nerdexam
CompTIA

SY0-501 · Question #477

A new Chief Information Officer (CIO) has been reviewing the badging and decides to write a policy that all employees must have their badges rekeyed at least annually. Which of the following…

The correct answer is D. Administrative. The policy mandating annual badge rekeying is an administrative control, as it is a directive established by management to govern security procedures.

Submitted by lars.no· Mar 4, 2026Security program management and oversight

Question

A new Chief Information Officer (CIO) has been reviewing the badging and decides to write a policy that all employees must have their badges rekeyed at least annually. Which of the following controls BEST describes this policy?

Options

  • APhysical
  • BCorrective
  • CTechnical
  • DAdministrative

How the community answered

(40 responses)
  • A
    10% (4)
  • B
    3% (1)
  • C
    5% (2)
  • D
    83% (33)

Why each option

The policy mandating annual badge rekeying is an administrative control, as it is a directive established by management to govern security procedures.

APhysical

Physical controls are tangible security measures that protect physical assets, such as fences, locks, guards, or biometric scanners, not the policies governing their use.

BCorrective

Corrective controls are implemented after an incident to mitigate damage or restore systems, whereas this policy is a preventative measure designed to reduce the likelihood of an unauthorized access event.

CTechnical

Technical controls are hardware or software mechanisms that enforce security, like firewalls, encryption, or access control systems, not the written policies that define their configuration or usage.

DAdministrativeCorrect

Administrative controls are management-oriented and include policies, procedures, guidelines, and personnel security practices. A policy written by the CIO mandating annual badge rekeying is a directive establishing a security procedure, making it a prime example of an administrative control designed to manage risk through organizational rules and oversight.

Concept tested: Security control types (Administrative controls)

Source: https://learn.microsoft.com/en-us/training/modules/describe-security-operations-capabilities/2-describe-security-controls

Topics

#administrative controls#security policy#physical access management#control types

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice