easyMultiple Select
Administrative Controls: Policies and Training
Which TWO of the following are examples of administrative controls? (Choose two.)
Quick Answer
Security awareness training qualifies as an administrative control because administrative controls are defined by what they govern, meaning people, processes, and policy, rather than by physical barriers or technical enforcement mechanisms. Training programs work by shaping human behavior and knowledge: teaching employees to recognize phishing attempts, follow proper data-handling procedures, and understand their security responsibilities, which reduces the likelihood of human error becoming the weak link in the organization's defenses. Access control policies belong in the same category for a related reason; they're the documented rules, procedures, and assigned responsibilities that establish how access should be managed, providing the governance framework that technical controls, like an actual access control system, and physical controls, like badge readers, are then built to implement. Neither training nor policy directly blocks or physically prevents anything on its own; instead, they set expectations, build capability, and define rules that other layers of control then enforce or that people are expected to follow voluntarily. This is the key distinction from technical controls, which use hardware or software to directly enforce restrictions, and physical controls, which use tangible barriers. When a question asks you to classify a control, ask whether it works through documented policy, procedure, or human education, and if so, it's administrative, regardless of what topic it happens to address.
⚠ Common exam trap
Many exam-takers confuse administrative controls with technical or physical controls, mistakenly selecting firewall rules or encryption because they are common security measures, but the SSCP exam specifically tests the distinction between administrative (policy/training), technical (software/hardware), and physical (guards/locks) control categories.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Access control policies
Access control policies (B) are administrative controls because they define the rules, procedures, and responsibilities for managing access to resources, forming the governance framework that guides technical and physical implementations. Security awareness training (C) is also an administrative control as it educates users on security policies and procedures, reducing human error and reinforcing organizational security culture.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Firewall rules
Why it's wrong here
Firewall rules are a technical control, enforced by network equipment inspecting traffic, not by organisational policy. It is tempting because rules are written down, but administrative controls are procedural documents such as policies, standards, guidelines and security awareness training.
- ✓
Access control policies
Why this is correct
Access control policies are administrative controls because they define rules, responsibilities and expected behaviour through documented management direction rather than technical enforcement. They satisfy the stem's requirement for administrative examples, unlike logical controls such as firewalls or physical controls such as locks.
- ✓
Security awareness training
Why this is correct
Security awareness training is an administrative control because it governs human behaviour through policy, education and procedure rather than technical enforcement. It satisfies the stem's requirement for administrative examples, unlike logical or physical controls such as firewalls, encryption or locks.
- ✗
Security guards
Why it's wrong here
Security guards are a physical control, enforcing deterrence and access through people and barriers, not policies or procedures. It is tempting because guards administer access, but administrative controls are documentation-based, such as security policies, awareness training and acceptable use agreements.
- ✗
Encryption of data at rest
Why it's wrong here
Encryption at rest is a technical control: it enforces protection through cryptographic mechanisms on the data itself, not through policy, procedure or training. It tempts because it is a recognised security safeguard, but administrative controls govern people and process, such as acceptable-use policies or security awareness training.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SSCP
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO of the following are examples of administrative controls in a security program? (Choose two.)
easy- ✓ A.Security policies
- B.Firewall rules
- C.Locks on server room doors
- ✓ D.Employee background checks
- E.Intrusion detection software
Why A: Administrative controls are management-driven, people-and-process safeguards rather than technical or physical mechanisms. Option A, security policies, is correct because written policies define required behavior, responsibilities, and governance, which is a classic administrative control. Option D, employee background checks, is correct because vetting personnel before hire is a procedural/administrative control that reduces insider risk. Option B, firewall rules, is a technical (logical) control enforced by network devices, so it does not belong. Option C, locks on server room doors, is a physical control, so it does not belong. Option E, intrusion detection software, is a technical detective control, so it does not belong.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.