DNS Logging Tool Control Type

Answer Correct answer: D — The DNS logging tool acts as a detective control by monitoring and reporting suspicious website visits without preventing or correcting them.

A network administrator deployed a DNS logging tool that logs suspicious websites that are visited and then sends a daily report based on various weighted metrics. Which of the following best describes the type of control the administrator put in place?

  1. Preventive
  2. Deterrent
  3. Corrective
  4. Detective Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The core concept tested is distinguishing between control types; the common trap is confusing Detective controls (logging/alerting) with Preventive (blocking) or Corrective (fixing) controls.

This question asks to identify the control type of a DNS logging tool that monitors and reports suspicious activity. The correct answer is Detective, as the tool observes and alerts rather than blocking or correcting.

Users often incorrectly select Preventive because they associate security tools with stopping threats, failing to recognize that logging alone does not block traffic.

Community Discussion (4 comments)

johnabayot 👍 7 Selected: D
The DNS logging tool is a detective control because it monitors the website visited by the users and reports any suspicious ones based on certain criteria. It does not prevent, deter or correct the behaviour of the users, but rather identifies and notifies the administrator of any potential security risks.
1403ad2 👍 7 Selected: D
choose D 2024-20-2 On Test and passed with 802
shady23 👍 1 Selected: D
D. Detective
Hs1208 👍 1 Selected: D
D. Detective The daily report based on various weighted metrics provides insights into potentially malicious or unauthorized activities. Detective controls are valuable for identifying and responding to security incidents after they have occurred. They help in understanding the nature of incidents, gathering evidence, and taking appropriate corrective action

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The correct answer is D (Detective). A detective control is designed to identify and alert on security incidents after they have occurred or are in progress. By logging DNS queries and generating reports on suspicious websites, the administrator has implemented a mechanism to detect potential threats without actively stopping them.

Why the Other Options Are Wrong

Option A (Preventive) is incorrect because preventive controls aim to stop an incident before it happens (e.g., firewalls, access controls); this tool only logs activity. Option B (Deterrent) is incorrect because deterrent controls discourage attackers through fear of consequences (e.g., warning banners), which this tool does not do. Option C (Corrective) is incorrect because corrective controls restore systems after an incident (e.g., backups, patching), whereas this tool only provides information.

Community Comment Notes

Community consensus strongly supports option D. One user noted that the tool "identifies and notifies" risks, which aligns perfectly with detective functions. Another commenter emphasized that the daily report provides insights into malicious activities, helping in understanding incidents, a key aspect of detective controls.

Exam Strategy

When identifying control types, look for keywords like 'log', 'monitor', 'audit', or 'report' to indicate Detective controls. If you see 'block', 'encrypt', or 'authenticate', think Preventive. If you see 'restore', 'backup', or 'patch', consider Corrective.

Frequently Asked Questions

Why isn't a DNS log considered a preventive control?

Preventive controls stop actions before they occur. Since DNS logging only records activity after it happens without blocking it, it cannot prevent the visit.

Does a daily report make this a corrective control?

No. Corrective controls fix damage or restore normal operations. A report merely informs administrators so they can decide on further actions, but the tool itself does not correct anything.

Related Analysis

← Back to SY0-601 Study Guide