CISSP Exam QuestionsBrowse all questions from this exam

CISSP Exam - Question 342


Which of the following are the three MAIN categories of security controls?

Show Answer
Correct Answer: B

The three main categories of security controls are administrative, technical, and physical. Administrative controls involve policies, procedures, and guidelines. Technical controls involve hardware and software to protect systems and data. Physical controls involve measures taken to protect physical assets and environments.

Discussion

4 comments
Sign in to comment
rdy4uOption: B
Apr 29, 2024

There are three main types of IT security controls including technical, administrative, and physical. The primary goal for implementing a security control can be preventative, detective, corrective, compensatory, or act as a deterrent. Controls are also used to protect people as is the case with social engineering awareness training or policies. https://purplesec.us/security-controls/

jackdryan
Nov 14, 2024

B is correct

DJOEKOption: B
Jul 12, 2024

answer is good. Simple knowledge question

Wilsonge1Option: A
Feb 25, 2025

Administrative, technical, and administrative are types. The three categories are Preventive, Corrective, and Detective

a_kto_toOption: B
May 2, 2025

The three MAIN categories of security controls refer to how the controls are implemented or applied in a system: Administrative Controls – Policies, procedures, training, and guidelines (e.g., security awareness training, hiring practices). Technical Controls – Also known as logical controls, these use technology to reduce risk (e.g., firewalls, encryption, access control lists). Physical Controls – Controls that prevent or deter physical access (e.g., locks, security guards, fences).