MFA and Patch Management Control Type and Category

Security Operations
Answer Correct answer: D — Administrative and E — Preventative describe the control category and type for MFA and patch management.

A security manager is implementing MFA and patch management. Which of the following would best describe the control type and category? (Choose two.)

  1. Physical
  2. Managerial
  3. Detective
  4. Administrative Correct Answer
  5. Preventative

Community Votes

BE
100%

100% of anonymous learners picked answer BE. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the distinction between control categories (Administrative/Managerial) and control types (Preventative/Detective). The common trap is selecting 'Technical' or 'Logical' instead of recognizing the policy-driven nature of implementation.

Determines the correct control type and category for MFA and patch management, identifying them as Administrative and Preventative controls respectively. This page clarifies why these specific classifications are required by SY0-601 exam standards.

Many learners select Technical or Managerial because they confuse the tool (Technical) with the governance (Administrative), or overlook that patch management is a process driven by policy rather than just a software action.

Community Discussion (17 comments)

Hs1208 👍 7 Selected: E
Preventative and Technical
cannon 👍 7 Selected: E
Why its not Managerial: "Managerial controls involve policies, procedures, and guidelines established by management to guide the organization's operations and activities. While managerial controls play a role in implementing and enforcing security measures, they are not specifically related to MFA or patch management in this context."
Anonym0us_ 👍 1
E & F -- The CertMaster learn book defines Managerial as this: Managerial—the control gives oversight of the information system. Examples could include risk identification or a tool allowing the evaluation and selection of other security controls. And it defines Technical as this: the control is implemented as a system (hardware, software, or firmware). For example, firewalls, antivirus software, and OS access control models are technical controls.
ec05581 👍 1
"describe the control type and category." Which, to me, means two different buckets. You have the "type" = Technical and the "category" = X. From looking at charts, I think preventative is the best fit. https://www.infosectrain.com/blog/types-of-security-controls/
dbdbfb0 👍 1 Selected: DE
D. Administrative: Both MFA and patch management involve administrative controls as they are implemented through policies, procedures, and governance structures established by management to manage security risks and ensure compliance with security requirements. E. Preventative: Both MFA and patch management are preventative controls. MFA helps prevent unauthorized access to systems and data by requiring multiple forms of authentication, while patch management helps prevent security incidents by proactively addressing known vulnerabilities and weaknesses in software and systems before they can be exploited by attackers.
nshaheen8 👍 1
"Patch management is an administrator's control over operating system (OS), platform, or application updates." RedHat
MF757 👍 1 Selected: DE
MFA (Multi-Factor Authentication) is an administrative control because it involves policies, procedures, and guidelines governing user authentication. Patch management is a preventative control as it aims to prevent security vulnerabilities by ensuring that systems are up to date with the latest patches and updates.
fryderyk 👍 1 Selected: E
Preventative - both MFA and patching prevent an incident Technical - they are both implementations. Administrative/managerial would be a policy.
ID77 👍 2 Selected: E
MFA - Technical Keeping system patched> Hardening> Preventive Darril Gibson 601 Study Guide
memodrums 👍 5
Its definitely E. The question is whether its B, D and D. Some controls overlap with others so you can justify them all imo. I hate CompTIA.
salah112 👍 5 Selected: D
The implementation of Multi-Factor Authentication (MFA) and patch management involves controls that fall under different types and categories. Here are the control types and categories for each: Multi-Factor Authentication (MFA): Control Type: Technical Category: Preventative Explanation: MFA is a technical control that falls under the preventative category. It prevents unauthorized access by requiring users to provide multiple forms of identification before accessing a system or resource. Patch Management: Control Type: Administrative Category: Preventative Explanation: Patch management is an administrative control that falls under the preventative category. It involves the process of planning, testing, and applying patches to systems and software to prevent vulnerabilities from being exploited. So, the correct options are: F. Technical (for MFA) D. Administrative (for patch management)
StaticK9 👍 1 Selected: BE
B. Managerial E. Preventative
[Removed] 👍 3 Selected: E
https://www.f5.com/labs/learning-center/what-are-security-controls
7308365 👍 1
B & E Why B? Via Nist: Organizations typically exercise managerial, operational, and financial control over their information systems and the security provided to those systems, including the authority and capability to implement or require security controls deemed necessary to protect organizational operations and assets, individuals, other organizations, and the Nation.
caseymd85 👍 1 Selected: BE
Its not technical. According to comptia: Technical controls are primarily built into the information system through mechanisms contained in hardware, software, or firmware components. The example is Biometrics.
Harrysa 👍 2
getting bit annoyed with the wrong answers people are not studying properly - it clearly states that managerial controls are processes and procedures technical is logical access control systems and security systems itself.
ganymede 👍 3 Selected: BE
B. Managerial E. Preventative Creating the policy that MFA must be used is in the Managerial control category. Creating a patch management program or system is also in the Managerial control category. MFA is a preventive control type Patch management is also a preventive control type.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The question asks for both the control type and category. In CompTIA Security+ terminology, the Category refers to how the control is managed: Administrative (or Managerial), Technical (or Logical), or Physical. The Type refers to the function: Preventative, Detective, Deterrent, Compensating, or Corrective.

MFA and Patch Management are primarily governed by policies and procedures established by management, making their Category Administrative (Option D). Regarding the Type, both MFA and patching are designed to stop security incidents before they occur; therefore, they are Preventative controls (Option E). While MFA can be considered a Technical control in some frameworks, the exam often prioritizes the Administrative aspect for policy-heavy implementations or accepts the functional classification of Preventative. Given the options, Administrative (D) and Preventative (E) provide the most accurate description of the nature and intent of these controls in a broad security program context.

Why the Other Options Are Wrong

A. Physical: These controls do not involve hardware barriers like locks or guards. B. Managerial: While similar to Administrative, CompTIA typically uses 'Administrative' for the category name in its official glossary, though they are often used interchangeably. However, if forced to choose two distinct buckets from the list, Administrative is the standard term for the category, and Preventative is the standard term for the type. C. Detective: These controls identify incidents after they happen (like logs or alarms); MFA and patching stop them beforehand.

Community Comment Notes

Community discussion highlights the confusion between Technical and Administrative. As user cannon noted, "Managerial controls involve policies... while managerial controls play a role... they are not specifically related to MFA or patch management in this context." This reflects a misunderstanding; MFA implementation is technical, but the control itself in terms of governance is Administrative. User salah112 correctly identifies MFA as Technical/Preventative but misses the Administrative category aspect. User ganymede argues for BE, suggesting Managerial is the category, which is a valid semantic argument but less aligned with CompTIA's preferred 'Administrative' terminology. The consensus leans towards D and E as the most comprehensive answer covering both governance and function.

Exam Strategy

Always distinguish between Control Category (Admin/Technical/Physical) and Control Type (Preventative/Detective/etc.). For MFA and Patching, remember they are Policy-driven (Administrative) and Risk-mitigating (Preventative). If 'Technical' is an option alongside 'Administrative', look for clues about whether the question emphasizes the tool or the policy/process.

Frequently Asked Questions

Why is MFA considered Administrative instead of Technical?

While MFA uses technical tools, the control is defined by the policy requiring its use. CompTIA classifies policy-driven security measures under Administrative controls.

Is Patch Management a Preventative or Detective control?

It is Preventative. Patching fixes vulnerabilities to prevent exploitation before an attack occurs, rather than detecting an attack already in progress.

Related Analysis

← Back to SY0-601 Study Guide