MFA and Patch Management Control Type and Category
A security manager is implementing MFA and patch management. Which of the following would best describe the control type and category? (Choose two.)
Community Votes
100% of anonymous learners picked answer BE. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests the distinction between control categories (Administrative/Managerial) and control types (Preventative/Detective). The common trap is selecting 'Technical' or 'Logical' instead of recognizing the policy-driven nature of implementation.
Determines the correct control type and category for MFA and patch management, identifying them as Administrative and Preventative controls respectively. This page clarifies why these specific classifications are required by SY0-601 exam standards.
Many learners select Technical or Managerial because they confuse the tool (Technical) with the governance (Administrative), or overlook that patch management is a process driven by policy rather than just a software action.
Community Discussion (17 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The question asks for both the control type and category. In CompTIA Security+ terminology, the Category refers to how the control is managed: Administrative (or Managerial), Technical (or Logical), or Physical. The Type refers to the function: Preventative, Detective, Deterrent, Compensating, or Corrective.MFA and Patch Management are primarily governed by policies and procedures established by management, making their Category Administrative (Option D). Regarding the Type, both MFA and patching are designed to stop security incidents before they occur; therefore, they are Preventative controls (Option E). While MFA can be considered a Technical control in some frameworks, the exam often prioritizes the Administrative aspect for policy-heavy implementations or accepts the functional classification of Preventative. Given the options, Administrative (D) and Preventative (E) provide the most accurate description of the nature and intent of these controls in a broad security program context.
Why the Other Options Are Wrong
A. Physical: These controls do not involve hardware barriers like locks or guards. B. Managerial: While similar to Administrative, CompTIA typically uses 'Administrative' for the category name in its official glossary, though they are often used interchangeably. However, if forced to choose two distinct buckets from the list, Administrative is the standard term for the category, and Preventative is the standard term for the type. C. Detective: These controls identify incidents after they happen (like logs or alarms); MFA and patching stop them beforehand.Community Comment Notes
Community discussion highlights the confusion between Technical and Administrative. As user cannon noted, "Managerial controls involve policies... while managerial controls play a role... they are not specifically related to MFA or patch management in this context." This reflects a misunderstanding; MFA implementation is technical, but the control itself in terms of governance is Administrative. User salah112 correctly identifies MFA as Technical/Preventative but misses the Administrative category aspect. User ganymede argues for BE, suggesting Managerial is the category, which is a valid semantic argument but less aligned with CompTIA's preferred 'Administrative' terminology. The consensus leans towards D and E as the most comprehensive answer covering both governance and function.Exam Strategy
Always distinguish between Control Category (Admin/Technical/Physical) and Control Type (Preventative/Detective/etc.). For MFA and Patching, remember they are Policy-driven (Administrative) and Risk-mitigating (Preventative). If 'Technical' is an option alongside 'Administrative', look for clues about whether the question emphasizes the tool or the policy/process.
Frequently Asked Questions
Why is MFA considered Administrative instead of Technical?
While MFA uses technical tools, the control is defined by the policy requiring its use. CompTIA classifies policy-driven security measures under Administrative controls.
Is Patch Management a Preventative or Detective control?
It is Preventative. Patching fixes vulnerabilities to prevent exploitation before an attack occurs, rather than detecting an attack already in progress.