SY0-701 Question 4
Single answerCategories: Technical , Managerial , Operational , PhysicalA company is preparing for an external audit after several security weaknesses were identified at its headquarters. Investigators found that server room doors were often propped open by contractors, employees had not completed annual security awareness training, privileged access reviews had not been performed in over a year, and several workstations were still missing endpoint protection updates. The security manager wants to categorize each issue correctly so the right control owners can be assigned. Which option lists the issues in the correct order of control categories: endpoint protection updates, access review process, security awareness training, and server room door controls?
- A
Technical, Managerial, Operational, Physical
- B
Operational, Technical, Managerial, Physical
- C
Technical, Operational, Managerial, Physical
- D
Physical, Managerial, Operational, Technical
Show answer and explanation
Correct answer: A
Explanation
Security+ expects candidates to distinguish among common control categories and apply them in real scenarios. Technical controls are enforced by systems or devices, such as endpoint protection, encryption, and firewalls. Managerial controls focus on governance, risk management, policies, and oversight activities, such as account reviews, risk assessments, and policy approval. Operational controls are people-driven and process-oriented, including training, incident response procedures, and change management execution. Physical controls protect facilities and assets through mechanisms such as locks, guards, badges, fences, and mantraps. This mapping aligns with widely used security frameworks and guidance, including NIST control families and standard Security+ domain treatment of administrative/managerial, operational, technical, and physical safeguards.
- A. Correct.
Correct. Endpoint protection updates are a technical control because they are implemented through technology such as EDR/antivirus platforms and patching mechanisms on systems. The access review process is a managerial control because it is part of governance, oversight, and administrative decision-making about who should retain privileges. Security awareness training is an operational control because it is carried out through people and day-to-day security procedures. Server room door controls are physical controls because they protect facilities and hardware through barriers, locks, and access restrictions.
- B. Incorrect.
Incorrect. This option reverses the first two categories. Endpoint protection updates are not primarily operational controls; while staff may perform them, the control itself is technical because it relies on security software and system configurations. Likewise, access reviews are not technical controls; they are managerial/administrative because they involve policy enforcement, approval, and governance.
- C. Incorrect.
Incorrect. The first category is correct, but the second and third are swapped. Access reviews are generally categorized as managerial controls because they support oversight, compliance, and risk management. Security awareness training is typically operational because it is executed as part of ongoing security operations and user-facing processes.
- D. Incorrect.
Incorrect. This option misclassifies nearly every item. Endpoint protection updates are not physical controls, and server room door controls are not technical in this context. While some doors may use technical components such as badge readers, the control category for protecting the room itself is physical.