Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

2.1. Security Controls

💡 First Principle: Every security breach traces back to a control that was missing, misconfigured, or insufficient. Security controls are the building blocks of every defense strategy — they exist to reduce risk. But a pile of controls isn't a security program any more than a pile of bricks is a building. The first step to designing a coherent defense is classifying controls along two independent dimensions: category (who implements it?) and type (what does it achieve?).

What breaks without proper classification? Compliance audits fail because you can't demonstrate layered coverage. Security architectures develop blind spots — an organization might stack five firewalls (all technical/preventive) while having zero detective controls and no incident response procedures. Imagine securing a home: you might install deadbolts (physical/preventive) and alarms (physical/detective), but if you never lock the deadbolt (operational gap) and have no insurance policy (managerial gap), you're exposed despite spending on technology.

The exam frequently presents a control and asks you to classify it on both dimensions simultaneously. A security camera is physical AND detective. An acceptable use policy is managerial AND directive. Master both axes, and you'll answer these questions instantly.

⚠️ Exam Trap: "Administrative" and "managerial" mean the same thing on SY0-701 — CompTIA uses "managerial" in the official objectives, so don't be thrown if a question uses the older term.

One more classification pattern worth internalizing: directive controls often get confused with preventive ones, since a policy is meant to prevent problems — but a policy that simply says "don't do X" without an enforcement mechanism is directive, not preventive. A firewall rule that actually blocks the traffic is preventive; the acceptable-use-policy paragraph telling employees not to visit certain sites is directive, because it relies on the employee choosing to comply. Similarly, compensating controls only apply when the primary control genuinely can't be implemented — if a legacy system can't run modern encryption, requiring extra network segmentation and monitoring around it is a compensating control, not just "defense in depth" applied loosely. The exam rewards precision here: identify the category first (who or what implements it), then the type (what it accomplishes), and resist the urge to guess based on vibes alone.

Alvin Varughese
Written byAlvin Varughese
Founder18 professional certifications