Security controls: the four categories and the six types

Objective 1.1 · General Security Concepts · 12% of the exam

Objective 1.1 in this course covers security controls — CompTIA's scope note for it compares technical, preventive, managerial, deterrent, operational, detective, physical, corrective, compensating and directive controls. That is one list with two different things in it, and separating them is most of the work of this lesson.

Why this matters

This is the first objective of the exam and it is the one most likely to be tested indirectly for the rest of it. A question in Domain 4 about a SIEM, or in Domain 5 about an audit finding, will often resolve to "which control type is this?" — and if you cannot answer that quickly you lose time on questions that were not really about controls at all.

It is also the classic place to lose marks through overconfidence. Everyone knows what a firewall is. Far fewer people can say, under time pressure and without hedging, whether a firewall is preventive or detective, and whether it is technical or operational. Those are two separate questions with two separate answers, and CompTIA asks them separately.

The lesson

Technical, managerial, operational and physical, and why the category is about WHO implements it

CompTIA's four categories answer one question: by what means is this control implemented?

  • Technical controls are implemented by technology. A firewall rule, an access control list, disk encryption, a password policy enforced by the directory. The machine does the enforcing.
  • Managerial controls are implemented by management decision and documentation. A risk assessment, a security policy, a supplier vetting standard. People often call these "administrative".
  • Operational controls are implemented by people doing things. Awareness training, a guard checking badges, a change advisory board meeting, an incident response exercise.
  • Physical controls act on the physical world. Fences, bollards, locks, lighting, cameras, mantraps, badge readers.

The useful test is the one in the heading: ask who or what actually carries this out. A written policy saying "all laptops must be encrypted" is managerial. The BitLocker configuration that enforces it is technical. The annual reminder session that tells staff why is operational. The same control objective, three categories, because three different mechanisms deliver it.

Preventive, deterrent, detective, corrective, compensating and directive

The six types answer a different question: what does this control do about an incident, relative to when the incident happens?

  • Preventive stops it happening. A locked door. A firewall deny rule.
  • Deterrent discourages someone from trying. A warning sign, a visible camera, a login banner. Note that it does not stop anyone who is undeterred.
  • Detective notices that it happened, or is happening. Logs, IDS, a reconciliation report, a camera that is actually being watched.
  • Corrective puts things right afterwards. A backup restore, a patch, an incident response procedure that removes the malware.
  • Compensating is what you put in place when the control you should have cannot be used. It does not do the same job; it reduces the same risk another way.
  • Directive tells people what they are supposed to do. A policy, a procedure, a sign saying "authorised personnel only" in the sense of instructing rather than warning.

Every control has one category and one type, and the exam will hand you a scenario and ask for one or the other. Read which it wants before you answer.

The same control landing in different boxes depending on how it is used

A camera is the standard example and it is worth being precise about, because the answer genuinely changes with the wording.

  • A camera in plain sight, with a sign, is deterrent — its purpose in that sentence is to make someone not try.
  • A camera recording to storage nobody reviews until after an incident is detective — it tells you what happened.
  • A camera nobody can see, feeding a monitor a guard watches live, is still detective; the guard who then intervenes is the preventive part.

By category, a camera is physical in all three readings. The category rarely moves; the type moves with the scenario. When a question describes what the control is for, it is asking about type.

A second example that trips people: a password policy. The document is managerial and directive. The setting in Active Directory that enforces minimum length is technical and preventive. Same intent, four different correct answers depending on which half the question describes.

Compensating controls, and the audit finding they are written to answer

A compensating control exists because something else could not be done. A legacy application needs an unsupported version of a library; it cannot be patched without breaking the business process that pays for it. The required control — patch it — is unavailable. So you compensate: put the server on an isolated segment, allow only two named source addresses to reach it, log every connection, and review that log weekly.

That is not as good as patching, and a compensating control never claims to be. What it claims is that the residual risk has been brought down to something the organisation has agreed to accept, and that somebody senior enough has agreed to it in writing. Auditors accept compensating controls; they do not accept undocumented ones.

Two things make a compensating control real rather than an excuse: it addresses the same risk as the control it replaces, and it has an expiry — a date by which the proper control will be in place or the decision revisited. Domain 5's risk register lesson is where those get recorded.

Reading an exam question that gives you a scenario and wants one word back

These questions have a shape. Learn it and they become fast.

  1. Find the verb. "Which control type would detect…" — the word in the question usually is the answer's family. CompTIA is not always trying to trick you.
  2. Decide whether it wants category or type. "Technical" and "preventive" are not competing answers to the same question, but they will happily appear in the same option list.
  3. Ask when the control acts. Before, during, or after. That sorts preventive from detective from corrective in one step.
  4. If two answers both fit, prefer the more specific. A visible camera is physical and deterrent; if both appear and the question asked for type, the answer is deterrent.

What to take into the exam

  • Category answers how it is implemented — technical, managerial, operational, physical. Type answers what it does about the incident — preventive, deterrent, detective, corrective, compensating, directive.
  • The same device changes type with the scenario and rarely changes category.
  • A compensating control addresses the same risk by another route, is documented, and is approved by someone who can accept the residual risk.
  • Deterrent is about discouraging an attempt; preventive is about stopping one. A sign is deterrent, a lock is preventive.
  • Directive is the one people forget. It instructs. If the scenario is a policy telling staff what to do, directive is on the table.

Practise what you just read

1. A visible camera with a warning sign is installed at a loading bay. Which control TYPE does the sign and visibility make it?

Select one

  1. Deterrent
  2. Corrective
  3. Compensating
  4. A detective control, because the recorded footage will be reviewed by the security team after any reported incident
Show answer

A. Type answers what the control does about an incident. Making it visible and adding a sign is aimed at stopping somebody trying, which is deterrent. The same camera recording to storage that is reviewed afterwards is detective; the category, physical, does not change in either reading.

2. An organisation cannot patch a legacy application, so it isolates the server and restricts access to two addresses. What is this?

Select one

  1. A directive control, because the isolation is written into the operating procedure staff must follow
  2. A compensating control
  3. A preventive control
  4. An operational control
Show answer

B. A compensating control is put in place when the required control cannot be applied, and it reduces the same risk by another route. Isolation and access restriction do not patch anything; they bring the residual risk to a level someone has agreed to accept, which must be documented and given a review date.

3. Security awareness training delivered by staff to staff falls into which control CATEGORY?

Select one

  1. Technical
  2. Physical
  3. Operational
  4. Managerial, because the training requirement originates in the information security policy approved by senior management
Show answer

C. Category answers how a control is implemented. Training is carried out by people doing something, which is operational. The policy requiring it is managerial and the platform delivering it is technical, so the same objective can appear in three categories depending on which part the question describes.

8 more questions on this objective are part of the full course.

Practise the full question bank in the exam simulator

Hands-on labs

All hands-on labs

This is an independent study companion for CompTIA Security+ SY0-701 and is not produced by or endorsed by CompTIA.