Courseiva
easyMultiple Select

Administrative Controls: Policies and Training

Which TWO of the following are examples of administrative controls? (Choose two.)

Quick Answer

Security awareness training qualifies as an administrative control because administrative controls are defined by what they govern, meaning people, processes, and policy, rather than by physical barriers or technical enforcement mechanisms. Training programs work by shaping human behavior and knowledge: teaching employees to recognize phishing attempts, follow proper data-handling procedures, and understand their security responsibilities, which reduces the likelihood of human error becoming the weak link in the organization's defenses. Access control policies belong in the same category for a related reason; they're the documented rules, procedures, and assigned responsibilities that establish how access should be managed, providing the governance framework that technical controls, like an actual access control system, and physical controls, like badge readers, are then built to implement. Neither training nor policy directly blocks or physically prevents anything on its own; instead, they set expectations, build capability, and define rules that other layers of control then enforce or that people are expected to follow voluntarily. This is the key distinction from technical controls, which use hardware or software to directly enforce restrictions, and physical controls, which use tangible barriers. When a question asks you to classify a control, ask whether it works through documented policy, procedure, or human education, and if so, it's administrative, regardless of what topic it happens to address.

⚠ Common exam trap

Many exam-takers confuse administrative controls with technical or physical controls, mistakenly selecting firewall rules or encryption because they are common security measures, but the SSCP exam specifically tests the distinction between administrative (policy/training), technical (software/hardware), and physical (guards/locks) control categories.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Access control policies

Access control policies (B) are administrative controls because they define the rules, procedures, and responsibilities for managing access to resources, forming the governance framework that guides technical and physical implementations. Security awareness training (C) is also an administrative control as it educates users on security policies and procedures, reducing human error and reinforcing organizational security culture.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Firewall rules

    Why it's wrong here

    Firewall rules are a technical control, enforced by network equipment inspecting traffic, not by organisational policy. It is tempting because rules are written down, but administrative controls are procedural documents such as policies, standards, guidelines and security awareness training.

  • ✓

    Access control policies

    Why this is correct

    Access control policies are administrative controls because they define rules, responsibilities and expected behaviour through documented management direction rather than technical enforcement. They satisfy the stem's requirement for administrative examples, unlike logical controls such as firewalls or physical controls such as locks.

  • ✓

    Security awareness training

    Why this is correct

    Security awareness training is an administrative control because it governs human behaviour through policy, education and procedure rather than technical enforcement. It satisfies the stem's requirement for administrative examples, unlike logical or physical controls such as firewalls, encryption or locks.

  • ✗

    Security guards

    Why it's wrong here

    Security guards are a physical control, enforcing deterrence and access through people and barriers, not policies or procedures. It is tempting because guards administer access, but administrative controls are documentation-based, such as security policies, awareness training and acceptable use agreements.

  • ✗

    Encryption of data at rest

    Why it's wrong here

    Encryption at rest is a technical control: it enforces protection through cryptographic mechanisms on the data itself, not through policy, procedure or training. It tempts because it is a recognised security safeguard, but administrative controls govern people and process, such as acceptable-use policies or security awareness training.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SSCP

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO of the following are examples of administrative controls in a security program? (Choose two.)

easy
  • ✓ A.Security policies
  • B.Firewall rules
  • C.Locks on server room doors
  • ✓ D.Employee background checks
  • E.Intrusion detection software

Why A: Administrative controls are management-driven, people-and-process safeguards rather than technical or physical mechanisms. Option A, security policies, is correct because written policies define required behavior, responsibilities, and governance, which is a classic administrative control. Option D, employee background checks, is correct because vetting personnel before hire is a procedural/administrative control that reduces insider risk. Option B, firewall rules, is a technical (logical) control enforced by network devices, so it does not belong. Option C, locks on server room doors, is a physical control, so it does not belong. Option E, intrusion detection software, is a technical detective control, so it does not belong.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.