nerdexam
(ISC)2

CISSP-ISSAP · Question #102

An access control secures the confidentiality, integrity, and availability of the information and data of an organization. In which of the following categories can you deploy the access control?…

The correct answer is A. Detective access control B. Corrective access control D. Preventive access control. Access controls are classified by function (how they act) and by type (how they're implemented). Detective (A), Corrective (B), and Preventive (D) are all functional deployment categories - they describe what a control does: Preventive controls stop incidents before they occur…

Identity and Access Management (IAM) Architecture

Question

An access control secures the confidentiality, integrity, and availability of the information and data of an organization. In which of the following categories can you deploy the access control? Each correct answer represents a part of the solution. Choose all that apply.

Options

  • ADetective access control
  • BCorrective access control
  • CAdministrative access control
  • DPreventive access control

How the community answered

(31 responses)
  • A
    81% (25)
  • C
    19% (6)

Explanation

Access controls are classified by function (how they act) and by type (how they're implemented). Detective (A), Corrective (B), and Preventive (D) are all functional deployment categories - they describe what a control does: Preventive controls stop incidents before they occur, Detective controls identify incidents in progress or after the fact, and Corrective controls restore systems or remediate damage after an incident. Together, these three represent the core functional lifecycle of deploying access controls to protect CIA.

Why C (Administrative) is wrong: Administrative is a type of access control (alongside Technical/Logical and Physical), describing how a control is implemented (e.g., policies, procedures, training) - not a deployment category in the functional sense. The question asks about deployment categories, so Administrative doesn't fit this dimension.

Memory tip: Think of the functional categories as a timeline - Prevent → Detect → Correct (PDC). Administrative is how you build those controls (via policies), not where you deploy them in that lifecycle.

Topics

#Detective Access Control#Preventive Access Control#Corrective Access Control#CIA Implementation

Community Discussion

No community discussion yet for this question.

Full CISSP-ISSAP Practice