SY0-701 Question 5
Single answerControl types: Preventive , Deterrent , Detective , Corrective , Compensating , DirectiveA healthcare organization stores patient records in a legacy application that cannot support modern multifactor authentication. The security team must reduce the risk of unauthorized access while the application is being replaced next year. Management wants a control that provides equivalent risk reduction when the preferred control cannot be implemented because of a technical limitation. Which control type best fits this requirement?
- A
Compensating control
- B
Corrective control
- C
Detective control
- D
Directive control
- E
Deterrent control
Show answer and explanation
Correct answer: A
Explanation
The best answer is compensating control. In Security+ and common security governance practice, compensating controls are implemented when a recommended or required control cannot be used as intended, often because of legacy technology, cost, or operational constraints. The key distinction is that the substitute control should provide comparable risk reduction. This aligns with real-world security frameworks and audit practices, where organizations document why the primary control is not feasible and what alternative safeguards are used instead. By contrast, preventive controls stop incidents before they happen, detective controls identify incidents, corrective controls restore systems after incidents, deterrent controls discourage violations, and directive controls instruct users and administrators on expected behavior.
- A. Correct.
Correct. A compensating control is used when the ideal or primary control cannot be implemented due to technical, operational, or business constraints, but another control is put in place to reduce risk to an acceptable level. In this scenario, the legacy application cannot support MFA, so the organization would use alternative measures, such as restricting access through a jump box, enforcing stronger network segmentation, or increasing monitoring, as compensating controls.
- B. Incorrect.
Incorrect. Corrective controls are intended to fix or remediate an issue after an event occurs. Examples include restoring from backup, reimaging a system, or applying a patch after a vulnerability is identified. The scenario is focused on reducing risk before unauthorized access occurs, not recovering afterward.
- C. Incorrect.
Incorrect. Detective controls identify or alert on events that have already happened or are in progress, such as log reviews, SIEM alerts, or intrusion detection systems. While detective controls might be part of the overall solution, the question specifically asks for the control type used when the preferred control cannot be implemented and an alternative is needed to provide similar risk reduction.
- D. Incorrect.
Incorrect. Directive controls guide behavior through policies, procedures, standards, and training. For example, an access control policy may require MFA for remote access. However, a directive control does not itself provide the substitute technical or operational protection described in the scenario.
- E. Incorrect.
Incorrect. Deterrent controls are designed to discourage undesirable actions, such as warning banners, visible cameras, or security lighting. These can reduce opportunistic misuse, but they do not specifically address the need for an alternative safeguard that compensates for a missing primary control in a legacy system.