Certified Incident Handler (CIH) Practice Ecam

Disable ads (and more) with a membership for a one time $2.99 payment

Prepare for the Certified Incident Handler (CIH) Exam. Enhance your knowledge with interactive quizzes and detailed insights into cyber incident handling. Boost your exam readiness with our expert-designed questions!

Each practice test/flash card set has 50 randomly selected questions from a bank of over 500. You'll get a new set of questions each time!

Practice this question and more.


Which type of control is designed to prevent incidents from occurring?

  1. Detective control

  2. Preventive control

  3. Corrective control

  4. Technical control

The correct answer is: Preventive control

Preventive control is specifically designed to avoid incidents before they occur. These controls proactively address vulnerabilities and mitigate risks through various measures, ensuring that potential threats do not materialize into actual security incidents. Examples of preventive controls include implementing firewalls, enforcing password policies, conducting security training for employees, and utilizing encryption technologies. Detective controls, in contrast, are focused on identifying and detecting incidents once they have occurred. Their purpose is to provide alerts and records of events for investigation. Corrective controls come into play post-incident, aiming to rectify and recover from occurrences, while technical controls primarily refer to the technological measures put in place, which can be preventive, detective, or corrective depending on their designed function. Thus, preventive control is the most appropriate choice for preventing incidents from happening in the first place.