — not administrative controls.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.