CompTIA Cloud Essentials+ (CLO-002)Governance, Risk, Compliance and SecurityHard
A security operations team configures a SIEM platform to automatically generate alerts whenever unusual login patterns are observed on cloud administrator accounts, allowing analysts to investigate potential compromises shortly after they occur. Which category of security control does this represent?
- ADeterrent control
- BCompensating control
- CDetective control
- DPreventive control
Show answer & explanationAnswer & explanation
Correct answer: C. Detective control
A detective control identifies and alerts on security events after they occur, allowing for investigation and response; SIEM alerting on anomalous logins is a classic example since it detects rather than prevents the activity.
Why the other options are wrong
- A. Deterrent controls discourage bad behavior through visible warnings, not active monitoring.
- B. Compensating controls are alternative safeguards used when a primary control cannot be implemented.
- D. Preventive controls stop an incident before it happens, such as firewalls blocking unauthorized traffic.
Detective Control
A security control designed to identify and alert on security incidents or policy violations after they have occurred, enabling investigation and response.
- Examples include SIEM alerts, IDS, and audit logs
- Does not prevent the incident, only detects it
- Complements preventive controls in a layered defense strategy
Memory trick: Detective = the 'detective' who spots the crime after it happens