CompTIA Cloud Essentials+ (CLO-002)Governance, Risk, Compliance and SecurityMedium
A cloud security architect configures network firewalls and web application firewalls to block malicious traffic before it can reach the organization's application servers. Which type of security control is being implemented?
- APreventive control
- BCorrective control
- CDetective control
- DCompensating control
Show answer & explanationAnswer & explanation
Correct answer: A. Preventive control
Preventive controls are designed to stop a security incident from occurring in the first place, such as firewalls blocking malicious traffic before it reaches servers. Detective controls identify incidents after they occur, corrective controls fix damage after an incident, and compensating controls are alternative measures used when the primary control cannot be implemented.
Why the other options are wrong
- B. Corrective controls act after damage has occurred to restore systems.
- C. Detective controls would alert on the traffic after it passed through, not block it.
- D. Compensating controls substitute for a missing primary control rather than actively blocking traffic.
Preventive Control
A security control designed to stop a security incident or unauthorized activity before it can occur.
- Examples: firewalls, encryption, access control lists
- Acts proactively, before an event happens
- Contrasts with detective controls, which act during/after an event
Memory trick: PDC-C: Prevent the fire, Detect the smoke, Correct the damage, Compensate if the sprinkler is broken.