hardMultiple Choice
SSCP Practice Question: An organization's risk register shows a high risk…
An organization's risk register shows a high risk for phishing attacks. Which controls are considered detective controls for this risk?
⚠ Common exam trap
ISC2 often tests the distinction between preventive and detective controls, and the trap here is that candidates confuse 'user reporting' as a reactive or corrective control rather than recognizing it as a detective control that identifies an ongoing or past incident.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
User reporting mechanism.
A user reporting mechanism is a detective control because it enables users to identify and report suspected phishing emails after they have been received, allowing the security team to investigate and respond. Unlike preventive controls that block attacks, detective controls discover incidents that have already occurred, such as a user recognizing a malicious link or attachment in their inbox.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Security awareness training.
Why it's wrong here
Training changes user behaviour before an attack, making it preventive rather than detective; it generates no alert once a phishing email arrives. It is tempting because awareness programmes are a standard phishing countermeasure, and they would be the right answer if the question asked for a preventive administrative control.
- ✗
Email filtering.
Why it's wrong here
Filtering blocks or quarantines messages before delivery, which is preventive; detection requires logging or alerting on mail that evades the filter. It is tempting because filtering is the primary phishing control, and it would be correct if the question asked for a preventive technical control.
- ✓
User reporting mechanism.
Why this is correct
A user reporting mechanism detects phishing attempts when recipients flag suspicious emails, enabling the security team to investigate and respond. It satisfies the scenario's need for a detective control by identifying incidents that bypass preventive filters, rather than blocking them outright. Reporting provides the visibility required to confirm an active phishing campaign.
- ✗
Multi-factor authentication.
Why it's wrong here
MFA blocks credential use at authentication, so it is preventive; it detects nothing about a phishing message itself. It is tempting because MFA is a flagship phishing mitigation, and it would be correct if the stem asked which control stops stolen credentials from being replayed.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.