CompTIA Security+ (SY0-701)

Lesson 1.4: Security Control Functional Types

Learning Objectives

By the end of this digital training module, you will be able to:

Introduction

In cybersecurity, knowing *who* enforces a control is only half the battle. To build resilient networks, we must categorize controls based on **their job during a security incident**.

These roles are classified into six **Functional Types**. Organizing controls by function allows systems engineers to structure multiple defense boundaries, ensuring that if a threat breaches our prevention barrier, detection and corrective triggers are already waiting.

Defense in Depth The architectural practice of nesting multiple layers of different functional safeguards to protect assets.
Functional Type Classification of a security control based on *when* and *how* it acts during an adverse event threat cycle.

The Six Functional Types

Hover, click, or tap each card below to flip it and explore its operational objective, core focus, and real-world implementations.

Preventive

Proactive Defense

Designed to actively block, deter, or stop a security incident before it can materialize or damage systems.

Examples:

Firewall Rules, Mantraps, Biometric Locks, System Hardening

Detective

Incident Visibility

Designed to identify, trace, register, and alert security operations of an intrusion attempt or operational anomaly.

Examples:

Intrusion Detection Systems (IDS), CCTV, Security Audit Log Audits

Corrective

Response & Recovery

Designed to actively minimize impact, rebuild system configurations, and restore stability after an exploit.

Examples:

Disaster Recovery Backups, IPS Block Rules, Active Incident Remediation

Deterrent

Psychological Decoy

Designed to discourage adversaries, increase perceived efforts, and visually signal defensive strength.

Examples:

High-Visibility Guard Towers, "Under CCTV Monitoring" Signs, Decoy Targets

Directive

Policy Mandate

Designed to govern organizational behavior, establish rules of conduct, and ensure standards compliance.

Examples:

Acceptable Use Policy (AUP), GDPR regulatory frameworks, NDAs

Compensating

Fallback Measure

Designed as temporary or alternative protections when standard controls are unavailable, impossible, or too costly.

Examples:

Hot sites, manual paper ledgers during terminal power outages, temporary security guards

Interactive Activity 1: The Tactical Functional Matching Challenge

Determine the correct functional control type for each enterprise scenario. Achieve a perfect match!

Loading Scenario...

Interactive Activity 2: Defense-In-Depth Architect

Deploy a multi-layered security plan. Assign the correct controls to mitigate the incoming threat.

Incoming Threat Scenario

Ransomware Lateral Movement

An attacker has breached an entry workstation and is attempting to deploy encryption payloads across your central servers.

Layer 1: Preventive Control
Empty slot
Layer 2: Detective Control
Empty slot
Layer 3: Corrective Control
Empty slot

Assessment: Verify Your Knowledge

Complete the 5 multiple-choice questions below to test your operational knowledge of control categories and functions.

1. A system administrator sets up a temporary firewall rule to block all inbound traffic from a specific subnet while the team investigates a breach. What functional type of control does this rule represent?

2. Which of the following best describes the core purpose of a "Directive" security control?

3. An enterprise security team configures a Host Intrusion Detection System (HIDS) to alert system engineers via SMS if critical registry values are modified. Which control type has been implemented?

4. During a massive blackout, an automatic badge reader entry system fails to unlock doors, and security guards are posted at the entrance to manually inspect employee IDs. The guards serve as which functional type?

5. Which of the following controls is categorized as CORRECTIVE?