Cisco Certified Support Technician (CCST) CybersecurityVulnerability ManagementMedium

A cybersecurity team has discovered a critical zero-day vulnerability in a proprietary internal application. There is no patch available from the vendor, and the development team cannot provide an immediate fix. To protect the application while a permanent solution is developed, the security team decides to isolate the application on a dedicated network segment with strict firewall rules and implement multi-factor authentication (MFA) for all access. What type of control best describes the firewall rules and MFA in this scenario?

  1. ADetective Controls
  2. BPreventive Controls
  3. CRecovery Controls
  4. DCorrective Controls
Show answer & explanation

Correct answer: B. Preventive Controls

Firewall rules and multi-factor authentication are implemented to prevent unauthorized access or exploitation from occurring in the first place. They are proactive measures designed to stop an attack before it succeeds, thus classifying them as preventive controls.

Why the other options are wrong

  • A. Detective controls identify incidents after they occur, like security logs or IDS.
  • C. Recovery controls restore systems to normal operation after an incident, like disaster recovery plans.
  • D. Corrective controls fix issues after they occur, such as patching or restoring backups.

Preventive Control

A preventive control is a security measure designed to deter or stop unauthorized actions or events from occurring.

  • Acts proactively to reduce the likelihood of an attack or incident.
  • Examples include firewalls, access controls, encryption, and security awareness training.
  • Aims to block threats before they can impact systems or data.

Memory trick: PDRC: Prevent, Detect, Recover, Correct.

More Vulnerability Management questions