Home > Blog > ISC2 Certified in Cybersecurity > Security Control Types for ISC2 CC: Comparison Guide

Security Control Types for ISC2 CC: Comparison Guide

Comparison Cert Sensei Team 2030-04-22 8 min read

Security control types are safeguards used to manage risk. They are categorized by function—preventive, detective, corrective, and deterrent—and by implementation—administrative, technical, and physical. Mastering these distinctions is critical for the ISC2 CC exam, as you must identify which control best mitigates a specific vulnerability in a given scenario.

#ISC2 CC #Security Controls #Cybersecurity Basics #Exam Prep

What are the primary categories of security controls?

Before we dive into the functions, you need to understand the three main implementation categories: Administrative, Technical, and Physical. Administrative controls are the 'paperwork' of security—think policies, procedures, and employee training. They set the rules of engagement for your organization. Technical controls (also called logical controls) use hardware and software to protect assets, such as firewalls, encryption, and Access Control Lists (ACLs).

Physical controls are the tangible barriers you can touch. This includes fences, locks, security guards, and biometric scanners at the door. In a real-world scenario, a secure data center doesn't rely on just one; it uses a blend. For example, a policy requiring background checks (Administrative) is paired with a badge reader (Physical) and an encrypted database (Technical). If you can't distinguish these on the exam, you'll struggle with the scenario-based questions.

How do Preventive and Detective controls differ?

This is where many students get tripped up. Preventive controls are proactive; their sole purpose is to stop a security incident from occurring in the first place. Think of a locked door or a firewall rule that blocks port 22. If the control works, the threat never enters the environment. You are essentially building a wall to keep the bad actors out.

Detective controls, on the other hand, are reactive. They don't stop the attack; they tell you that an attack is happening or has already happened. Examples include Intrusion Detection Systems (IDS), security camera footage, and system audit logs. A common exam trap is asking which control 'identifies' a breach—that's always a detective control. Remember: Preventive stops the fire; Detective smells the smoke.

When should you use Corrective versus Deterrent controls?

Once a detective control alerts you to a problem, you need a Corrective control to fix it. Corrective controls are designed to restore a system to its original state or mitigate the damage. The gold standard here is the data backup. If ransomware hits your servers, the backup is your corrective control. Patching a vulnerability after a breach is also a corrective action. You're essentially cleaning up the mess and ensuring it doesn't happen again.

Deterrent controls are psychological. They don't physically stop an attacker, nor do they fix a problem; they simply discourage someone from attempting an attack. A 'Warning: Trespassers will be prosecuted' sign or a visible security camera is a deterrent. While a determined hacker might ignore a sign, deterrents are highly effective at reducing the volume of opportunistic attacks. On the CC exam, look for keywords like 'discourage' or 'warn' to identify these.

How do you apply these controls to real-world security scenarios?

In the field, we use a strategy called 'Defense in Depth.' This means layering different control types so that if one fails, another catches the threat. Imagine a corporate office: the perimeter fence is a Physical/Deterrent control. The badge reader at the front door is a Physical/Preventive control. Once inside, the antivirus software on the workstations is a Technical/Preventive control. If a virus slips through, the system logs (Technical/Detective) alert the admin, who then restores the affected file from a backup (Technical/Corrective).

When you're analyzing a scenario for the ISC2 CC, ask yourself: 'Is this trying to stop the event, find the event, discourage the event, or fix the event?' Mapping the scenario to these four functions will lead you to the correct answer every time. Don't overthink it—stick to the definitions.

Why is understanding control types critical for the ISC2 CC exam?

The ISC2 CC exam doesn't just ask you to define these terms; it tests your ability to apply them. You'll likely encounter questions that describe a business problem and ask for the 'most effective' control. To answer these, you must understand the relationship between the risk and the control function. For instance, if the goal is to ensure accountability, a detective control like an audit log is the correct choice.

Because these nuances are so specific, generic studying isn't enough. We've built Cert Sensei to bridge this gap. We offer 1,000 expert-curated ISC2 Certified in Cybersecurity (CC) practice questions that mirror the actual exam's complexity. With detailed expert reasoning for every answer and domain-level analytics, you can pinpoint exactly where you're confusing 'preventive' with 'deterrent' and fix those gaps before test day.

Which common mistakes do students make when identifying controls?

The most frequent mistake is confusing Detective controls with Corrective controls. Students often think that because a log 'helps' fix a problem, it is corrective. It's not. The log only tells you what happened (Detective); the actual act of restoring the system is what's Corrective. Always separate the 'finding' from the 'fixing.'

Another common error is ignoring Administrative controls. Many candidates focus entirely on the 'cool' technical tools like firewalls and forget that a well-written Acceptable Use Policy (AUP) is a powerful administrative control. If a question mentions training, policies, or guidelines, your mind should immediately jump to Administrative. Read the prompt carefully—if the scenario mentions a human behavior change, it's likely an administrative or deterrent control.

❓ Frequently Asked Questions

Can a single security control fall into multiple categories?

Absolutely. For example, a security camera is a Physical control (you can touch it), a Detective control (it records the event), and a Deterrent control (its presence discourages criminals). On the exam, choose the answer that best fits the primary goal described in the scenario.


What is the difference between a technical and a logical control?

There is no difference. 'Technical control' and 'Logical control' are interchangeable terms used to describe security measures implemented through software or hardware, such as encryption, firewalls, and password requirements.


How do I distinguish between a deterrent and a preventive control on the exam?

Focus on the mechanism. A preventive control creates a hard barrier that physically or logically stops an action (e.g., a firewall rule). A deterrent control creates a psychological barrier that makes the attacker think twice (e.g., a warning sign).

More from ISC2 Certified in Cybersecurity

🧠

Test Your Knowledge

Ready to practice Certified in Cybersecurity? Put what you've learned to the test.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium
📖 Browse the Glossary

Join thousands of certification students

Sign Up Free