Courseiva
easyMultiple SelectObjective-mapped

Examples of Administrative Controls in Information Security

Which TWO of the following are examples of administrative controls? (Select exactly 2)

Quick Answer

The answer is background checks for employees and security awareness training, as both are classic examples of administrative controls in information security. Administrative controls are the policies, procedures, and guidelines that manage human behavior and organizational processes to reduce risk, rather than relying on hardware or physical barriers. Background checks enforce personnel security policies by vetting employees before access is granted, while security awareness training educates staff on secure practices—both are documented in the security policy framework and fall under the management domain. On the CISSP exam, this question tests your ability to distinguish administrative controls from technical controls (like firewalls) and physical controls (like locks); a common trap is confusing training with a technical control, but remember that anything involving people, policy, or procedure is administrative. Memory tip: think “People and Paper”—if it involves human vetting, training, or written rules, it’s administrative.

⚠ Common exam trap

ISC2 often tests the distinction between administrative, technical, and physical controls, and the trap here is that candidates confuse security guards (physical) or firewall rules (technical) with administrative controls because they involve 'security' or 'rules,' but they are not policy-based or procedural in nature.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Security awareness training

Security awareness training (B) is an administrative control because it involves policies, procedures, and human behavior management to reduce risk. Background checks (E) are also administrative controls, as they are part of personnel security policies that vet employees before granting access. Both are documented in the organization's security policy framework and are not technical or physical mechanisms.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Firewall rules

    Why it's wrong here

    Technical control.

  • Security awareness training

    Why this is correct

    Correct - Administrative control addressing people.

  • Security guards at entrances

    Why it's wrong here

    Physical control.

  • Encryption of data at rest

    Why it's wrong here

    Technical control.

  • Background checks for employees

    Why this is correct

    Correct - Administrative control for personnel security.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CISSP

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO are examples of administrative controls in an information security program?

medium
  • A.Background checks
  • B.Encryption algorithms
  • C.Security awareness training
  • D.Firewall rules
  • E.Access control lists (ACLs)

Why A: Background checks and security awareness training are both administrative (or managerial) controls. Background checks are part of personnel security policies and procedures to vet employees before hiring. Security awareness training is an administrative control designed to alter user behavior and reduce human risk through education. In contrast, encryption algorithms, firewall rules, and access control lists (ACLs) are technical (logical) controls implemented via hardware or software.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.