Cisco CyberOps Associate (CBROPS) 200-201Security Policies and ProceduresMedium
A new employee, unfamiliar with the organization's data handling guidelines, inadvertently uploads sensitive customer data to a publicly accessible cloud storage service. This incident highlights a gap in the organization's security posture. Which type of security control, if adequately implemented, would have been most effective in preventing this particular incident?
- AAdministrative control
- BPhysical control
- CTechnical control
- DCompensating control
Show answer & explanationAnswer & explanation
Correct answer: A. Administrative control
Security awareness and training, which falls under administrative controls, would have educated the employee on proper data handling, directly preventing the inadvertent data leak.
Why the other options are wrong
- B. Physical controls protect physical assets, not data handling practices by employees.
- C. Technical controls (e.g., DLP) could detect/prevent, but the root cause here is lack of awareness.
- D. Compensating controls address deficiencies when primary controls are not feasible, but here a primary control (training) is missing.
Administrative Security Controls
Security controls that involve policies, procedures, guidelines, and training to manage security risks.
- Focus on human behavior and organizational processes.
- Examples include security policies, incident response plans, and security awareness training.
- Often the first line of defense against human error.
Memory trick: Think PAT for controls: Physical, Administrative, Technical.