CRISC Certified in Risk and Information Systems ControlInformation Technology and SecurityMedium

A retail company is planning to launch a new e-commerce website. The project team is considering various security controls. They decide to implement a Web Application Firewall (WAF) to protect against common web-based attacks like SQL injection and cross-site scripting (XSS). This implementation is an example of which type of security control?

  1. ADetective
  2. BCorrective
  3. CCompensating
  4. DPreventive
Show answer & explanation

Correct answer: D. Preventive

A Web Application Firewall (WAF) is designed to actively block or prevent attacks like SQL injection and XSS from reaching the web application. Therefore, it is a preventive control.

Why the other options are wrong

  • A. Detective controls identify incidents after they have occurred (e.g., intrusion detection systems).
  • B. Corrective controls fix issues after an incident (e.g., patching vulnerabilities).
  • C. Compensating controls are alternative controls used when a primary control cannot be implemented.

Preventive Control

A security control designed to stop an undesirable event from occurring.

  • Acts before an incident happens.
  • Aims to reduce likelihood of risk.
  • Examples include firewalls, access controls, encryption.

Memory trick: Prevent, Detect, Correct, Compensate.

More Information Technology and Security questions