Certified In Cybersecurity CC · Free Practice Question Easy

Question 82

As the IT security manager for a financial institution, you are constantly looking for ways to prevent unauthorized access to sensitive systems or data. What type of security control is designed to restrict access to resources based on an individual's need to know and role within an organization?
  • A Network security control
  • B Administrative control
  • C Encryption control
  • D Physical security control
Reveal correct answer

Correct answer: B

Explanation

The correct answer: Administrative controls, also known as procedural controls, are the policies and procedures put in place to manage the behavior of users. This includes policies like access control, which limit access to resources based on an individual's need to know and their role within an organization. These controls dictate how, when, where, and by whom the systems and data can be accessed, used, and managed. The incorrect answers: Physical security control: While these controls are essential for maintaining the security of data centers and other physical resources, they primarily concern preventing physical access to resources rather than restricting digital access based on an individual's role or need to know. Network security control: This type of control refers to the mechanisms put in place to protect the integrity and usability of network and data. They are typically used to prevent unauthorized access, use, disclosure, disruption, modification, or destruction of information on the network. However, network security controls in themselves do not necessarily restrict access based on individual's role or need to know. Encryption control: Encryption is a method of converting data into a code to prevent unauthorized access. While it is a vital part of data security, it does not inherently restrict access to resources based on an individual's need to know and role within an organization. It primarily provides confidentiality to the data in transit or at rest but doesn't deal with who should have access based on their role.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need