easyMultiple SelectObjective-mapped
Examples of Administrative Controls in Information Security
Which TWO of the following are examples of administrative controls? (Select exactly 2)
Quick Answer
The answer is background checks for employees and security awareness training, as both are classic examples of administrative controls in information security. Administrative controls are the policies, procedures, and guidelines that manage human behavior and organizational processes to reduce risk, rather than relying on hardware or physical barriers. Background checks enforce personnel security policies by vetting employees before access is granted, while security awareness training educates staff on secure practices—both are documented in the security policy framework and fall under the management domain. On the CISSP exam, this question tests your ability to distinguish administrative controls from technical controls (like firewalls) and physical controls (like locks); a common trap is confusing training with a technical control, but remember that anything involving people, policy, or procedure is administrative. Memory tip: think “People and Paper”—if it involves human vetting, training, or written rules, it’s administrative.
⚠ Common exam trap
ISC2 often tests the distinction between administrative, technical, and physical controls, and the trap here is that candidates confuse security guards (physical) or firewall rules (technical) with administrative controls because they involve 'security' or 'rules,' but they are not policy-based or procedural in nature.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security awareness training
Security awareness training (B) is an administrative control because it involves policies, procedures, and human behavior management to reduce risk. Background checks (E) are also administrative controls, as they are part of personnel security policies that vet employees before granting access. Both are documented in the organization's security policy framework and are not technical or physical mechanisms.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Firewall rules
Why it's wrong here
Technical control.
- ✓
Security awareness training
Why this is correct
Correct - Administrative control addressing people.
- ✗
Security guards at entrances
Why it's wrong here
Physical control.
- ✗
Encryption of data at rest
Why it's wrong here
Technical control.
- ✓
Background checks for employees
Why this is correct
Correct - Administrative control for personnel security.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Security policy
A security policy is a formal set of rules and guidelines that an organization establishes to protect its information assets and technology resources.
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CISSP
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO are examples of administrative controls in an information security program?
medium- ✓ A.Background checks
- B.Encryption algorithms
- ✓ C.Security awareness training
- D.Firewall rules
- E.Access control lists (ACLs)
Why A: Background checks and security awareness training are both administrative (or managerial) controls. Background checks are part of personnel security policies and procedures to vet employees before hiring. Security awareness training is an administrative control designed to alter user behavior and reduce human risk through education. In contrast, encryption algorithms, firewall rules, and access control lists (ACLs) are technical (logical) controls implemented via hardware or software.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.