Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

1.3. How Security Controls Work

💡 First Principle: Security controls exist to reduce risk — either by reducing the likelihood of a threat materializing, reducing the impact if it does, or both. Knowing what kind of reduction a control provides is as important as knowing the control exists.

Controls are categorized two ways simultaneously: by what they do (functional type) and by how they're implemented (implementation category). A physical lock is physical + preventive. A security awareness training program is administrative + preventive. A SIEM alert is technical + detective. The exam uses both dimensions.

⚠️ Common Misconception: Many candidates treat "preventive" and "detective" as if one is better than the other. Preventive controls stop harm before it occurs; detective controls identify harm after it begins. You need both — preventive controls are never 100% effective, and without detective controls you may never know when they fail.

Alvin Varughese
Written byAlvin Varughese
Founder15 professional certifications