CSSLP · Question #395
Which type of controls is intended to limit the extent of any damage caused by an incident?
The correct answer is A. Corrective controls. The question asks about the type of security controls designed to limit damage after an incident. Corrective controls are specifically implemented to minimize the impact of an event and restore normal operations.
Question
Which type of controls is intended to limit the extent of any damage caused by an incident?
Options
- ACorrective controls
- BPreventive controls
- CDetective controls
- DLimitation controls
How the community answered
(35 responses)- A94% (33)
- B3% (1)
- C3% (1)
Why each option
The question asks about the type of security controls designed to limit damage after an incident. Corrective controls are specifically implemented to minimize the impact of an event and restore normal operations.
Corrective controls are implemented after an incident has occurred to reduce the impact and restore systems to their normal state. Examples include incident response plans, disaster recovery plans, and data backups, all aimed at limiting damage and aiding recovery processes.
Preventive controls aim to stop an incident from happening in the first place, such as firewalls or access controls.
Detective controls identify incidents as they occur or after they have occurred, like intrusion detection systems or security audits.
Limitation controls is not a standard, recognized category of security controls.
Concept tested: Types of security controls (corrective)
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf
Topics
Community Discussion
No community discussion yet for this question.