Security controls: the four categories and the six types
This course teaches SY0-801, the Security+ exam that launches on or around 17 November 2026. If you are booked on SY0-701, which can be taken until 11 June 2027, use our SY0-701 course instead.
Listen to this lesson
Every episode of this course is also a podcast: listen on Spotify.
This episode is a study companion for CompTIA Security+ SY0-801 and is not produced by or endorsed by CompTIA.
Objective 1.1 asks you to explain security concepts and controls. Half of it is a vocabulary you will use for the rest of the exam: every control can be sorted two ways at once -- by the means that delivers it, and by what it does about an incident. Keeping those two sortings apart is most of the work of this lesson. The other half of 1.1 -- defence in depth, CIA, AAA, zero trust and least privilege -- is the next two lessons.
Why this matters
This is the first objective of the exam and the one most likely to be tested indirectly for the rest of it. A question in Domain 4 about a SIEM, or in Domain 5 about an audit finding, will often resolve to "which kind of control is this?" -- and if you cannot answer that quickly you lose time on questions that were not really about controls at all.
It is also the classic place to lose marks through overconfidence. Everyone knows what a firewall is. Far fewer people can say, under time pressure and without hedging, whether a firewall is preventive or detective, and whether it is technical or operational. Those are two separate questions with two separate answers, and the exam asks them separately.
SY0-801 also changed some labels. The categories now carry paired names, and the type once called "deterrent" now appears as deterring. The ideas are unchanged; the words in the answer options are not, so learn both forms.
The lesson
The four categories under both of the names V8 now gives them, and why the category is about WHO implements it
The four categories answer one question: by what means is this control carried out? In V8, three of them come with a second name, and you should treat each pair as one answer.
- Technical / logical controls are enforced by technology. A firewall rule, an access control list, disk encryption, a password length the directory refuses to go below. The machine does the enforcing. "Logical" is the older name and you will see it in access-control questions -- logical access is access to systems and data, as opposed to buildings.
- Managerial / administrative controls are set by management decision and documentation. A risk assessment, a security policy, a supplier vetting standard, a decision to accept a risk. They direct and oversee; they do not touch a packet.
- Operational controls are carried out by people doing things day to day. Awareness training, a guard checking badges, a change advisory board meeting, an incident response exercise, someone reviewing a log every morning.
- Physical / environmental controls act on the physical world. Fences, locks, lighting, cameras, access vestibules, badge readers -- and, on the environmental side, the things that protect equipment from conditions rather than from people: fire suppression, climate control, water and humidity sensors, conditioned power.
The useful test is the one in the heading: ask who or what actually carries this out. A written policy saying "all laptops must be encrypted" is managerial. The configuration that enforces it is technical. The reminder session that tells staff why is operational. The locked cabinet the spare laptops sit in is physical. One control objective, four categories, because four different mechanisms deliver it.
The pair that causes most hesitation is managerial against operational. A simple rule: managerial controls are decided, operational controls are done. The policy requiring quarterly access reviews is managerial; the team member performing this quarter's review is operational.
Six control types, from preventive and deterring through to directive, and the question each one answers
The six types answer a different question: what does this control do about an incident, and when does it act?
- Preventive -- stops it happening. A locked door, a firewall deny rule, multifactor authentication. Can this stop the attempt?
- Deterring -- discourages someone from trying. A warning sign, a visible camera, a login banner stating that use is monitored. It does nothing against someone who is not discouraged. Does this make the attempt less attractive?
- Detective -- notices that something happened, or is happening. Logs, an IDS, a reconciliation report, a camera whose footage someone actually reviews. Will we find out?
- Corrective -- puts things right afterwards and limits the damage. Restoring from backup, applying a patch, removing malware, rebuilding a host from a known good image. Can we recover?
- Compensating -- stands in when the control you should have cannot be used. It does not do the same job; it reduces the same risk another way. What do we do instead?
- Directive -- tells people what they are supposed to do. A policy, a procedure, an instruction on a door. Does everyone know what is expected?
A control is normally described by one category and one type, and the exam will hand you a scenario and ask for one or the other. Read which it wants before you answer.
A quick timing aid sorts most of them: deterring and preventive act before, detective acts during or after, corrective acts after. Directive and compensating do not fit the timeline neatly, which is exactly why they are the two people forget.
The same control landing in different boxes depending on how it is used
A camera is the standard example and it is worth being precise about, because the answer genuinely changes with the wording.
