EC-Council
312-50V9 · Question #47
312-50V9 Question #47: Real Exam Question with Answer & Explanation
The correct answer is B: Procedural. A prohibition on personal devices is a procedural control because it is enforced through policy and rules governing employee behavior, not through physical barriers or technology.
Question
The precaution of prohibiting employees from bringing personal computing devices into a facility is what type of security control?
Options
- APhysical
- BProcedural
- CTechnical
- DCompliance
Explanation
A prohibition on personal devices is a procedural control because it is enforced through policy and rules governing employee behavior, not through physical barriers or technology.
Common mistakes.
- A. Physical controls are tangible, hardware-based measures such as locks, mantraps, or security guards that physically prevent access - not rules about what employees may carry.
- C. Technical controls use technology to enforce security, such as network access control (NAC) systems that block unauthorized devices - not a verbal or written prohibition.
- D. Compliance is not a category of security control; it refers to adherence to laws, regulations, or standards rather than describing how a control is implemented.
Concept tested. Categorizing administrative vs physical vs technical security controls
Reference. https://csrc.nist.gov/glossary/term/administrative_control
Community Discussion
No community discussion yet for this question.