Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CompTIA SY0-701 Exam - Topic 1 Question 59 Discussion

Which of the following control types involves restricting IP connectivity to a router's web management interface to protect it from being exploited by a vulnerability?
C) Preventive
A) Corrective
B) Physical
D) Managerial

CompTIA SY0-701 Exam - Topic 1 Question 59 Discussion

Actual exam question for CompTIA's SY0-701 exam
Question #: 59
Topic #: 1
[All SY0-701 Questions]

Which of the following control types involves restricting IP connectivity to a router's web management interface to protect it from being exploited by a vulnerability?

Show Suggested Answer Hide Answer
Suggested Answer: C

Restricting access to a router's web management interface is apreventive control (C). This type of control is implementedbefore a threat occursto reduce the likelihood of exploitation.

CompTIA Security+ SY0-701listspreventive controlssuch asIP whitelisting, ACLs, and firewallsunderDomain 1.4: Security controls.


Contribute your Thoughts:

0/2000 characters

Yuki Cho

15 days ago
This is a preventive control distinguishing preventive vs detective is tricky, but restricting access helps.
upvoted 0 times

Harsh Kumar

15 days ago
User N: Agree, restricting IP access clearly helps; adding an ACL or whitelist enhances the preventive control by limiting who can reach the interface.
upvoted 0 times

Matthew Taylor

14 days ago
User M: I was stuck between B and C too, that mixup about preventive vs detective confused me until the example on preemptive controls clarified it.
upvoted 0 times

Michael Davis

13 days ago
User N: That's true, and as you pointed out, ACLs or whitelists strengthen the preventive control by limiting who can reach the router's interface.
upvoted 0 times
...
...

Abdullah Hassan

14 days ago
Because the goal is to stop exploitation before it happens, restricting IP access is preventive, while detective controls would only monitor or log activity after the fact, not prevent initial access.
upvoted 0 times

Adnan Hussain

12 days ago
User N: That's true, but restricting IPs is primarily preventive; logging attempts would add detective value without changing the initial preventive aim.
upvoted 0 times
...
...

Andrei Novikov

14 days ago
That's true, restricting IPs strengthens the preventive control; ACLs or a whitelist further reduce exposure to the router's web interface.
upvoted 0 times

Miguel Marino

14 days ago
Exactly, restricting IPs is preventive; adding ACLs or a whitelist strengthens that preventive control even more.
upvoted 0 times
...
...
...

Rupali Kapoor

15 days ago
User N: You're right, but this question focuses on a preventive control implemented before exploitation rather than a detective measure.
upvoted 0 times

Tariq Choudhury

12 days ago
User N: Agree. Exactly, it's a preventive control implemented before exploitation rather than a detective measure in this context.
upvoted 0 times

Faisal Ali

12 days ago
Exactly. To add nuance, preventive controls like IP restrictions reduce exposure before an attack, while detective controls would flag or log attempts after they occur.
upvoted 0 times
...
...

Shruti Nair

14 days ago
User M: I was unsure too, the 'implemented before exploitation' phrasing made me doubt if it was preventive or detective at first.
upvoted 0 times

Kazuki Pham

13 days ago
User N: That's true, but the key is it's implemented before exploitation, which makes it preventive rather than detective.
upvoted 0 times
...
...

Rachel Allen

14 days ago
User N: Because it blocks an attack before it happens, restricting the router's web interface is preventive. The key difference is detective controls detect incidents after the fact, not preemptively blocking access.
upvoted 0 times

Wei Choi

13 days ago
Exactly, the distinction matters. It's a preventive control implemented before exploitation, not a detective measure.
upvoted 0 times
...
...
...

Clara Marino

15 days ago
User N: Why wouldn't B Physical be considered a detective control in this router access scenario?
upvoted 0 times

Carmen Ricci

12 days ago
User N: That's true, but the subtle distinction is that restricting access prevents exploitation (preventive) whereas detective controls would log or alert after an attempt.
upvoted 0 times

Lucia Andersen

11 days ago
That's right, but another nuance is that some controls are both preventive and detective. For example, an IP ACL can block access (preventive) and log attempts (detective).
upvoted 0 times
...
...

Emily Carter

15 days ago
I was torn between B and C too; the confusing part was whether restricting access is detective or preventive before an incident.
upvoted 0 times

Rupali Shah

14 days ago
That's plausible, but detective controls detect after something happens; restricting IP access to the router's web UI prevents exploitation in the first place, so it's preventive.
upvoted 0 times
...
...

Carmen Fernandez

15 days ago
Because a physical control would secure the device or environment, not the router’s web access. Detective controls observe incidents after they occur; this scenario prevents access beforehand.
upvoted 0 times

Sigrid Esposito

14 days ago
User N: That’s true, but this scenario specifically shows a preventive control: restricting IP access prevents exploitation before it occurs, unlike detective controls that only observe after.
upvoted 0 times
...
...
...

Giovanni Lopez

15 days ago
User 2: I was stuck between A and C too, the idea of preventive vs detective was confusing. The note about restricting access before threats helped.
upvoted 0 times

Patricia Carter

14 days ago
User N: That's true, but the distinction is that restricting access before an attack happens makes it preventive, not detective.
upvoted 0 times

Jian Huang

13 days ago
User N: That helps, and to clarify, preventive controls stop exploitation before it happens, while detective controls identify and respond after an event.
upvoted 0 times
...
...

Joseph Baker

14 days ago
User N: The key difference is timing: preventive controls are put in place before threats to reduce likelihood, while detective controls identify issues after they occur. Restricting router access is preventive.
upvoted 0 times

Kazuki Sato

13 days ago
That's true, and as you noted, restricting IP connectivity before threats makes it preventive rather than detective.
upvoted 0 times
...
...

Bushra Rizvi

15 days ago
User N: I was torn between A and C too, the preventive vs detective mix was murky. That note about restricting access clarified it's preventive.
upvoted 0 times

Stephanie Johnson

12 days ago
That's true, and a subtle distinction: restricting access is preventive because it blocks exploitation before it begins, rather than detecting it after.
upvoted 0 times
...
...
...

Zainab Iqbal

15 days ago
Agree, restricting access clearly shows this is a preventive control.
upvoted 0 times

Ana Kuznetsov

15 days ago
User N: Because this restriction stops attackers before they reach the router web interface, it's preventive; detective would only alert on access attempts after they occur, not block them upfront.
upvoted 0 times

Preeti Saxena

13 days ago
That's true, but the distinction is that it blocks before any access attempt, making it preventive rather than detective.
upvoted 0 times
...
...

Duc Park

15 days ago
User N: That's true, and the subtle distinction is that restricting access is preventive, blocking exploitation before it happens, whereas detective would only detect attempts after they occur.
upvoted 0 times

Nicolas Lopez

12 days ago
That's true, but the scenario could also benefit from detective monitoring to catch misconfigurations later.
upvoted 0 times
...
...

Katya Kristiansen

15 days ago
User N: I was torn between preventive and managerial at first; that 'before a threat occurs' detail helped me see restrict access as preventive.
upvoted 0 times

Pallavi Tiwari

12 days ago
That makes sense. The key distinction is that preventive controls act before an incident, while managerial controls govern processes; restricting IP access is preventive.
upvoted 0 times
...
...
...

Jin Yamamoto

15 days ago
User N: Because this is applied before an exploit, it prevents the threat from happening, and detective controls would detect after an attempt rather than stop it at the gateway.
upvoted 0 times

Tao Nguyen

12 days ago
That aligns with your point that it prevents the exploit, but the question targets preventing access at the gateway, hence preventive.
upvoted 0 times

Clara Lopez

12 days ago
User N: That's true, but the key nuance is gateway-level prevention: restricting IP to the router's web interface blocks exploitation before it even reaches the device.
upvoted 0 times
...
...

Clara Sokolov

15 days ago
I was stuck between A and C too since it sounds like a detective measure, but the 'before an exploit' wording clarified it's preventive.
upvoted 0 times

Sumayya Jamil

13 days ago
User N: Exactly. Preventive controls act before an exploit, so restricting access to the router's web interface stops the threat at the gateway, not after an attempt.
upvoted 0 times
...
...

Yuna Choi

15 days ago
Because the access is blocked before any exploit can occur, it is preventive; detective controls would only flag an attempt after it happens, not stop it at the gateway.
upvoted 0 times

Neha Sharma

15 days ago
User N: Exactly, that aligns with preventive controls: it blocks access before exploitation rather than flagging it after an attempt.
upvoted 0 times
...
...
...

Geeta Chopra

15 days ago
I disagree with the tricky part; restricting access is clearly a preventive control, not a detective one.
upvoted 0 times

Umar Raza

14 days ago
Because detective controls identify incidents after they occur, while restricting access blocks exploitation upfront; IP whitelisting and ACLs are preventive, not detective.
upvoted 0 times

Ali Baig

13 days ago
User N: That's true, but the subtle distinction is that blocking access upfront is preventive, whereas detective would flag after a breach.
upvoted 0 times
...
...

Aditya Mishra

15 days ago
User N: That's true, but even preventive measures can include detective elements like logging attempts; restricting IP access remains a preventive control.
upvoted 0 times

Eunji Vo

12 days ago
User N: That's true, but a subtle distinction: restricting access is preventive by design, while logging is detective, and together they complement each other but don't change the control type.
upvoted 0 times
...
...

Thomas Carter

15 days ago
User N: I was stuck on whether it’s preventive or detective; that wording confused me, but the explanation of preventive controls helped clarify it.
upvoted 0 times

Kunal Joshi

13 days ago
User N: That's true, but the subtle distinction is that detective controls catch incidents after they occur. Restricting access prevents exploitation in the first place.
upvoted 0 times
...
...
...
...

Sneha Kumar

16 days ago
I think C is correct, distinguishing preventive vs detective controls in network security is tricky.
upvoted 0 times

Ritu Kapoor

15 days ago
Because it stops an exploit before it happens by denying unauthorized access, rather than detecting it later. The key difference is preventative controls reduce risk while detective controls identify incidents after they occur.
upvoted 0 times

Robert Wright

14 days ago
User 2: Same here I was between C and D at first; the preventive vs detective wording tripped me up, this explanation helped.
upvoted 0 times

Fatima Nawaz

12 days ago
I agree with your assessment; it's clearly a preventive control, so C is correct.
upvoted 0 times
...
...

Hao Sato

15 days ago
That is right, and the distinction here is preventive controls block access before an exploit happens, whereas detective controls only detect and alert after an attempted access.
upvoted 0 times

Maryam Raza

13 days ago
I agree with that distinction; restricting IP access to the router's web interface is a preventive control that reduces risk before exploitation.
upvoted 0 times
...
...

Joseph Johnson

15 days ago
User N: That's true, but as the child noted, preventive controls block access up front, while detective controls detect or log attempts after they happen.
upvoted 0 times

Ingrid Ivanov

14 days ago
User N: That's true, but the key subtlety is that the question targets a preventive control, restricting access blocks exploitation before it can occur.
upvoted 0 times
...
...
...

Deepak Patel

15 days ago
I was between B and C too; restricting IP access to a router's web interface being preventive was confusing, but the preventive concept helped.
upvoted 0 times

Sofia Fedorov

14 days ago
User N: That's true, but the subtle distinction is that IP restriction reduces exposure before an attack, making it preventive rather than detective.
upvoted 0 times

Ankit Saxena

13 days ago
User N: That's true, but the subtle distinction is that preventive controls reduce exposure before an attack, so restricting IP access is still preventive.
upvoted 0 times
...
...

Rajesh Gupta

15 days ago
Because blocking access before an attack starts reduces exposure, this is preventive. Physical or managerial controls address other angles, and the router rule here is an access-control preventive measure.
upvoted 0 times

Ali Khan

15 days ago
User N: That's true, but the subtle distinction is that IP filtering is preventive because it blocks exposure before an attack, not a detective control that logs breaches.
upvoted 0 times
...
...

Abdullah Islam

15 days ago
I was torn between B and C too, the confusing part was why restricting access is preventive, but the 'before an attack' framing helped.
upvoted 0 times

Rahul Rao

14 days ago
User N: That's true; restricting IP access is preventive because it blocks the route before an attacker exploits the router, a preemptive measure that reduces exposure.
upvoted 0 times
...
...
...

Umar Rizvi

15 days ago
That's true, but your point about access controls overlaps with preventive measures; the exam asks for a preventive control.
upvoted 0 times

Daniel King

14 days ago
I also got hung up by labeling access controls as preventive, the tricky bit was separating preventive from detective in practice.
upvoted 0 times

Preeti Sinha

13 days ago
That's true, but the key distinction is preventive controls act before an incident; access controls can be detective through logs, while here restricting IP access makes it preventive.
upvoted 0 times
...
...

Yan Kim

15 days ago
Because it blocks unauthorized access before any exploit, it acts as a preventive control; access controls are the mechanism, but the exam asks the control’s preventive purpose, not the method.
upvoted 0 times

Neha Agarwal

14 days ago
That's right, but note the subtle distinction: the exam cares about the control type (preventive), not the specific mechanism like an ACL or firewall.
upvoted 0 times
...
...

Rosa Esposito

15 days ago
User N: You're right that distinguishing preventive vs detective controls can be tricky; in this case restricting access to the router's web interface is a preventive control.
upvoted 0 times

Emi Chen

13 days ago
I agree the answer is preventive; one subtle distinction is that access controls can be detective if they log and alert, but here restricting access remains preventive.
upvoted 0 times
...
...
...

Mark Parker

15 days ago
Agree, preventive controls stop threats before they happen.
upvoted 0 times

Khanh Hoang

14 days ago
Initially I was between B and C too because preventive vs detective was confusing. The explanation about before threats clarifies why restricting access is preventive.
upvoted 0 times

Minhee Kato

14 days ago
User N: Yes, that makes sense. To clarify, the control is preventive because it's applied before an exploit; detective would only alert after a breach.
upvoted 0 times
...
...

Sunita Mehta

15 days ago
Because it blocks access to the router before an exploit can occur, preventive controls stop threats upfront, while detective controls only log or alert after an attack begins.
upvoted 0 times

Bjorn Novikov

14 days ago
That's true, but the subtle distinction is proactive prevention versus post-event detection; even preventive controls can be complemented by detective controls for layered security.
upvoted 0 times
...
...

Tao Nakamura

15 days ago
User N: That's true, but this example focuses on a preventive control restricting router web access rather than detective measures used later.
upvoted 0 times

Aiko Zhao

15 days ago
User N: That's true, but a subtle distinction: preventive controls block access before exploitation, while detective controls detect and alert on access attempts after they occur.
upvoted 0 times
...
...
...

Ali Raza

15 days ago
I don't think C is right, because the question emphasizes hardening access, which is clearly preventive; it's not detective.
upvoted 0 times

Sanjay Kumar

15 days ago
I was stuck between B and C too because preventive vs detective felt fuzzy; the explanation clarified that restricting access is preventive.
upvoted 0 times

Xiao Lee

13 days ago
User N: Exactly. Restricting the router's web interface is preventive because it stops exploitation before it occurs, not detected afterward.
upvoted 0 times
...
...

Mark Williams

15 days ago
User N: That's true, but the question is about preventive controls. Restricting the router's web interface is exactly a preventive measure, so C is correct.
upvoted 0 times

Karen Baker

12 days ago
User N: You're right that hardening access suggests preventive controls; however the scenario targets preventing exploitation, so restricting the router interface is a preventive measure (C).
upvoted 0 times
...
...

