CompTIA Security+ (SY0-701)Security Program Management and OversightHard

A PCI DSS assessment reveals that a legacy point-of-sale system cannot support encryption of stored cardholder data as normally required. To address this gap, the organization implements additional network segmentation, restrictive access controls, and enhanced monitoring around the legacy system. What type of control has the organization implemented?

  1. ACompensating control
  2. BCorrective control
  3. CDeterrent control
  4. DDetective control
Show answer & explanation

Correct answer: A. Compensating control

A compensating control is an alternative safeguard implemented when the primary required control cannot be met, providing equivalent protection through other means.

Why the other options are wrong

  • B. Corrective controls restore systems after an incident, not substitute for a missing safeguard.
  • C. Deterrent controls discourage attackers (e.g., warning banners) rather than substitute for an unmet requirement.
  • D. Detective controls identify that an event occurred; monitoring here is only part of a broader compensating strategy, not the category itself.

Compensating Control

An alternative security measure implemented when a required control cannot be directly applied, providing equivalent risk mitigation.

  • Common in compliance frameworks like PCI DSS when a specific requirement can't be met
  • Must provide a similar level of protection as the original control
  • Combines multiple safeguards (e.g., segmentation + monitoring) to offset the gap

Memory trick: Compensating = 'making up for' what's missing.

More Security Program Management and Oversight questions