Courseiva
mediumMultiple Select

CISSP Practice Question: Which TWO of the following are examples of…

Which TWO of the following are examples of detective controls?

⚠ Common exam trap

A common mix-up: candidates confuse preventive controls (like ACLs and firewalls) with detective controls, as candidates often misclassify any technology that 'monitors' as detective, but ACLs and firewalls are inherently preventive because they block or allow access in real-time, not after the fact.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

CCTV surveillance

B (CCTV surveillance) is a detective control because it records and monitors activity after or during an event to identify and investigate security incidents, rather than stopping them. E (Intrusion detection system (IDS)) is also detective because it monitors network or host traffic and generates alerts on suspicious or malicious activity, detecting intrusions that have occurred or are occurring. A (Access control list) is a preventive control, as it enforces which subjects may access resources and blocks unauthorized access. C (Firewall) is preventive, filtering and blocking traffic according to rules before it reaches protected systems. D (Security awareness training) is a preventive/administrative control that reduces the likelihood of user errors and policy violations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Access control list

    Why it's wrong here

    Access control lists (ACLs) are fundamental security mechanisms that define and enforce permissions for users and processes attempting to access system resources. By explicitly specifying who can perform what actions on which objects, ACLs proactively restrict unauthorized access and operations before they can occur. This upfront enforcement of rules to prevent undesirable events classifies them as a preventive control, rather than a system designed to detect an incident after it has begun.

  • ✓

    CCTV surveillance

    Why this is correct

    Closed-circuit television (CCTV) surveillance systems are designed to continuously monitor and record activities within a specified physical area. While their visible presence can act as a deterrent, their primary security function is detective, as they capture visual evidence of events such as unauthorized entry, theft, or vandalism as they unfold or after they have occurred. This recorded footage is invaluable for post-incident analysis, identification of perpetrators, and understanding the timeline of a security breach.

  • ✗

    Firewall

    Why it's wrong here

    A firewall serves as a network security device that monitors and filters incoming and outgoing network traffic based on an organization's previously established security policies. Its core function is to create a barrier between trusted internal networks and untrusted external networks, actively blocking unauthorized access and malicious data packets from reaching internal systems. This proactive filtering and blocking mechanism, which stops threats before they can impact resources, firmly establishes the firewall as a preventive control.

  • ✗

    Security awareness training

    Why it's wrong here

    Security awareness training is a crucial organizational control aimed at educating employees about security policies, best practices, and potential threats like phishing, social engineering, or malware. Its purpose is to influence user behavior and guide individuals to make secure decisions and follow established protocols. By providing instruction and setting expectations to prevent incidents through informed actions, it functions as a directive control, guiding users toward secure actions rather than detecting breaches after they happen.

  • ✓

    Intrusion detection system (IDS)

    Why this is correct

    An Intrusion Detection System (IDS) is a security technology that continuously monitors network traffic or system activities for suspicious patterns, known attack signatures, or anomalies indicative of a security breach or policy violation. Unlike preventive controls that block actions, an IDS primarily focuses on identifying and reporting these events as they occur or after they have happened. By generating alerts and logs, it serves as a quintessential detective control, enabling security personnel to respond to potential threats.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.