Courseiva
mediumMultiple SelectObjective-mapped

CISSP Practice Question: Which THREE of the following are control families…

Which THREE of the following are control families defined in NIST SP 800-53? (Choose three.)

⚠ Common exam trap

Candidates often confuse common security domains (like encryption or business continuity) with the specific control family names used in NIST SP 800-53, leading them to select plausible-sounding but non-existent families like Data Encryption or Business Continuity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Access Control (AC)

Access Control (AC) is a control family in NIST SP 800-53 that encompasses policies, procedures, and mechanisms for managing user permissions, authentication, and authorization. It includes controls like AC-2 (Account Management) and AC-3 (Access Enforcement), which are fundamental to enforcing least privilege and separation of duties.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Access Control (AC)

    Why this is correct

    Access Control (AC) is a foundational control family within NIST SP 800-53, focusing on limiting information system access to authorized users, processes, or devices. This family establishes the policies and procedures for granting, revoking, and reviewing permissions based on roles and responsibilities. It ensures that only entities with appropriate clearances and need-to-know can interact with sensitive data and system resources.

  • System and Communications Protection (SC)

    Why this is correct

    The System and Communications Protection (SC) control family in NIST SP 800-53 addresses the security of information system boundaries and the integrity and confidentiality of information transmitted across those boundaries. This family includes controls for network segmentation, boundary protection devices like firewalls, and cryptographic protection for data in transit and at rest. Its objective is to safeguard the communication channels and the systems themselves from external and internal threats.

  • Data Encryption (DE)

    Why it's wrong here

    Data Encryption (DE) is not recognized as a standalone control family within the NIST SP 800-53 framework. Instead, encryption is a crucial security mechanism or control that is primarily implemented under the System and Communications Protection (SC) family, specifically within controls like SC-8 (Transmission Confidentiality and Integrity) and SC-13 (Cryptographic Protection). While vital for data protection, encryption serves as a technical implementation detail rather than a broad category of security management.

  • Business Continuity (BC)

    Why it's wrong here

    Business Continuity (BC) is not a distinct control family in the NIST SP 800-53 framework; rather, it represents a critical organizational objective or program. The controls necessary to achieve business continuity and disaster recovery are primarily found within the Contingency Planning (CP) control family. CP encompasses requirements for developing, maintaining, and testing plans to ensure the continued operation of information systems during disruptions, directly supporting an organization's overall business continuity strategy.

  • Identification and Authentication (IA)

    Why this is correct

    Identification and Authentication (IA) is a core control family in NIST SP 800-53, dedicated to verifying the identity of users, processes, or devices before granting access to information systems. This family mandates controls for establishing unique identifiers, managing credentials, and implementing robust authentication mechanisms such as multi-factor authentication. It forms the critical initial gatekeeping function, ensuring that only legitimate entities can attempt to access protected resources.

About these practice questions

One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.