What Control Type Is Implemented by Security Baseline Policies?
An organization has implemented a policy to require minimum security control baselines when configuring servers or systems. What control type has been implemented?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests the distinction between directive controls (policies/guidelines) and preventive controls (technical safeguards), with the trap being confusion over the policy requirement versus the technical prevention it enables.
This CISA question tests the classification of security controls based on organizational policies. It establishes that mandating minimum security baselines through a formal policy constitutes a directive control.
Many candidates incorrectly select Preventive because baselines reduce risk, but they overlook that the implemented mechanism here is a mandatory policy, which defines it as directive.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Directive controls are designed to direct or guide individual behavior through formal policies, standards, and guidelines. By implementing a policy that requires minimum security control baselines, the organization is establishing mandatory expectations that dictate how servers must be configured. ISACA classifies any control primarily communicated through written mandates or procedural requirements as directive.Why the Other Options Are Wrong
Compensating controls act as alternative safeguards when primary controls are impractical or unavailable, which does not apply here. Corrective controls focus on restoring systems and data after a security incident occurs, rather than setting pre-implementation standards. Preventive controls utilize active technical mechanisms like firewalls or encryption to stop threats, whereas this scenario specifically highlights a policy mandate rather than a technical barrier.Community Comment Notes
One candidate argued that baselines proactively reduce vulnerabilities, but overlooked that the implemented artifact is a policy mandate rather than a technical barrier. Another noted that directives "establish expectations and requirements for security practices," which accurately matches the scenario. The majority correctly identified the control type by focusing on the word "policy" as the defining implementation method.Exam Strategy
When scanning CISA questions for control classifications, immediately flag keywords like "policy," "standard," "guideline," and "procedure." These terms consistently point to directive controls, regardless of whether the underlying measure eventually prevents or detects an incident.
Frequently Asked Questions
Why isn't a security baseline considered a preventive control?
Baselines are technical standards, but when implemented via a mandatory policy, the control type becomes directive. Preventive controls rely on active technical mechanisms like firewalls.
How does ISACA distinguish directive from compensating controls?
Directive controls set mandatory rules and baselines to guide behavior, while compensating controls substitute for missing primary controls. CISA focuses on policy mandates versus technical workarounds.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →