TechKnowSurge
ISC2 CC 1.4 CompTIA A+ Core 2 2.1 Cisco CCST Cybersecurity 1.1 NIST CSF PR.AA-06 NIST CSF GV.PO-01
InteractiveSecurityFree

Spot the Controls

Search an office for its security controls, then name each one’s category and the type that fits it best.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

Security controls rarely come labelled. In a real building they are just part of the furniture — a fence, a camera over the door, a poster by the desks, a box in the server rack — sitting next to things that protect nothing at all. This activity drops you into one office and asks you to find them. Fifteen objects are clickable. Eleven are controls; four are ordinary things, and two of those are chosen to look like controls: a wet-floor warning sign sits in the same lobby as the CCTV sign, and a whiteboard hangs on the same wall as the acceptable use policy. Find any five controls and check them. For each one you decide which category it falls into — technical, administrative or physical — and which type best describes its main job. Real controls rarely do just one thing: a surveillance camera deters a would-be intruder and detects a break-in, and a barbed-wire fence both keeps people out and makes climbing it painful. So after each check you see every type labelled best fit, also fits or doesn’t fit, with a reason for each. Read each description closely, because it tells you what the control actually does here — the antivirus that found malware already on a laptop and quarantined it, the intrusion detection system that raises the alarm but blocks nothing.

How to play

This office has security controls in plain sight — and a few things that are not controls at all. Select any object in the picture (tap it, or press Tab to reach it and Enter to open it) to inspect it.

For each object, decide:

  1. What it is — a technical, administrative or physical control, or not a security control.
  2. Which type fits it best — preventative, deterrent, detective, corrective, recovery or compensating. Many controls serve more than one type, so pick the one that best describes its main job. Where two are genuinely tied, either counts.

Read each description closely: it tells you what the control actually does in this office. Press Check to see every type explained, then move on. Checked objects get a mark in the picture: ✓ full marks, ~ partly right, ✕ missed.

Check any 5 controls to finish. Each control is worth 2 marks — 1 for the category and 1 for the type, with half a mark for a type that fits but isn’t the best fit. Any non-control you inspect along the way is worth 1 mark for spotting it. 80% passes.

What you'll learn

Aligned to

ISC2 CC
1.4 Understand cybersecurity controls
CompTIA A+ Core 2
2.1 Summarize various security measures and their purposes.
Cisco CCST Cybersecurity
1.1 Define essential security principles
NIST CSF
PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk.
GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced.

Key terms

Technical Control
A security control implemented through technology — such as firewalls, antivirus software, encryption, or access control systems — rather than through physical measures or administrative policies.
Administrative Control
A cybersecurity control based on policies, procedures, and checklists that guide how an organization manages and implements its security practices.
Physical Control
A security control that protects assets through tangible, real-world measures — such as locks, security cameras, mantraps, fences, and safes — to prevent unauthorized physical access or tampering.
Preventative Control
A security control designed to stop a threat or incident from occurring in the first place. Firewalls, encryption, and access control policies are common examples of preventative controls.
Deterrent Control
A security control that discourages threat actors from attempting an attack by making the environment appear more difficult or risky to compromise. Warning banners, visible cameras, and security signage are common deterrent controls.
Detective Control
A security control that identifies and alerts on security incidents or anomalous activity as they occur or after the fact. Intrusion detection systems, security logs, and audit trails are examples of detective controls.
Corrective Control
A security control that addresses and remediates a security incident after it has been identified — such as restoring systems from backup, patching a exploited vulnerability, or blocking an attacker's IP address.
Recovery Control
A security control designed to restore systems, data, and normal operations after a security incident has been identified and contained. Backup restoration, disaster recovery procedures, and system reimaging are examples of recovery controls.
Compensating Control
An alternative security measure implemented to offset a known risk or vulnerability when a primary control cannot be fully applied. A compensating control must provide an equivalent or greater level of protection.
Security Control
Any safeguard or countermeasure — whether technical, physical, or administrative — implemented to protect the confidentiality, integrity, and availability of systems and data. Security controls are classified by function (preventative, detective, corrective) and type (technical, physical, administrative).

Topics

Interactive Cybersecurity Controls Hotspot

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →