SY0-701 exam dumps

SY0-701 practice question 5 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 5

Single answerControl types: Preventive , Deterrent , Detective , Corrective , Compensating , Directive

A healthcare organization stores patient records in a legacy application that cannot support modern multifactor authentication. The security team must reduce the risk of unauthorized access while the application is being replaced next year. Management wants a control that provides equivalent risk reduction when the preferred control cannot be implemented because of a technical limitation. Which control type best fits this requirement?

  1. A

    Compensating control

  2. B

    Corrective control

  3. C

    Detective control

  4. D

    Directive control

  5. E

    Deterrent control

Show answer and explanation

Correct answer: A

Explanation

The best answer is compensating control. In Security+ and common security governance practice, compensating controls are implemented when a recommended or required control cannot be used as intended, often because of legacy technology, cost, or operational constraints. The key distinction is that the substitute control should provide comparable risk reduction. This aligns with real-world security frameworks and audit practices, where organizations document why the primary control is not feasible and what alternative safeguards are used instead. By contrast, preventive controls stop incidents before they happen, detective controls identify incidents, corrective controls restore systems after incidents, deterrent controls discourage violations, and directive controls instruct users and administrators on expected behavior.

  • A. Correct.

    Correct. A compensating control is used when the ideal or primary control cannot be implemented due to technical, operational, or business constraints, but another control is put in place to reduce risk to an acceptable level. In this scenario, the legacy application cannot support MFA, so the organization would use alternative measures, such as restricting access through a jump box, enforcing stronger network segmentation, or increasing monitoring, as compensating controls.

  • B. Incorrect.

    Incorrect. Corrective controls are intended to fix or remediate an issue after an event occurs. Examples include restoring from backup, reimaging a system, or applying a patch after a vulnerability is identified. The scenario is focused on reducing risk before unauthorized access occurs, not recovering afterward.

  • C. Incorrect.

    Incorrect. Detective controls identify or alert on events that have already happened or are in progress, such as log reviews, SIEM alerts, or intrusion detection systems. While detective controls might be part of the overall solution, the question specifically asks for the control type used when the preferred control cannot be implemented and an alternative is needed to provide similar risk reduction.

  • D. Incorrect.

    Incorrect. Directive controls guide behavior through policies, procedures, standards, and training. For example, an access control policy may require MFA for remote access. However, a directive control does not itself provide the substitute technical or operational protection described in the scenario.

  • E. Incorrect.

    Incorrect. Deterrent controls are designed to discourage undesirable actions, such as warning banners, visible cameras, or security lighting. These can reduce opportunistic misuse, but they do not specifically address the need for an alternative safeguard that compensates for a missing primary control in a legacy system.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam