CompTIA Security+ (SY0-701)General Security ConceptsMedium

A security analyst is investigating a suspected data breach. Forensic analysis reveals that an attacker gained access to a database containing sensitive customer information. To prevent future unauthorized access to this data, the analyst recommends implementing a control that will prevent the database from being accessed directly from the internet, and instead require all access to pass through a web application firewall (WAF) and an intrusion prevention system (IPS). Which type of control category is the analyst recommending?

  1. APreventative
  2. BDeterrent
  3. CDetective
  4. DCorrective
Show answer & explanation

Correct answer: A. Preventative

The recommendation focuses on stopping unauthorized access before it happens by forcing traffic through security devices. This proactive approach categorizes the control as preventative, as it aims to prevent an incident from occurring.

Why the other options are wrong

  • B. Deterrent controls aim to discourage attacks but do not actively stop them.
  • C. Detective controls identify incidents after they have occurred.
  • D. Corrective controls reduce the impact of an incident after it has occurred.

Preventative Control

A type of security control designed to stop an incident from occurring by actively blocking or mitigating threats.

  • Acts proactively to prevent security breaches.
  • Examples include firewalls, access control lists, and encryption.
  • Part of an organization's defense-in-depth strategy.

Memory trick: Preventing problems before they pop up is always preferred.

More General Security Concepts questions