ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 352 - SY0-601 discussion

Report
Export

An organization recently completed a security control assessment The organization determined some controls did not meet the existing security measures. Additional mitigations are needed to lessen the risk of the non-complaint controls. Which of the following best describes these mitigations?

A.
Corrective
Answers
A.
Corrective
B.
Compensating
Answers
B.
Compensating
C.
Deterrent
Answers
C.
Deterrent
D.
Technical
Answers
D.
Technical
Suggested answer: B

Explanation:

Compensating controls are additional security measures that are implemented to reduce the risk of non-compliant controls. They do not fix the underlying issue, but they provide an alternative way of achieving the same security objective. For example, if a system does not have encryption, a compensating control could be to restrict access to the system or use a secure network connection.

asked 02/10/2024
Kayode Omotosho
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first