Systems Security Certified Practitioner – SSCP – Question0229

Sensitivity labels are an example of what application control type?

A.
Preventive security controls
B. Detective security controls
C. Compensating administrative controls
D. Preventive accuracy controls

Correct Answer: A

Explanation:

Sensitivity labels are a preventive security application controls, such as are firewalls, reference monitors, traffic padding, encryption, data classification, one-time passwords, contingency planning, separation of development, application and test environments.
The incorrect answers are:
Detective security controls -Intrusion detection systems (IDS), monitoring activities, and audit trails.
Compensating administrative controls -There no such application control.
Preventive accuracy controls -data checks, forms, custom screens, validity checks, contingency planning, and backups.
Sources: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, John Wiley & Sons, 2001, Chapter 7: Applications and Systems Development (page 264). KRUTZ, Ronald & VINES, Russel, The CISSP Prep Guide: Gold Edition, Wiley Publishing Inc., 2003, Chapter 7: Application Controls, Figure 7.1 (page 360).