CompTIA Cloud Essentials+ (CLO-002)Governance, Risk, Compliance and SecurityMedium
After detecting a ransomware infection on a cloud-hosted virtual machine, the organization's automated incident response system isolates the infected VM and restores the affected data from the most recent clean backup. Which type of security control does this action represent?
- ADeterrent control
- BDetective control
- CCorrective control
- DPreventive control
Show answer & explanationAnswer & explanation
Correct answer: C. Corrective control
Corrective controls act after an incident has been detected to limit damage and restore systems to a known-good state, such as restoring data from backup after ransomware infection. Preventive controls would have stopped the infection beforehand, detective controls would only identify the infection, and deterrent controls discourage attackers rather than remediate damage.
Why the other options are wrong
- A. Deterrent controls discourage attacks rather than fix systems after compromise.
- B. Detective controls only identify the problem; restoring from backup goes beyond detection.
- D. Preventive controls act before the incident, but the infection already occurred here.
Corrective Control
A security control that responds to and remediates the effects of a security incident after it has occurred.
- Examples: restoring from backup, patching a vulnerability, quarantining infected hosts
- Applied after detection has already identified the incident
- Goal is to return systems to normal, secure operation
Memory trick: PDC-C: Prevent the fire, Detect the smoke, Correct the damage, Compensate if the sprinkler is broken.