Why its not Managerial: "Managerial controls involve policies, procedures, and guidelines established by management to guide the organization's operations and activities. While managerial controls play a role in implementing and enforcing security measures, they are not specifically related to MFA or patch management in this context."
E & F -- The CertMaster learn book defines Managerial as this:
Managerial—the control gives oversight of the information system. Examples could include risk identification or a tool allowing the evaluation and selection of other security controls.
And it defines Technical as this:
the control is implemented as a system (hardware, software, or firmware). For example, firewalls, antivirus software, and OS access control models are technical controls.
"describe the control type and category." Which, to me, means two different buckets. You have the "type" = Technical and the "category" = X. From looking at charts, I think preventative is the best fit. https://www.infosectrain.com/blog/types-of-security-controls/
D. Administrative: Both MFA and patch management involve administrative controls as they are implemented through policies, procedures, and governance structures established by management to manage security risks and ensure compliance with security requirements.
E. Preventative: Both MFA and patch management are preventative controls. MFA helps prevent unauthorized access to systems and data by requiring multiple forms of authentication, while patch management helps prevent security incidents by proactively addressing known vulnerabilities and weaknesses in software and systems before they can be exploited by attackers.
MFA (Multi-Factor Authentication) is an administrative control because it involves policies, procedures, and guidelines governing user authentication.
Patch management is a preventative control as it aims to prevent security vulnerabilities by ensuring that systems are up to date with the latest patches and updates.
The implementation of Multi-Factor Authentication (MFA) and patch management involves controls that fall under different types and categories. Here are the control types and categories for each:
Multi-Factor Authentication (MFA):
Control Type: Technical
Category: Preventative
Explanation: MFA is a technical control that falls under the preventative category. It prevents unauthorized access by requiring users to provide multiple forms of identification before accessing a system or resource.
Patch Management:
Control Type: Administrative
Category: Preventative
Explanation: Patch management is an administrative control that falls under the preventative category. It involves the process of planning, testing, and applying patches to systems and software to prevent vulnerabilities from being exploited.
So, the correct options are:
F. Technical (for MFA)
D. Administrative (for patch management)
B & E
Why B? Via Nist:
Organizations typically exercise managerial, operational, and financial control over their information systems and the security provided to those systems, including the authority and capability to implement or require security controls deemed necessary to protect organizational operations and assets, individuals, other organizations, and the Nation.
I think you really have to focus on the phrasing of this question. If MFA was already being used, then I believe it would fall under technical, but at this point in time, it's still being implemented, and so it would fall under managerial.
Its not technical. According to comptia: Technical controls are primarily built into the information system through mechanisms contained in hardware, software, or firmware components. The example is Biometrics.
getting bit annoyed with the wrong answers people are not studying properly - it clearly states that managerial controls are processes and procedures technical is logical access control systems and security systems itself.
B. Managerial
E. Preventative
Creating the policy that MFA must be used is in the Managerial control category.
Creating a patch management program or system is also in the Managerial control category.
MFA is a preventive control type
Patch management is also a preventive control type.
So, by the same token, the question could have read... "A Security Technician is implementing..."
They are both in the Preventative & Technical control category. To create a Patch Management Program requires sound TECHNICAL nuances; same applies to designing/implementing an MFA.
Thereafter, they are both methods that offer different levels of PREVENTION against malicious actors.
upvoted 2 times
...
...
...
This section is not available anymore. Please use the main Exam Page.SY0-601 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Hs1208
Highly Voted 1 year, 5 months agocannon
Highly Voted 1 year, 4 months agoAnonym0us_
Most Recent 1 year, 1 month agoec05581
1 year, 2 months agodbdbfb0
1 year, 2 months agonshaheen8
1 year, 3 months agoMF757
1 year, 3 months agofryderyk
1 year, 3 months agoID77
1 year, 3 months agomemodrums
1 year, 4 months agosalah112
1 year, 4 months agoStaticK9
1 year, 4 months ago[Removed]
1 year, 4 months ago7308365
1 year, 4 months ago7308365
1 year, 4 months agocaseymd85
1 year, 4 months agoHarrysa
1 year, 4 months agoganymede
1 year, 5 months agoganymede
1 year, 5 months agoYomzie
1 year, 5 months ago