What Type of Security Control Is an Acceptable Use Policy?

Which of the following security control types does an acceptable use policy best represent?

  1. Detective
  2. Compensating
  3. Corrective
  4. Preventive Source Reference Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests your ability to map administrative governance documents to control categories, with the common trap being the assumption that only technical mechanisms can qualify as preventive.

An acceptable use policy (AUP) is classified as a preventive security control because it establishes behavioral guidelines to deter unauthorized actions before incidents occur. The overwhelming community consensus confirms this classification, emphasizing that administrative policies function as proactive deterrents rather than reactive or monitoring tools.

Candidates frequently select Detective or Compensating controls, mistakenly believing that a written policy cannot actively prevent attacks or that it merely tracks activity after the fact. Others confuse AUPs with Directive controls, though Directive is simply an alternative term for preventive administrative policies in certain study materials.

Community Discussion (12 comments)

TheMichael 👍 13 Selected: D
D. Preventive AUP is pretty obviously trying to prevent things from happening. It's not A. Detective because it doesn't detect anything. It's a policy. It's not B. Compensating because it isn't making up for any other policy included in the question. It's not C. Corrective because it doesn't correct anything on it's own, it's simply a policy that is to be followed. So it could only be D. Preventive, as it prevents people from doing things that might compromise the network.
noragami 👍 8 Selected: D
An acceptable use policy best represents: D. Preventive An acceptable use policy is designed to prevent security incidents by defining the acceptable and unacceptable behaviors and actions for users within an organization. By setting clear guidelines and expectations, it aims to prevent misuse and ensure that users adhere to security protocols, thereby reducing the risk of security breaches.
braveheart22 👍 1 Selected: D
An Acceptable Use Policy sets guidelines and rules for how users should behave when using an organization's network, devices, and other resources. It is preventive in nature because it aims to prevent improper behavior and reduce the likelihood of security incidents before they occur by clearly defining acceptable and unacceptable actions. Preventive controls aim to deter security violations or unwanted behaviors from happening in the first place. AUPs prevent misuse of resources by setting clear boundaries on what is and isn’t allowed, such as restrictions on accessing certain websites or using unauthorized software.
Examplary 👍 2
I find myself wondering if the actual exam uses "Directive" as A instead of Detective. Jason Dion's course actually used AUP as it's example of a Directive Control: Directive Controls - Often rooted in policy or documentation and set the standards for behavior within an org. Ex. Acceptable Use Policies (AUPs). Guides the entire process.
dbrowndiver 👍 1 Selected: D
An acceptable use policy serves as a preventive measure by clearly outlining what constitutes acceptable and unacceptable behavior. This deters employees from engaging in activities that could lead to security breaches or misuse of resources. Education: By educating users about proper usage and potential consequences of violations, the policy reduces the likelihood of accidental or intentional security incidents. Legal and Compliance: AUPs also help establish a legal framework for acceptable use, which can prevent legal liabilities and ensure compliance with regulatory requirements. Why it is is the best choice: The primary goal of an AUP is to prevent misuse of IT resources by setting clear expectations and guidelines. By defining what is acceptable, the policy acts as a preventive control, helping to mitigate risks before they materialize.
PAWarriors 👍 1 Selected: D
Acceptable Use Policy (AUP) is a preventive security control type. AUP is a document that outlines the do's and don'ts for users when interacting with an organization's IT systems and resources and defines appropriate and prohibited use of IT systems/resources as a preventive security control.
dbrowndiver 👍 1 Selected: D
By restricting access to the administrator console to just the IT manager and the help desk lead, the IT manager is implementing least privilege. This ensures that only those who need elevated access for their roles can use administrative functions, reducing the risk of unauthorized changes or misuse.
ebomuchekingsley 👍 3
Policies are usually a type of preventive admin control.
elbarozz 👍 3 Selected: D
its clearly D
Gadoof 👍 3 Selected: B
It's impossible for a policy to be a detective, corrective, or preventative control as a policy CANNOT stop/prevent, or detect any attack in any way. It has to be B
MAKOhunter33333333 👍 4 Selected: D
AUP = lets user know what is acceptable and allowed to prevent them from performing certain activity
rjbb 👍 2 Selected: D
preventive - an acceptable use policy enforces rules to users to use company resources. example - company A states that in order to access files in the company server you must connect to your company VPN when working from home. This prevents you from connecting from an insecure network.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Security Control Taxonomy

Security controls are organized by their operational timing and purpose. Preventive controls aim to stop incidents before they occur, detective controls identify ongoing or past events, corrective controls restore systems after an incident, and compensating controls provide alternative safeguards when primary measures are unfeasible.

Why Preventive is Correct

An Acceptable Use Policy (AUP) is a foundational administrative control designed to shape user behavior through clear expectations and consequences. As highlighted by community experts, an AUP deters misuse by educating personnel on proper resource utilization and outlining disciplinary actions for violations. In certification frameworks, any policy, procedure, or training initiative intended to reduce risk proactively is categorized as preventive, regardless of whether it relies on technology. [Comment #1] emphasizes that an AUP is inherently preventive because it sets rules to stop incidents before they happen, rather than detecting or correcting them afterward.

Analyzing the Distractors

  • Detective: Focuses on identification and alerting (e.g., SIEM, audit logs). An AUP does not monitor traffic or generate notifications.
  • Corrective: Implemented post-incident to remediate damage (e.g., backups, patch deployment). An AUP plays no role in system restoration.
  • Compensating: Serves as a fallback when standard controls fail or cannot be deployed. An AUP is a primary governance requirement, not a workaround.
Note: Some training providers label AUPs as 'Directive' controls. This is functionally identical to preventive administrative controls in the context of SY0-701.

Official Reference

Exam Strategy

When classifying controls, determine the timing and intent of the measure: does it stop an event beforehand, catch it during/afterward, fix the aftermath, or replace a missing safeguard? For administrative artifacts like policies, SOPs, and training programs, default to preventive unless the scenario explicitly describes monitoring, logging, or recovery workflows.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide