An analyst reviews a vulnerability-management program and notes that critical CVEs are patched within 14 days to stop attackers from using published exploits against internet-facing servers. Which control type does this patching activity best represent?
Select an answer to reveal the explanation.
Short Explanation
Think of patching like locking the door before someone tries the knob. You are stopping the break-in, not just noticing it after the fact. That makes it a preventive control, not a detective or corrective one.
Full Explanation
Patch management is classified as a preventive control because it acts before an adversary can exploit a known software defect. By applying vendor fixes, configuration updates, or firmware updates, the organization reduces the likelihood that a publicly disclosed vulnerability becomes a successful intrusion. Detective controls are wrong because they identify activity after it has occurred, such as alerting on suspicious behavior or log anomalies, rather than stopping exploitation. Corrective controls are wrong because they respond after a failure or incident, such as restoring a compromised host or removing malware, while the vulnerability may still exist. Compensating controls are wrong because they provide an alternative safeguard when a primary control cannot be applied, such as isolating an unpatchable system, not the direct act of patching. Exam caveat: if the question emphasizes reducing chance of exploitation, select preventive even when remediation language appears. Operational check: compare the vulnerability inventory with patch deployment reports and track mean time to patch for known exploitable vulnerabilities.