Systems Security Certified Practitioner – SSCP – Question0177

Which type of control is concerned with avoiding occurrences of risks?

A.
Deterrent controls
B. Detective controls
C. Preventive controls
D. Compensating controls

Correct Answer: C

Explanation:

Preventive controls are concerned with avoiding occurrences of risks while deterrent controls are concerned with discouraging violations. Detecting controls identify occurrences and compensating controls are alternative controls, used to compensate weaknesses in other controls. Supervision is an example of compensating control. Source: TIPTON, Hal, (ISC)2, Introduction to the CISSP Exam presentation.