Used in place of a primary access control measure in order to mitigate a given risk.

Study for the CompTIA SecurityX Test. Equip yourself with comprehensive flashcards and multiple choice questions that include hints and explanations. Gear up for your certification exam!

Multiple Choice

Used in place of a primary access control measure in order to mitigate a given risk.

Explanation:
A compensating control is a security measure used in place of a primary access control when the original control cannot be implemented or would not be feasible, with the goal of achieving equivalent risk reduction. In practice, if you can’t deploy a desired primary control (such as a certain form of strong authentication) for a system, you implement an alternative set of controls that together provide similar protection. For example, you might add enhanced monitoring, stricter access review processes, or additional compensating procedures to compensate for not having the primary control in place. The established term for this concept is compensating control; one option here appears to be a misspelled form of that term.

A compensating control is a security measure used in place of a primary access control when the original control cannot be implemented or would not be feasible, with the goal of achieving equivalent risk reduction. In practice, if you can’t deploy a desired primary control (such as a certain form of strong authentication) for a system, you implement an alternative set of controls that together provide similar protection. For example, you might add enhanced monitoring, stricter access review processes, or additional compensating procedures to compensate for not having the primary control in place. The established term for this concept is compensating control; one option here appears to be a misspelled form of that term.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy