StudyToCert

All certifications / Security+ / Lessons

CompTIA Security+ SY0-701 · Domain 1: General security concepts

Control types: preventive, deterrent, detective, corrective, compensating, directive

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

Control types describe what a control does to a threat, independent of how it is implemented. SY0-701 lists six: preventive, deterrent, detective, corrective, compensating and directive. Every control has a category (technical, managerial, operational or physical) and a type, and exam questions deliberately mix the two lists, so knowing both vocabularies precisely is worth easy points. Understanding types also helps real design work: a good program stops what it can, notices what it cannot stop, and fixes the damage when something gets through.

Preventive controls stop an incident from happening at all. Firewall rules that block traffic, locked doors, MFA, input validation and separation of duties are preventive. Deterrent controls discourage an attacker from trying, but do not physically or technically stop them. Warning signs, visible cameras, login banners that warn of prosecution and lighting around a building are deterrents. The key difference: a preventive control still works against someone who ignores it, while a deterrent only works if the attacker is put off. A fence prevents; a 'trespassers will be prosecuted' sign deters.

Detective controls identify and record that something happened or is happening. Intrusion detection systems (IDS), log review, security information and event management (SIEM) alerts, audits, file integrity monitoring and motion sensors are detective. They do not stop the event, but they let you respond. Corrective controls fix or reduce damage after an incident: restoring from backup, reimaging an infected host, applying a patch after exploitation, or an intrusion prevention system (IPS) terminating a malicious session. Detective finds; corrective repairs.

Compensating controls are alternatives used when the preferred control is not possible or practical. If a legacy medical device cannot be patched, isolating it on its own network segment with tight firewall rules compensates for the missing patch. If a small team cannot fully separate duties, extra management review of logs compensates. A compensating control should address the same risk to a similar degree, and it is usually documented as a formal exception. Directive controls tell people what to do or not do: policies, acceptable use agreements, procedures, signs saying 'authorized personnel only' and training instructions. They rely on people choosing to comply.

A worked walk-through makes the lifecycle clear. Imagine ransomware aimed at a file server. Email filtering and application allow listing are preventive. A policy forbidding users from running unapproved software is directive. The login banner warning that activity is monitored is deterrent. EDR raising an alert when files are being mass-encrypted is detective. Restoring the files from immutable backups is corrective. And if the file server runs an old operating system that cannot receive the vendor's fix, putting it behind a restrictive firewall is compensating. One threat, six types, and a question could ask about any of them.

Many controls have more than one type, and the exam wants the best fit for the scenario. A visible camera is detective because it records, and deterrent because people see it. A guard can deter, detect and prevent. When a question describes a single function, answer that function. 'Cameras were installed so incidents could be reviewed later' is detective. 'Cameras were mounted in plain view to discourage theft' is deterrent. Read the purpose in the sentence rather than picking the control's most famous role.

Common mistakes: calling an IDS preventive (it detects; an IPS placed inline can prevent); calling backups preventive (backups do not stop the incident, they support recovery, so the restore is corrective, though some texts also call backups a recovery control); confusing deterrent and directive (deterrent discourages attackers with consequences; directive instructs people who are expected to comply, usually insiders); and assuming a compensating control is just any extra control. Compensating specifically replaces a control that cannot be used as intended.

Question framing tends to follow clue words. 'Stop', 'block', 'prevent' point to preventive. 'Discourage', 'warn', 'visible' point to deterrent. 'Identify', 'alert', 'log', 'discover', 'after the fact review' point to detective. 'Restore', 'remediate', 'recover', 'fix' point to corrective. 'Cannot be patched', 'alternative', 'legacy', 'exception' point to compensating. 'Policy', 'instruct', 'must', 'acceptable use' point to directive. When a scenario says a requirement cannot be met and asks what to do, compensating is almost always the answer.

Key terms

Preventive control
Stops an incident before it happens, such as a firewall rule, lock or MFA.
Deterrent control
Discourages an attacker from trying, such as a warning sign, visible camera or login banner.
Detective control
Identifies or records an incident, such as an IDS, SIEM alert, audit or log review.
Corrective control
Limits damage and restores normal operation after an incident, such as restoring backups or reimaging.
Compensating control
An alternative control used when the primary control cannot be implemented, addressing the same risk.
Directive control
Instructs people on required behavior, such as a policy, procedure or acceptable use agreement.
Real-world example

A hospital runs an imaging system on an operating system the vendor no longer patches, and replacing it would cost millions. The security team places it on an isolated VLAN, allows only the imaging workstations to reach it, and adds extra monitoring of its traffic. They document these compensating controls in a risk exception signed by the business owner, and review the exception every quarter until the device is replaced.

Exam tip: When a question says the normal control 'cannot' be applied, look for compensating. When a control only discourages but would not physically stop a determined attacker, it is deterrent, not preventive.

Check yourself

An IDS alerts on suspicious traffic but does not block it. What type of control is it?

Detective, because it identifies and reports the activity without stopping it.

A company cannot enable MFA on a legacy application, so it restricts access to that app to a single jump server with MFA. What type of control is this?

Compensating, because it provides an alternative way to reduce the same risk when the preferred control is not possible.

A sign reading 'Visitors must sign in at reception' is posted in the lobby. Is it deterrent or directive?

Directive, because it instructs people what to do rather than threatening consequences to discourage an attacker.

Why is restoring from backup considered corrective rather than preventive?

It does not stop the incident; it repairs the damage and returns systems to normal afterward.

Study Security+ for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Security+ study plan