easyMultiple SelectObjective-mapped
Administrative Controls: Policies and Training
Which TWO of the following are examples of administrative controls? (Choose two.)
Quick Answer
Security awareness training qualifies as an administrative control because administrative controls are defined by what they govern, meaning people, processes, and policy, rather than by physical barriers or technical enforcement mechanisms. Training programs work by shaping human behavior and knowledge: teaching employees to recognize phishing attempts, follow proper data-handling procedures, and understand their security responsibilities, which reduces the likelihood of human error becoming the weak link in the organization's defenses. Access control policies belong in the same category for a related reason; they're the documented rules, procedures, and assigned responsibilities that establish how access should be managed, providing the governance framework that technical controls, like an actual access control system, and physical controls, like badge readers, are then built to implement. Neither training nor policy directly blocks or physically prevents anything on its own; instead, they set expectations, build capability, and define rules that other layers of control then enforce or that people are expected to follow voluntarily. This is the key distinction from technical controls, which use hardware or software to directly enforce restrictions, and physical controls, which use tangible barriers. When a question asks you to classify a control, ask whether it works through documented policy, procedure, or human education, and if so, it's administrative, regardless of what topic it happens to address.
⚠ Common exam trap
Many exam-takers confuse administrative controls with technical or physical controls, mistakenly selecting firewall rules or encryption because they are common security measures, but the SSCP exam specifically tests the distinction between administrative (policy/training), technical (software/hardware), and physical (guards/locks) control categories.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Access control policies
Access control policies (B) are administrative controls because they define the rules, procedures, and responsibilities for managing access to resources, forming the governance framework that guides technical and physical implementations. Security awareness training (C) is also an administrative control as it educates users on security policies and procedures, reducing human error and reinforcing organizational security culture.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Firewall rules
Why it's wrong here
Firewalls are technical controls.
- ✓
Access control policies
Why this is correct
Policies are administrative controls.
- ✓
Security awareness training
Why this is correct
Training is an administrative control.
- ✗
Security guards
Why it's wrong here
Guards are physical controls.
- ✗
Encryption of data at rest
Why it's wrong here
Encryption is a technical control.
Go deeper
Related to this question
About these practice questions
One of 920 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SSCP
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO of the following are examples of administrative controls in a security program? (Choose two.)
easy- ✓ A.Security policies
- B.Firewall rules
- C.Locks on server room doors
- ✓ D.Employee background checks
- E.Intrusion detection software
Why A: Security policies (A) are administrative controls because they define the rules, responsibilities, and expected behaviors for users and administrators, forming the foundation of a security program. Employee background checks (D) are also administrative controls, as they are personnel vetting procedures that reduce insider risk and enforce trust before granting access. Both are non-technical, process-based measures that guide human actions rather than directly blocking or detecting threats.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.