After a recent ransomware attack on a company's system, an administrator reviewed the log files. Which of the following control types did the administrator use?
Choose an answer
Tap an option to check your answer.
Correct answer: Detective.
Why this is the answer
The administrator used a detective control. Detective controls are designed to identify and alert about security incidents that have already occurred. In this scenario, reviewing log files after a ransomware attack is an activity aimed at understanding what happened, how it happened, and the extent of the damage, which are all functions of a detective control. Preventive controls aim to stop incidents before they occur. Corrective controls are used to fix issues after an incident, such as restoring data from backups. Compensating controls are alternative controls used when a primary control cannot be implemented.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed