EC-Council Certified Ethical Hacker (CEH) v12Information Security and Ethical Hacking OverviewHard

A software development company mandates that all code changes must undergo a peer review process, followed by automated static code analysis, and then dynamic application security testing (DAST) before deployment. This multi-faceted approach aims to catch vulnerabilities at different stages of the development and testing lifecycle. Which type of information security control is being most effectively implemented here?

  1. ADetective Control
  2. BPreventive Control
  3. CDeterrent Control
  4. DCompensating Control
Show answer & explanation

Correct answer: A. Detective Control

Detective controls are designed to identify and alert about security incidents or policy violations after they have occurred or are in progress. Peer reviews, static code analysis, and DAST primarily aim to *find* vulnerabilities or flaws, even if they are caught before deployment, they are 'detecting' issues that already exist in the code rather than preventing their creation in the first place.

Why the other options are wrong

  • B. Preventive controls stop an attack or vulnerability from occurring (e.g., strong encryption, input validation). While these tools aim to find issues 'before deployment', their core function is to detect existing flaws, not prevent their initial creation.
  • C. Deterrent controls discourage potential attackers (e.g., warning banners), which is not what these testing methods do.
  • D. Compensating controls are alternative controls used when a primary control cannot be implemented, which isn't the primary function here.

Detective Controls

Security controls designed to identify and alert about security events, incidents, or policy violations after they have occurred or are in progress, providing visibility into vulnerabilities and attacks.

  • Identifies existing issues or ongoing attacks.
  • Examples: IDS, SIEM, audits, logging, code reviews, vulnerability scans.
  • Crucial for incident response and accountability.
  • Provides information for improving preventive controls.

Memory trick: Prevent, Detect, Correct: the PDC of security.

More Information Security and Ethical Hacking Overview questions