Which control is used to detect an attack while it is occurring and to notify proper personnel?

Study for the CompTIA SecurityX Test. Equip yourself with comprehensive flashcards and multiple choice questions that include hints and explanations. Gear up for your certification exam!

Multiple Choice

Which control is used to detect an attack while it is occurring and to notify proper personnel?

Detective controls identify and report security incidents as they happen. They monitor activity, look for signs of an attack, and alert the right people so response can begin immediately. In this scenario you want something that can detect an attack while it’s occurring and notify personnel, which is exactly what a detective control does. Examples include intrusion detection systems, security information and event management (SIEM) systems, log monitoring, and surveillance cameras. This differs from preventive controls, which focus on stopping incidents before they happen, and from compensating controls, which provide alternatives when primary controls can’t be used. Because the emphasis here is on real-time detection and notification, the best fit is a detective control.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy