SY0-701 exam dumps

SY0-701 practice question 6 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 6

Single answerControl types: Preventive , Deterrent , Detective , Corrective , Compensating , Directive

A healthcare company operates a legacy radiology system that cannot support modern endpoint protection software without causing system instability. The security team still needs to reduce the risk of malware spreading from that system while the vendor works on an upgrade. Which control type best describes placing the radiology system on a restricted VLAN with tightly limited firewall rules and additional monitoring to reduce the risk created by the unsupported security capability?

  1. A

    Preventive control

  2. B

    Detective control

  3. C

    Compensating control

  4. D

    Directive control

  5. E

    Deterrent control

Show answer and explanation

Correct answer: C

Explanation

The key to this question is distinguishing between the functional effect of a control and the reason it is being used. Network segmentation and firewall rules can absolutely be preventive controls in many contexts because they block or limit unwanted access. However, in this scenario they are specifically being used as an alternate safeguard because the preferred control, endpoint protection on the legacy system, cannot be implemented. That is the classic definition of a compensating control.

This distinction appears in common security practice and governance models: when a required or preferred control is not feasible, organizations document an exception and implement other measures that provide comparable risk reduction. Examples include isolating unsupported systems, limiting administrative access, increasing logging, and applying stricter network filtering. This approach aligns with best practices described in control frameworks and guidance such as NIST SP 800-53, which discusses control selection and tailoring, and PCI DSS, which explicitly uses the term compensating controls for alternate measures that meet the intent and rigor of the original requirement.

In exam scenarios, watch for wording such as 'cannot support,' 'not feasible,' 'legacy system,' 'business constraint,' or 'temporary alternative.' Those clues often indicate compensating controls rather than simply preventive, detective, or corrective controls.

  • A. Incorrect.

    A preventive control is designed to stop an event from occurring in the first place, such as application allowlisting, MFA, or network segmentation. While the restricted VLAN and firewall rules do have preventive elements, the key detail in the scenario is that they are being implemented because the primary control, endpoint protection on the host, cannot be used. That makes this a compensating control rather than simply classifying it at the higher level as preventive.

  • B. Incorrect.

    A detective control identifies or records events after or as they occur, such as log monitoring, SIEM alerts, IDS, or CCTV review. The scenario does mention additional monitoring, which is detective in nature, but the overall question asks for the control type that best describes the alternative security measure used to address the missing host-based protection. That is not primarily detective.

  • C. Correct.

    A compensating control is the best answer because it is an alternative safeguard used when the preferred or standard control cannot be implemented due to technical, operational, or business constraints. In this case, the legacy radiology system cannot run endpoint protection, so the organization uses segmentation, restrictive firewall rules, and monitoring to reduce risk in another way. This matches the definition of a compensating control commonly used in frameworks and real-world exception handling.

  • D. Incorrect.

    A directive control tells people what they are supposed to do through policies, standards, procedures, or training. Examples include an acceptable use policy or incident response procedures. The scenario is focused on a technical risk-reduction measure implemented because of a system limitation, not on guidance or instruction to personnel.

  • E. Incorrect.

    A deterrent control is intended to discourage malicious activity, such as warning banners, visible guards, or prominent camera signage. Although deterrent controls may influence behavior, the restricted VLAN and firewall rules in the scenario are not primarily there to discourage action; they are there to offset the inability to deploy the normal host protection.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam