CISSP Exam QuestionsBrowse all questions from this exam

CISSP Exam - Question 334


Employee training, risk management, and data handling procedures and policies could be characterized as which type of security measure?

Show Answer
Correct Answer: D

Employee training, risk management, and data handling procedures and policies are types of administrative security measures. Administrative security measures, also known as management controls, include the development and implementation of policies, procedures, and training programs designed to establish and enforce an organization's security framework. These measures are used to manage and control security practices, ensuring that proper protocols are followed to protect data and mitigate risks.

Discussion

21 comments
Sign in to comment
krasskoOption: D
Mar 26, 2023

Administrative includes preventive

jackdryan
Nov 14, 2023

D is correct

rc7
Apr 22, 2023

Answer is D. Employee training, risk management, and data handling procedures and policies are all part of Administrative security measures. Preventative measures are closely aligned put with technical measures.

stickerbush1970Option: A
Mar 15, 2023

Agree with A

dirk_gentley
Mar 19, 2023

Administrative Also known as management controls, these represent organizational policies and training regarding security. Common administrative controls include password policies, employee screening, training procedures, and compliance with legal regulations

CuteRabbit168Option: D
Mar 29, 2023

Examples of administrative controls include policies, procedures, hiring practices, background checks, data classifications and labeling, security awareness and training efforts, reports and reviews, work supervision, personnel controls, and testing.

NickolosOption: D
Apr 20, 2023

Administrative Security consists of policies, procedures, and personnel controls including security policies, training, and audits, technical training, supervision, separation of duties, rotation of duties, recruiting and termination procedures, user access control, background checks, performance evaluations, and disaster recovery, contingency, and emergency plans. These measures ensure that authorized users know and understand how to properly use the system in order to maintain security of data. It's D

YesPleaseOption: D
Jun 21, 2024

Answer D) Administrative There are three main types of IT security controls including technical, administrative, and physical. The primary goal for implementing a security control can be preventative, detective, corrective, compensatory, or act as a deterrent. https://purplesec.us/security-controls/

GregPOption: A
Mar 14, 2023

Preventative?

RollizoOption: A
Apr 1, 2023

Administrative controls is a category, preventive is a type

thanhlb
Apr 23, 2024

agree with A

JAckThePip
Apr 5, 2023

Be careful not to confuse security control with security measure. In this specific case it indicated measure therefore he correct answer is A

rdy4uOption: D
Apr 29, 2023

Administrative security controls refer to policies, procedures, or guidelines that define personnel or business practices in accordance with the organization's security goals.

Moose01
Nov 24, 2023

A. is the correct! Employee training - that means any one of the employee in the organization - not a particular employee. Preventive is when the organization train or send awareness emails, or posters.

xxxBadManxxx
Feb 15, 2024

correct answer is D: Employee training, risk management, and data handling procedures and policies could be characterized as Administrative Security Measures.

JamatiOption: A
May 13, 2023

It's preventative

Mann0302Option: A
May 16, 2023

A is correct as it is a type. B and D is the same thing.

IvanchunOption: D
Jun 27, 2023

D, procedure is the keywords

noname4Option: A
Aug 21, 2023

the keyword is "type" - so the correct Anwser is A Preventative see Study Guide Figure 2.4 and following sites

bherto39Option: D
Mar 27, 2024

Employee training, risk management, and data handling procedures and policies could be characterized as: D. Administrative These measures focus on managing and controlling security aspects within an organization, such as establishing policies, procedures, and training to ensure that security practices are followed and that risks are managed effectively.

Soleandheel
Jun 15, 2024

D. Administrative........employee training can make it seem like A is the correct answer but all the other activities mentioned are administrative controls and Employee training can also fall under that categroy making D. Administrative the best answer.

BigITGuyOption: D
Apr 3, 2025

NOT A. Preventative controls are a category (like technical, physical, or administrative) but the question asks for the type of control, not its function.

a_kto_toOption: D
May 2, 2025

Administrative security measures involve the policies, procedures, and practices that govern how an organization manages and protects its information and systems. This includes employee training, risk management processes, and data handling procedures, all of which are aimed at ensuring the security of the organization through proper management practices and governance.