What type of control is a SIEM system with weekly log reviews?
A company is planning to set up a SIEM system and assign an analyst to review the logs on a weekly basis. Which of the following types of controls is the company setting up?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests your ability to classify security controls by their function; the common trap is confusing detective controls (which find incidents) with preventive controls (which stop them).
A SIEM system with regular log reviews is classified as a detective control because it identifies and alerts on security incidents after they occur. The CompTIA SY0-701 community overwhelmingly agrees that monitoring and logging fall under detective controls.
Many candidates incorrectly choose 'Preventive' because a SIEM can trigger automated responses, but the scenario only describes log collection and manual weekly review, which detects rather than prevents incidents.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
A SIEM (Security Information and Event Management) system aggregates and analyzes log data to identify suspicious activity after it has occurred. Assigning an analyst to review logs weekly is a monitoring activity designed to discover incidents, which is the textbook definition of a detective control. Detective controls do not stop attacks; they reveal them so that corrective or preventive actions can follow.Why the Other Options Are Wrong
Corrective controls restore systems after an incident (e.g., backups, patching), which is not what the scenario describes. Preventive controls block attacks before they happen (e.g., firewalls, encryption), and the scenario mentions no blocking mechanism. Deterrent controls discourage attackers through visible warnings (e.g., security signs, policies), which is unrelated to internal log monitoring.Community Comment Notes
Community comments unanimously support answer C, with top-voted explanations emphasizing that SIEM log review is a classic detective control. Commenters note that the key distinction is that the system identifies incidents rather than preventing them, reinforcing the exam's focus on control classification by function.Official Reference
Exam Strategy
When classifying security controls, focus on what the control actively does: if it monitors, logs, or alerts after an event, it is detective. Eliminate preventive options unless the control explicitly blocks or stops an action before it occurs.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →