Identifying Operational Controls in Code Deployment
A company has implemented a policy that requires two people to agree in order to push any changes from the test codebase repository into production. Which of the following best describes this control type?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam often confuses 'technical' safeguards with 'operational' policies; this scenario describes a procedural policy (dual approval) which is inherently operational, not technical.
This question tests the ability to classify security controls based on implementation method. The requirement for two people to agree on changes is an operational control because it relies on human procedure rather than technology.
Candidates frequently select 'Technical' because code repositories are software tools, failing to recognize that the specific control mechanism (human agreement/policy) defines the control type.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
A dual-approval process requiring two individuals to agree is a classic example of an operational control. Operational controls are those that depend on people and their execution of procedures, policies, and rules. Since the control mechanism here is the human decision-making process enforced by policy, it falls squarely under the operational category.Why the Other Options Are Wrong
Detective controls identify incidents after they occur, whereas this is a preventative step. Technical controls involve hardware or software mechanisms (like encryption or firewalls); while a repository is technical, the control described is the policy of human consent. Physical controls relate to tangible barriers like locks or guards, which are irrelevant to software deployment processes.Community Comment Notes
Community consensus strongly supports D, with users noting that operational controls depend on persons for implementation. One commenter highlighted that operational controls govern day-to-day activities, distinguishing them from purely technical or physical safeguards.Exam Strategy
When analyzing control types, focus on the primary enforcement mechanism. If the control relies on a person following a rule or procedure, it is operational. If it relies on a device or software function, it is technical. If it detects an event, it is detective.
Frequently Asked Questions
Why isn't this a technical control since it involves a repository?
While the repository is a technical tool, the control itself is the policy requiring human agreement. Technical controls enforce security via software/hardware, not manual policy.
What distinguishes operational from administrative controls?
Administrative controls are high-level policies and guidelines. Operational controls are the specific daily procedures and practices implemented to execute those policies.