DNS Logging Tool Control Type
A network administrator deployed a DNS logging tool that logs suspicious websites that are visited and then sends a daily report based on various weighted metrics. Which of the following best describes the type of control the administrator put in place?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The core concept tested is distinguishing between control types; the common trap is confusing Detective controls (logging/alerting) with Preventive (blocking) or Corrective (fixing) controls.
This question asks to identify the control type of a DNS logging tool that monitors and reports suspicious activity. The correct answer is Detective, as the tool observes and alerts rather than blocking or correcting.
Users often incorrectly select Preventive because they associate security tools with stopping threats, failing to recognize that logging alone does not block traffic.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The correct answer is D (Detective). A detective control is designed to identify and alert on security incidents after they have occurred or are in progress. By logging DNS queries and generating reports on suspicious websites, the administrator has implemented a mechanism to detect potential threats without actively stopping them.Why the Other Options Are Wrong
Option A (Preventive) is incorrect because preventive controls aim to stop an incident before it happens (e.g., firewalls, access controls); this tool only logs activity. Option B (Deterrent) is incorrect because deterrent controls discourage attackers through fear of consequences (e.g., warning banners), which this tool does not do. Option C (Corrective) is incorrect because corrective controls restore systems after an incident (e.g., backups, patching), whereas this tool only provides information.Community Comment Notes
Community consensus strongly supports option D. One user noted that the tool "identifies and notifies" risks, which aligns perfectly with detective functions. Another commenter emphasized that the daily report provides insights into malicious activities, helping in understanding incidents, a key aspect of detective controls.Exam Strategy
When identifying control types, look for keywords like 'log', 'monitor', 'audit', or 'report' to indicate Detective controls. If you see 'block', 'encrypt', or 'authenticate', think Preventive. If you see 'restore', 'backup', or 'patch', consider Corrective.
Frequently Asked Questions
Why isn't a DNS log considered a preventive control?
Preventive controls stop actions before they occur. Since DNS logging only records activity after it happens without blocking it, it cannot prevent the visit.
Does a daily report make this a corrective control?
No. Corrective controls fix damage or restore normal operations. A report merely informs administrators so they can decide on further actions, but the tool itself does not correct anything.