Identifying Detective Controls in Security Incident Response

Security Operations and Incident Response

After a recent ransomware attack on a company's system, an administrator reviewed the log files. Which of the following control types did the administrator use?

  1. Compensating
  2. Detective Source Reference Answer
  3. Preventive
  4. Corrective

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The core trap is confusing post-incident analysis with prevention; the key is recognizing that 'reviewing' and 'identifying' past events falls under detection, not prevention or correction.

This question tests the ability to classify security controls based on their timing relative to an incident. The community consensus confirms that reviewing logs after an attack is a classic example of a detective control.

Candidates often select Preventive (C) because they associate security controls with stopping attacks, failing to distinguish between controls that stop attacks before they happen versus those that identify them after.

Community Discussion (4 comments)

dbrowndiver 👍 5 Selected: B
Detective is the correct answer because reviewing log files after a ransomware attack is an example of a detective control. It is used to identify, analyze, and understand security incidents post-occurrence, providing valuable information for future prevention and response strategies.
opeyemi777 👍 1 Selected: B
Detective
Ina22 👍 1
Its B : Detective
Shaman73 👍 1
• B. Detective

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Detective controls are designed to identify and record unauthorized activities or security incidents as they occur or after they have taken place. By reviewing log files following a ransomware attack, the administrator is actively looking for evidence, indicators of compromise, and the scope of the breach, which aligns perfectly with the definition of detective controls.

Why the Other Options Are Wrong

Preventive controls (C) aim to stop an incident from occurring in the first place, such as firewalls or access controls. Corrective controls (D) are implemented to restore systems to normal operation after an incident, such as restoring from backups. Compensating controls (A) are alternative measures used when primary controls are ineffective, which does not describe the act of log review.

Community Comment Notes

The community unanimously agreed on option B. Comment [1] provides a strong explanation by highlighting that detective controls help analyze incidents post-occurrence to inform future strategies. Comments [2], [3], and [4] simply confirm the answer without additional detail, reinforcing the straightforward nature of this classification question.

Official Reference

Exam Strategy

When analyzing control types, focus on the action's timing: 'stopping' is preventive, 'finding' is detective, and 'fixing' is corrective. Always read the scenario carefully to see if the action happens before, during, or after the event.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide