What Type of Security Control Is an Acceptable Use Policy?
Which of the following security control types does an acceptable use policy best represent?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests your ability to map administrative governance documents to control categories, with the common trap being the assumption that only technical mechanisms can qualify as preventive.
An acceptable use policy (AUP) is classified as a preventive security control because it establishes behavioral guidelines to deter unauthorized actions before incidents occur. The overwhelming community consensus confirms this classification, emphasizing that administrative policies function as proactive deterrents rather than reactive or monitoring tools.
Candidates frequently select Detective or Compensating controls, mistakenly believing that a written policy cannot actively prevent attacks or that it merely tracks activity after the fact. Others confuse AUPs with Directive controls, though Directive is simply an alternative term for preventive administrative policies in certain study materials.
Community Discussion (12 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Security Control Taxonomy
Security controls are organized by their operational timing and purpose. Preventive controls aim to stop incidents before they occur, detective controls identify ongoing or past events, corrective controls restore systems after an incident, and compensating controls provide alternative safeguards when primary measures are unfeasible.Why Preventive is Correct
An Acceptable Use Policy (AUP) is a foundational administrative control designed to shape user behavior through clear expectations and consequences. As highlighted by community experts, an AUP deters misuse by educating personnel on proper resource utilization and outlining disciplinary actions for violations. In certification frameworks, any policy, procedure, or training initiative intended to reduce risk proactively is categorized as preventive, regardless of whether it relies on technology. [Comment #1] emphasizes that an AUP is inherently preventive because it sets rules to stop incidents before they happen, rather than detecting or correcting them afterward.Analyzing the Distractors
- Detective: Focuses on identification and alerting (e.g., SIEM, audit logs). An AUP does not monitor traffic or generate notifications.
- Corrective: Implemented post-incident to remediate damage (e.g., backups, patch deployment). An AUP plays no role in system restoration.
- Compensating: Serves as a fallback when standard controls fail or cannot be deployed. An AUP is a primary governance requirement, not a workaround.
Official Reference
- https://csrc.nist.gov/pubs/sp/800-53/r5/final
- https://www.iso.org/standard/27001.html
- CompTIA Security+ SY0-701 Exam Objectives v4.0 (Domain 1.0: General Security Principles)
Exam Strategy
When classifying controls, determine the timing and intent of the measure: does it stop an event beforehand, catch it during/afterward, fix the aftermath, or replace a missing safeguard? For administrative artifacts like policies, SOPs, and training programs, default to preventive unless the scenario explicitly describes monitoring, logging, or recovery workflows.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →