Which type of control is designed to detect an attack while it is occurring?

Disable ads (and more) with a premium pass for a one time $4.99 payment

Enhance your CompTIA Security+ exam readiness with flashcards and multiple-choice questions, including hints and detailed explanations. Prepare effectively for a successful exam experience!

Detective controls are specifically designed to identify and detect security incidents as they occur, which makes them essential for maintaining security and responsiveness in an organization. These controls provide alerts and notifications about suspicious activities or potential threats, allowing security teams to respond to incidents in real-time. Examples include intrusion detection systems (IDS), security information and event management (SIEM) systems, and logs that highlight anomaly detection.

In contrast, preventative controls aim to stop issues before they happen, such as firewalls and access control measures. Corrective controls focus on restoring systems after an incident has occurred, while compensating controls provide alternative protections when primary controls are ineffective or impractical. Therefore, in the context of this question, the best choice that fulfills the requirement of detecting ongoing attacks is indeed the detective control.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy