ISC2-CC - Security Principles (26% of the exam) - Section 1.3

Understand security controls and categorise them as technical, administrative, or physical safeguards.

Classify security controls into the three categories - technical (logical) controls such as firewalls and encryption, administrative (managerial) controls such as policies and training, and physical controls such as locks and guards. Recognise that defence in depth layers controls across all three categories so that no single failure exposes an asset.

Technical controlsAdministrative controlsPhysical controlsDefence in depth

Practice question for this objective

Free sampleSecurity Principleseasy

A study group debates why defence in depth places administrative, technical, and physical controls together in layers. Which statement best captures the rationale for combining the three categories?

  • ACombining categories lets an organisation discard the weakest layer once a stronger layer is proven effective.
  • BIf one control fails or is bypassed, controls from other categories can still detect, deter, or stop the threat. Correct
  • CUsing all three categories guarantees that no attacker can ever breach the protected environment.
  • DLayering the categories chiefly lowers cost by letting one physical control replace all technical controls.
Defence in depth layers administrative, technical, and physical controls so that the failure of one still leaves others protecting the asset. The strategy assumes controls will occasionally fail, so it stacks safeguards of different types; an attacker who defeats one layer still faces independent controls that can detect or block the attack.

Why A is wrong: This misreads the concept: defence in depth retains overlapping layers deliberately rather than removing any once another appears strong.

Why B is correct: Defence in depth assumes any single control may fail, so overlapping layers across categories provide redundancy that keeps protection intact when one layer is defeated.

Why C is wrong: This is tempting but overstated: layering reduces risk and buys time, yet it offers no absolute guarantee against every breach.

Why D is wrong: Cost may improve indirectly, but the categories address different weaknesses and cannot substitute for one another, so this misstates the purpose.

See more ISC2-CC practice questions, answers explained.

Exam traps in Security Principles

Answers that look right on this material and are not. Each one is a distractor from a different question in the ISC2-CC bank for this domain.

  • Least privilege, because each user receives only the minimum access needed for their role

    Why it is wrong: Tempting because access is being restricted, but least privilege concerns how much access each subject gets, not the stacking of independent safeguards.

  • Least privilege, granting each user only the access their job requires

    Why it is wrong: Least privilege is a sound principle, but it concerns limiting individual access rights rather than stacking varied control types against one threat.

  • It is a hardware or software mechanism, such as encryption or a firewall, that enforces protection automatically.

    Why it is wrong: This is tempting because such mechanisms are genuine controls, but automated hardware and software enforcement defines technical controls, not administrative ones.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.