Kunal Rao

15 days ago
You're right that hardening access leans preventive; the key difference is timing: preventive controls stop the attack before it happens, detective controls detect after the event.
upvoted 0 times

Ryan Jackson

13 days ago
I see why it seems tricky, but restricting access is preventive because it stops exploitation before it happens, not after.
upvoted 0 times
...
...
...

Ritu Chopra

16 days ago
Agree, preventive controls are before threat; adding IP whitelisting or ACLs helps limit access to the router UI.
upvoted 0 times

Preeti Patel

15 days ago
I was torn between C and D too; the 'before threat' wording tripped me up. Seeing IP whitelisting labeled preventive helped me.
upvoted 0 times

Sana Farooqi

13 days ago
User N: That's right. Restricting access before any threat makes it preventive, like IP whitelisting and ACLs; detective or managerial controls wouldn't block that upfront.
upvoted 0 times
...
...

Bao Tanaka

15 days ago
User N: That's true, but note the distinction: restricting the router's UI via IP whitelisting is a technical preventive control, not a managerial one.
upvoted 0 times

Luca Popov

13 days ago
That's true, and it's a technical preventive control rather than a managerial one, since it blocks access before exploitation rather than relying on policy.
upvoted 0 times
...
...

Omar Hashmi

15 days ago
You're right; the key difference is preventive controls stop an exploit before it starts. Limiting router UI access with IP whitelisting/ACLs reduces exposure so no unauthorized attempts succeed.
upvoted 0 times

Alejandro Morozov

14 days ago
That's true, and to add nuance: preventive controls like IP whitelisting reduce exposure; adding ACLs at the router edge further ensures only trusted sources reach the UI.
upvoted 0 times
...
...
...

Magnus Petrov

16 days ago
Why wouldn’t D be considered preventive here, given policy controls shape access to the management interface?
upvoted 0 times

Pierre Bianchi

12 days ago
That's a fair point, but there's a subtle distinction: policy controls are managerial, while restricting IP access to the interface is a preventive control.
upvoted 0 times

Elena Fernandez

12 days ago
User N: That's true, but the question targets a preventive technical measure; D is managerial, while IP restriction is a preemptive control.
upvoted 0 times
...
...

Carlos Ferrari

15 days ago
I was stuck between D and C too. The policy controls shaping access confused me, but preventive means the actual blocking action.
upvoted 0 times

Shruti Dubey

13 days ago
User N: That's true, but the key distinction is that D is managerial and shapes policy, not the actual block; the blocking is preventive (C).
upvoted 0 times
...
...

Ritu Chopra

15 days ago
You're right that policy can shape access, but D is managerial. Preventive here is the actual control that blocks access (ACLs/firewalls). The requirement is the concrete preventive mechanism, not the governance policy.
upvoted 0 times

Ibrahim Jamil

13 days ago
Exactly. The preventive mechanism is the ACL or firewall itself, not the governance policy; policies guide access, but blocking access is the concrete preventive control.
upvoted 0 times
...
...
...
...
Terrilyn
3 days ago
I thought it was B) Physical at first.
upvoted 0 times
...
Shakira
8 days ago
Agreed, C makes the most sense!
upvoted 0 times
...
Tomoko
13 days ago
It's definitely C) Preventive.
upvoted 0 times
...
Latonia
19 days ago
I thought it was B) Physical at first.
upvoted 0 times
...
Carlee
24 days ago
It's definitely C) Preventive.
upvoted 0 times
...
Leontine
29 days ago
I feel like the answer could be managerial too, but that doesn't really fit the context of restricting IP connectivity. I'm leaning towards preventive.
upvoted 0 times
...
Oliva
1 month ago
This sounds similar to a practice question we had on securing management interfaces. I want to say it's preventive, but I could be mixing it up with corrective controls.
upvoted 0 times
...
Breana
1 month ago
I'm not entirely sure, but I remember something about restricting access being a physical control? That doesn't seem right now that I think about it.
upvoted 0 times
...
Alayna
1 month ago
I think this might be related to preventive controls since we're trying to stop vulnerabilities before they can be exploited.
upvoted 0 times
...

Save Cancel