CRISC - Risk Response and Reporting - Section 3.5

Classify control types and apply control standards and frameworks to the control environment.

Classify controls as preventive, detective, or corrective, and further by whether they are administrative, technical, or physical. Apply control frameworks to evaluate whether the control environment provides adequate coverage across each risk category.

Preventive controlsDetective controlsCorrective controlsControl frameworks

Practice question for this objective

Free sampleRisk Response and Reportingmedium

A risk practitioner reviews a firewall rule that drops inbound traffic on ports not used by a critical application before any packet reaches the host. By control type, how should this rule be classified?

  • ADetective, because the firewall rule actively inspects each packet and logs the traffic it observes
  • BCorrective, because the firewall rule restores the network to a safe state after an intrusion occurs
  • CCompensating, because the firewall rule substitutes for an absent control the design originally intended
  • DPreventive, because the firewall rule stops disallowed traffic from reaching the host before harm occurs Correct
Classify a control that blocks an event before it happens as a preventive control rather than detective, corrective, or compensating. Control type is decided by when and how a control acts relative to the event. A rule that denies disallowed traffic at the perimeter operates before any harm reaches the asset, which is the defining behaviour of a preventive control, so it is classified as preventive even though it also produces log entries.

Why A is wrong: Logging makes the rule look detective, but the rule blocks traffic before any harm reaches the host, so its primary purpose is prevention rather than after the fact discovery.

Why B is wrong: Corrective controls act after an incident to restore service, yet this rule stops the traffic up front, so nothing has gone wrong for it to correct.

Why C is wrong: A compensating control fills in for a missing primary control, but nothing here indicates a gap being covered, so this misreads a normal preventive measure.

Why D is correct: A preventive control acts before an event to stop it happening, and blocking disallowed packets at the perimeter denies the threat any chance to reach the asset.

See more CRISC practice questions, answers explained.

More in this domain

Back to all Risk Response and Reporting objectives, or the CRISC cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.