- A camera in plain sight, with a sign beside it, is deterring -- its purpose in that sentence is to make someone not try.
- A camera recording to storage that is reviewed after an incident is detective -- it tells you what happened.
- A camera feeding a monitor that a guard watches live is still detective; the guard who then intervenes is the preventive part.
By category, a camera is physical in all three readings. The category rarely moves; the type moves with the scenario. When a question describes what the control is for, it is asking about type.
A second example that trips people: a password policy. The document is managerial and directive. The directory setting that refuses short passwords is technical and preventive. Same intent, four different correct answers depending on which half the question describes.
A third: a backup. Taking it is a managerial decision put into practice by an operational or technical process, but its type is corrective, because its value appears only after something has gone wrong. If a question asks what kind of control lets you recover, the answer is corrective regardless of who runs the job.
Compensating controls, and the audit finding they are written to answer
A compensating control exists because something else could not be done. A legacy application needs an unsupported version of a library; it cannot be patched without breaking the business process that pays for it. The required control -- patch it -- is unavailable. So you compensate: put the server on an isolated segment, allow only two named source addresses to reach it, log every connection, and review that log weekly.
That is not as good as patching, and a compensating control never claims to be. What it claims is that the remaining risk has been brought down to something the organisation has agreed to accept, and that somebody with the authority to accept it has done so in writing. Auditors work with documented compensating controls; they do not accept undocumented ones.
This is why the heading talks about an audit finding. The usual sequence is: an assessment finds that a required control is missing; the organisation explains why it cannot be implemented as written; and the compensating control is the documented answer to that finding.
Two things make a compensating control real rather than an excuse: it addresses the same risk as the control it replaces, and it has an expiry -- a date by which the proper control will be in place or the decision is revisited. The risk register, covered in Domain 5, is where those decisions are recorded.
Reading an exam question that gives you a scenario and wants one word back
These questions have a shape. Learn it and they become fast.
- Decide whether it wants category or type. "Technical" and "preventive" are not competing answers to the same question, but they will appear side by side in the same option list. Words like implemented by, carried out by or what kind of control in relation to the mechanism point at category; words like purpose, stop, discourage, identify or restore point at type.
- Find the verb. "Which control would detect..." usually tells you the family of the answer. The question is not always trying to trick you.
- Ask when the control acts. Before, during, or after. That sorts preventive from detective from corrective in one step.
- Check for the two quiet ones. If the scenario is a document telling people what to do, directive is on the table. If it says the usual control "could not be applied", compensating almost certainly is the answer.
- Accept either half of a paired name. "Logical" for technical, "administrative" for managerial and "environmental" for physical are the same answers in V8's vocabulary.
What to take into the exam
- Category answers by what means -- technical/logical, managerial/ administrative, operational, physical/environmental. Type answers what it does about the incident -- preventive, deterring, detective, corrective, compensating, directive.
- Managerial controls are decided; operational controls are done.
- The same device changes type with the scenario and rarely changes category.
- A compensating control addresses the same risk by another route, is documented, has an expiry, and is accepted by someone who owns the risk.
- Deterring discourages an attempt; preventive stops one. A sign deters, a lock prevents.
- Directive is the one people forget. It instructs.
Practise what you just read
1. A camera is mounted in plain view at a loading bay beside a sign saying the area is recorded. Which control TYPE does that placement make it?
Select one
Show answer
A. Type answers what the control does about an incident. A visible camera with a sign is there to make someone decide not to try, which is deterring. The same camera recording footage that is reviewed after an incident would be detective; its category, physical, does not change in either reading.
2. A legacy application cannot be patched without breaking the process it supports, so its server is isolated and reachable from two addresses only. What is this?
Select one
Show answer
B. A compensating control stands in when the required control, here the patch, cannot be applied. It does not do the same job; it reduces the same risk by another route. To be real it must be documented, accepted by someone who owns the risk, and given a date for review.
3. Annual security awareness sessions, delivered by staff to other staff, fall into which control CATEGORY?
Select one
Show answer
C. Category answers by what means a control is carried out. Training is done by people, which makes it operational. The policy that requires the training is managerial, also called administrative, and the platform that delivers it is technical, so read which part the question actually describes.
Hands-on labs
Part of the free CompTIA Security+ SY0-801 course — 47 lessons and 78 hands-on labs.
This is an independent study companion for CompTIA Security+ SY0-801 and is not produced by or endorsed by CompTIA.