CompTIA Security+ SY0-701 · Free study guide
Objective 1.1 — Classify safeguards by control category and purpose
Security controls are easiest to reason about on two independent axes. The category tells you how the safeguard is implemented or governed: technical, managerial, operational, or physical. The purpose tells you what it is meant to do: prevent, deter, detect, correct, compensate, or direct. A camera, for example, is a physical safeguard. Its visible placement may deter entry, while recorded footage supports detection and investigation. One device can therefore serve more than one purpose.
Categories describe where the control lives
- Technical controls are enforced by technology: multifactor authentication, encryption, endpoint protection, firewall rules, and file-integrity monitoring.
- Managerial controls shape decisions and accountability: risk assessments, security plans, governance reviews, and approved policies.
- Operational controls are performed through people and recurring processes: visitor checks, change reviews, backup tests, incident exercises, and account recertification.
- Physical controls protect facilities and equipment: locks, fencing, bollards, lighting, guards, cameras, and access-control vestibules.
Do not classify a control solely by what it protects. A policy about server access remains managerial even though servers are technical assets. A guard checking badges is an operational activity using a physical access system.
Purposes describe the intended effect
A preventive control tries to stop an event, while a deterrent makes the attempt less attractive. Detective controls reveal events; corrective controls restore a safe state. Directive controls tell people what must be done. A compensating control provides comparable risk reduction when the preferred control is not feasible.
Suppose a legacy laboratory instrument cannot run modern endpoint software. Network isolation, restrictive firewall rules, enhanced logging, and manual review may form a compensating package. Calling the package “compensating” does not make it temporary or weak. It must be documented, owned, tested, and matched to the original requirement.
Scenario method
When a question names a safeguard, ask:
- Who or what enforces it?
- What result is the organization trying to achieve?
- Is the stated purpose primary, or only a side effect?
- Does the safeguard replace a preferred control or add another layer?
The best design rarely depends on a single control. A restricted server room might use a policy, badge reader, access log, camera, and guard review. Those safeguards cross categories and purposes, reducing the chance that one failure defeats the whole protection strategy.
Decision rule: classify category and purpose separately, then choose the description supported by the scenario rather than assuming every technical product is preventive.
Practice and apply this objective
A free ExamOps account includes guided hands-on labs plus 10 practice questions per day shared across live tracks, with a written explanation on every question. No card required.
Start practicing free