Courseiva
hardMultiple Choice

SSCP Practice Question: An organization's risk register shows a high risk…

An organization's risk register shows a high risk for phishing attacks. Which controls are considered detective controls for this risk?

⚠ Common exam trap

ISC2 often tests the distinction between preventive and detective controls, and the trap here is that candidates confuse 'user reporting' as a reactive or corrective control rather than recognizing it as a detective control that identifies an ongoing or past incident.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

User reporting mechanism.

A user reporting mechanism is a detective control because it enables users to identify and report suspected phishing emails after they have been received, allowing the security team to investigate and respond. Unlike preventive controls that block attacks, detective controls discover incidents that have already occurred, such as a user recognizing a malicious link or attachment in their inbox.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Security awareness training.

    Why it's wrong here

    Training changes user behaviour before an attack, making it preventive rather than detective; it generates no alert once a phishing email arrives. It is tempting because awareness programmes are a standard phishing countermeasure, and they would be the right answer if the question asked for a preventive administrative control.

  • ✗

    Email filtering.

    Why it's wrong here

    Filtering blocks or quarantines messages before delivery, which is preventive; detection requires logging or alerting on mail that evades the filter. It is tempting because filtering is the primary phishing control, and it would be correct if the question asked for a preventive technical control.

  • ✓

    User reporting mechanism.

    Why this is correct

    A user reporting mechanism detects phishing attempts when recipients flag suspicious emails, enabling the security team to investigate and respond. It satisfies the scenario's need for a detective control by identifying incidents that bypass preventive filters, rather than blocking them outright. Reporting provides the visibility required to confirm an active phishing campaign.

  • ✗

    Multi-factor authentication.

    Why it's wrong here

    MFA blocks credential use at authentication, so it is preventive; it detects nothing about a phishing message itself. It is tempting because MFA is a flagship phishing mitigation, and it would be correct if the stem asked which control stops stolen credentials from being replayed.

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.