What type of control is a SIEM system with weekly log reviews?

A company is planning to set up a SIEM system and assign an analyst to review the logs on a weekly basis. Which of the following types of controls is the company setting up?

  1. Corrective
  2. Preventive
  3. Detective Source Reference Answer
  4. Deterrent

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests your ability to classify security controls by their function; the common trap is confusing detective controls (which find incidents) with preventive controls (which stop them).

A SIEM system with regular log reviews is classified as a detective control because it identifies and alerts on security incidents after they occur. The CompTIA SY0-701 community overwhelmingly agrees that monitoring and logging fall under detective controls.

Many candidates incorrectly choose 'Preventive' because a SIEM can trigger automated responses, but the scenario only describes log collection and manual weekly review, which detects rather than prevents incidents.

Community Discussion (3 comments)

Etc_Shadow28000 👍 11 Selected: C
C. Detective By setting up a Security Information and Event Management (SIEM) system and assigning an analyst to review the logs on a weekly basis, the company is implementing a detective control. Detective controls are designed to identify and alert on potential security incidents, allowing the organization to take appropriate action after an event has occurred. Therefore, the correct answer is: C. Detective
dbrowndiver 👍 4 Selected: C
A Security Information and Event Management (SIEM) system is primarily used to detect security incidents by collecting and analyzing logs from various sources.The setup of a SIEM system and regular log reviews is focused on identifying incidents, making it a classic example of a detective control, which is intended to uncover issues rather than prevent them.
Hayder81 👍 4
C. Detective

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A SIEM (Security Information and Event Management) system aggregates and analyzes log data to identify suspicious activity after it has occurred. Assigning an analyst to review logs weekly is a monitoring activity designed to discover incidents, which is the textbook definition of a detective control. Detective controls do not stop attacks; they reveal them so that corrective or preventive actions can follow.

Why the Other Options Are Wrong

Corrective controls restore systems after an incident (e.g., backups, patching), which is not what the scenario describes. Preventive controls block attacks before they happen (e.g., firewalls, encryption), and the scenario mentions no blocking mechanism. Deterrent controls discourage attackers through visible warnings (e.g., security signs, policies), which is unrelated to internal log monitoring.

Community Comment Notes

Community comments unanimously support answer C, with top-voted explanations emphasizing that SIEM log review is a classic detective control. Commenters note that the key distinction is that the system identifies incidents rather than preventing them, reinforcing the exam's focus on control classification by function.

Official Reference

Exam Strategy

When classifying security controls, focus on what the control actively does: if it monitors, logs, or alerts after an event, it is detective. Eliminate preventive options unless the control explicitly blocks or stops an action before it occurs.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide