Courseiva
easyMultiple SelectObjective-mapped

Administrative Controls: Policies and Training

Which TWO of the following are examples of administrative controls? (Choose two.)

Quick Answer

Security awareness training qualifies as an administrative control because administrative controls are defined by what they govern, meaning people, processes, and policy, rather than by physical barriers or technical enforcement mechanisms. Training programs work by shaping human behavior and knowledge: teaching employees to recognize phishing attempts, follow proper data-handling procedures, and understand their security responsibilities, which reduces the likelihood of human error becoming the weak link in the organization's defenses. Access control policies belong in the same category for a related reason; they're the documented rules, procedures, and assigned responsibilities that establish how access should be managed, providing the governance framework that technical controls, like an actual access control system, and physical controls, like badge readers, are then built to implement. Neither training nor policy directly blocks or physically prevents anything on its own; instead, they set expectations, build capability, and define rules that other layers of control then enforce or that people are expected to follow voluntarily. This is the key distinction from technical controls, which use hardware or software to directly enforce restrictions, and physical controls, which use tangible barriers. When a question asks you to classify a control, ask whether it works through documented policy, procedure, or human education, and if so, it's administrative, regardless of what topic it happens to address.

⚠ Common exam trap

Many exam-takers confuse administrative controls with technical or physical controls, mistakenly selecting firewall rules or encryption because they are common security measures, but the SSCP exam specifically tests the distinction between administrative (policy/training), technical (software/hardware), and physical (guards/locks) control categories.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Access control policies

Access control policies (B) are administrative controls because they define the rules, procedures, and responsibilities for managing access to resources, forming the governance framework that guides technical and physical implementations. Security awareness training (C) is also an administrative control as it educates users on security policies and procedures, reducing human error and reinforcing organizational security culture.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Firewall rules

    Why it's wrong here

    Firewalls are technical controls.

  • Access control policies

    Why this is correct

    Policies are administrative controls.

  • Security awareness training

    Why this is correct

    Training is an administrative control.

  • Security guards

    Why it's wrong here

    Guards are physical controls.

  • Encryption of data at rest

    Why it's wrong here

    Encryption is a technical control.

About these practice questions

One of 920 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SSCP

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO of the following are examples of administrative controls in a security program? (Choose two.)

easy
  • A.Security policies
  • B.Firewall rules
  • C.Locks on server room doors
  • D.Employee background checks
  • E.Intrusion detection software

Why A: Security policies (A) are administrative controls because they define the rules, responsibilities, and expected behaviors for users and administrators, forming the foundation of a security program. Employee background checks (D) are also administrative controls, as they are personnel vetting procedures that reduce insider risk and enforce trust before granting access. Both are non-technical, process-based measures that guide human actions rather than directly blocking or detecting threats.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.