SY0-701 - General Security Concepts (12% of the exam) - Section 1.1

Compare and contrast various types of security controls.

Distinguish technical, managerial, operational, and physical controls, and explain how each category addresses a different layer of security. Recognise when a control is preventive, detective, corrective, deterrent, compensating, or directive, and select the appropriate type for a given scenario.

technical controlmanagerial controloperational controlphysical controlpreventive vs detective

Practice question for this objective

Free sampleGeneral Security Conceptseasy

A security team is categorising the controls used to protect a corporate office. Which example is best classified as a physical security control rather than a technical, managerial, or operational one?

  • AA host-based firewall on every laptop that filters inbound and outbound network traffic.
  • BA mantrap at the data centre entrance that prevents tailgating into the server hall. Correct
  • CAn acceptable use policy that staff must read and sign before being issued an account.
  • DA nightly user access review performed by team leads to remove unneeded permissions.
Recognise that physical controls are tangible mechanisms guarding facilities and assets, distinct from technical, managerial, or operational controls. Security controls are grouped by how they enforce protection. Physical controls are tangible items in the environment, such as locks, fences, guards, bollards, and mantraps, that constrain or monitor access to a location. A mantrap is a small interlocked vestibule that allows only one authorised person through at a time, defeating tailgating into a server hall, which makes it a clear physical control.

Why A is wrong: A host-based firewall is software enforcing rules on a computer, which makes it a technical control rather than a physical one, even though it protects the device.

Why B is correct: A mantrap is a tangible barrier in the environment that physically restricts who can enter a sensitive area, which is the defining trait of a physical control.

Why C is wrong: Signed policies guide behaviour and risk decisions, so they are managerial controls; they are tempting because they protect the office but they are not physical objects.

Why D is wrong: Recurring access reviews are an operational control performed by people as part of a process, not a physical barrier or device guarding a location.

See more SY0-701 practice questions, answers explained.

Exam traps in General Security Concepts

Answers that look right on this material and are not. Each one is a distractor from a different question in the SY0-701 bank for this domain.

  • A documented acceptable use policy that staff must sign before they are issued a laptop and network account.

    Why it is wrong: A signed policy looks like a real safeguard, but a written rule that governs behaviour is a managerial control, not a physical one, because it imposes no tangible barrier.

  • A motion-activated alarm that sounds and logs an alert when someone enters the room after hours.

    Why it is wrong: An alarm that fires on entry is tempting because it reacts to intruders, but it identifies activity after it begins rather than stopping it, making it detective.

  • A preventive control that blocks suspicious messages at the secure email gateway before delivery

    Why it is wrong: Gateway blocking is a classic preventive control, but the requirement explicitly states the analyst wants to react after delivery rather than block, so a preventive function is the wrong fit.

Examworthy is not affiliated with or endorsed by CompTIA. Original, blueprint-aligned practice material only.