SSCP Security Operations and Administration Practice Question
An organization's security policy requires that all portable media containing sensitive data be encrypted. Which type of control does this requirement represent?
⚠ Common exam trap
ISC2 SSCP exams test the distinction between administrative and technical controls. The requirement to encrypt is a policy (administrative control), while the encryption algorithm itself is a technical control. Candidates often select 'Technical control' because they focus on the encryption mechanism rather than the mandate.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Administrative control
This requirement is an administrative control because it is a policy mandate that defines rules and procedures for handling sensitive data. Administrative controls are management directives, such as security policies, standards, and guidelines, that govern behavior and processes. The encryption itself is a technical control, but the requirement to encrypt is a policy statement, which falls under administrative controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Detective control
Why it's wrong here
Encryption of portable media is a preventive control: it stops unauthorised disclosure before it occurs. Detective controls identify events after the fact, such as log monitoring or file integrity checks. The option is tempting because encryption's ciphertext could later reveal tampering, but the policy mandates protection, not detection.
- ✓
Administrative control
Why this is correct
Administrative controls are policy-level directives governing behaviour, and the stem's requirement is precisely a mandated rule rather than a technical mechanism. Encryption itself is the technical control; the policy compelling its use on portable media is administrative. It satisfies the constraint by defining expected practise without enforcing it through hardware or software.
- ✗
Technical control
Why it's wrong here
Encryption is applied by software or hardware mechanisms, making it technical; a policy statement itself is administrative. It tempts because the requirement originates in policy, but the control implemented is the encryption mechanism, so administrative is wrong here.
- ✗
Physical control
Why it's wrong here
Encrypting portable media is a logical or technical safeguard applied to data, not a barrier restricting physical access to facilities or devices. Physical controls are tempting because portable media itself is a tangible asset, and locks, cages, and locked cabinets are the correct choice when the requirement is to prevent physical theft or contact.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.