CGRC · Question #21
Which of the following techniques are used after a security breach and are intended to limit the extent of any damage caused by the incident? Response:
The correct answer is D. Corrective controls. Corrective controls are security measures implemented after an incident has occurred to mitigate damage and restore systems to a secure state. They focus on minimizing the impact and recovering from a security breach.
Question
Which of the following techniques are used after a security breach and are intended to limit the extent of any damage caused by the incident? Response:
Options
- ASafeguards
- BPreventive controls
- CDetective controls
- DCorrective controls
How the community answered
(70 responses)- A1% (1)
- B4% (3)
- C1% (1)
- D93% (65)
Why each option
Corrective controls are security measures implemented after an incident has occurred to mitigate damage and restore systems to a secure state. They focus on minimizing the impact and recovering from a security breach.
Safeguards are general measures taken to protect assets, often encompassing all types of controls, not specifically post-breach actions.
Preventive controls aim to stop incidents from happening in the first place, acting before any breach occurs.
Detective controls are designed to identify and alert about ongoing or past incidents, but they do not actively limit damage or correct the situation.
Corrective controls are explicitly designed to be applied after a security incident or breach to limit damage and facilitate recovery. Examples include incident response procedures, disaster recovery plans, and system restoration processes which address issues post-event.
Concept tested: Types of security controls - Corrective
Source: https://csrc.nist.gov/glossary/term/corrective_controls
Topics
Community Discussion
No community discussion yet for this question.