nerdexam
(ISC)2

CSSLP · Question #395

Which type of controls is intended to limit the extent of any damage caused by an incident?

The correct answer is A. Corrective controls. The question asks about the type of security controls designed to limit damage after an incident. Corrective controls are specifically implemented to minimize the impact of an event and restore normal operations.

Secure Software Concepts

Question

Which type of controls is intended to limit the extent of any damage caused by an incident?

Options

  • ACorrective controls
  • BPreventive controls
  • CDetective controls
  • DLimitation controls

How the community answered

(35 responses)
  • A
    94% (33)
  • B
    3% (1)
  • C
    3% (1)

Why each option

The question asks about the type of security controls designed to limit damage after an incident. Corrective controls are specifically implemented to minimize the impact of an event and restore normal operations.

ACorrective controlsCorrect

Corrective controls are implemented after an incident has occurred to reduce the impact and restore systems to their normal state. Examples include incident response plans, disaster recovery plans, and data backups, all aimed at limiting damage and aiding recovery processes.

BPreventive controls

Preventive controls aim to stop an incident from happening in the first place, such as firewalls or access controls.

CDetective controls

Detective controls identify incidents as they occur or after they have occurred, like intrusion detection systems or security audits.

DLimitation controls

Limitation controls is not a standard, recognized category of security controls.

Concept tested: Types of security controls (corrective)

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf

Topics

#Security Controls#Corrective Controls#Incident Management#Damage Limitation

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice