TechKnowSurge
CompTIA Security+ 1.1 CompTIA CySA+ 2.4 CompTIA Security+ 5.1 CompTIA Security+ 1.2
InteractiveSecurityFree

Security Control Type Sorter

Sort security controls into Technical, Administrative, or Physical categories, each labeled with its function (Preventive, Detective, Corrective).

Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

Every control in this activity carries two labels, and only one of them is what you are being asked for. The bracketed word — Preventive, Detective, Corrective — says what the control does about a threat: stop it, notice it, or clean up after it. The bin you drop the card into says something different: how the control is actually built. Technical controls are enforced by technology, Administrative controls are enforced by written policy and human process, and Physical controls are enforced by objects you could walk up and touch. The two axes are independent, which is why every bin here holds a preventive, a detective and a corrective example rather than clustering by function. Read the label, then ignore it and ask what the thing is made of. That reframing is what most of the traps turn on. An incident response plan is activated after a breach, which makes it sound operational and urgent, but the plan is a document that tells people what to do — Administrative. Security awareness training is about technology and is delivered on a screen, but what does the work is the process of running the training, not any software involved — Administrative again. A UPS is the sharpest case: a battery in a rack is unambiguously a tangible object, so it is Physical, and it is Corrective because it restores availability after the power has already failed rather than preventing the failure. Antivirus is tagged Detective here for a reason worth pausing on — signature scanning's job is to identify known malware; quarantining or blocking is a separate action that follows the detection. One wrinkle to carry into the exam room: CompTIA Security+ SY0-701 objective 1.1 lists control categories as technical, managerial, operational and physical, splitting what this activity and most other frameworks call Administrative into two. The mechanism test is identical — policy and process rather than technology or barriers — but if the exam offers you "managerial" and "operational" instead of "administrative", they are the two halves of the same category, not a fourth and fifth type.

What you'll learn

Aligned to

CompTIA Security+
1.1 Compare and contrast various types of security controls.
5.1 Summarize elements of effective security governance.
1.2 Summarize fundamental security concepts.
CompTIA CySA+
2.4 Given a scenario, recommend controls to mitigate attacks and software vulnerabilities.

Key terms

Security Control
Any safeguard or countermeasure — whether technical, physical, or administrative — implemented to protect the confidentiality, integrity, and availability of systems and data. Security controls are classified by function (preventative, detective, corrective) and type (technical, physical, administrative).
Technical Control
A security control implemented through technology — such as firewalls, antivirus software, encryption, or access control systems — rather than through physical measures or administrative policies.
Administrative Control
A cybersecurity control based on policies, procedures, and checklists that guide how an organization manages and implements its security practices.
Physical Control
A security control that protects assets through tangible, real-world measures — such as locks, security cameras, mantraps, fences, and safes — to prevent unauthorized physical access or tampering.
Preventative Control
A security control designed to stop a threat or incident from occurring in the first place. Firewalls, encryption, and access control policies are common examples of preventative controls.
Detective Control
A security control that identifies and alerts on security incidents or anomalous activity as they occur or after the fact. Intrusion detection systems, security logs, and audit trails are examples of detective controls.
Corrective Control
A security control that addresses and remediates a security incident after it has been identified — such as restoring systems from backup, patching a exploited vulnerability, or blocking an attacker's IP address.
Access Control
A security mechanism that restricts access to resources based on policies, roles, or identity.
Security Framework
A structured set of guidelines, best practices, and standards used as a starting point for designing and implementing a security program, such as the NIST Cybersecurity Framework.

Topics

Interactive Categorize

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →