ExamOpsPractice free

CompTIA Security+ SY0-701 · Free study guide

Objective 1.1 — Classify safeguards by control category and purpose

Security controls are easiest to reason about on two independent axes. The category tells you how the safeguard is implemented or governed: technical, managerial, operational, or physical. The purpose tells you what it is meant to do: prevent, deter, detect, correct, compensate, or direct. A camera, for example, is a physical safeguard. Its visible placement may deter entry, while recorded footage supports detection and investigation. One device can therefore serve more than one purpose.

Categories describe where the control lives

Do not classify a control solely by what it protects. A policy about server access remains managerial even though servers are technical assets. A guard checking badges is an operational activity using a physical access system.

Purposes describe the intended effect

A preventive control tries to stop an event, while a deterrent makes the attempt less attractive. Detective controls reveal events; corrective controls restore a safe state. Directive controls tell people what must be done. A compensating control provides comparable risk reduction when the preferred control is not feasible.

Suppose a legacy laboratory instrument cannot run modern endpoint software. Network isolation, restrictive firewall rules, enhanced logging, and manual review may form a compensating package. Calling the package “compensating” does not make it temporary or weak. It must be documented, owned, tested, and matched to the original requirement.

Scenario method

When a question names a safeguard, ask:

  1. Who or what enforces it?
  2. What result is the organization trying to achieve?
  3. Is the stated purpose primary, or only a side effect?
  4. Does the safeguard replace a preferred control or add another layer?

The best design rarely depends on a single control. A restricted server room might use a policy, badge reader, access log, camera, and guard review. Those safeguards cross categories and purposes, reducing the chance that one failure defeats the whole protection strategy.

Decision rule: classify category and purpose separately, then choose the description supported by the scenario rather than assuming every technical product is preventive.

Practice and apply this objective

A free ExamOps account includes guided hands-on labs plus 10 practice questions per day shared across live tracks, with a written explanation on every question. No card required.

Start practicing free