A SOC analyst confirms a critical privilege-escalation vulnerability on a file server. After a risk assessment, administrators apply the vendor patch, restart the service, and validate that the vulnerable code path no longer executes. Which control type best describes this action?
Select an answer to reveal the explanation.
Short Explanation
Think of it like fixing a hole after the alarm has already gone off: the patch is corrective, not just detective. You first saw the issue, then you repaired it and checked that the risk went away. If you were only blocking future attempts, that would be preventive.
Full Explanation
Remediation that follows a confirmed vulnerability finding is corrective because it acts on an identified weakness to restore a safer configuration and reduce residual risk. Patching, configuration hardening, or service restoration after a scan or alert are corrective responses: the control is triggered by a discovered issue and aims to repair it rather than merely observe or prevent future occurrences. A preventive control would be applied before an incident to stop a class of actions, such as disabling an unused protocol or enforcing patch deployment policy, so waiting for a confirmed finding makes it corrective. A detective control only identifies or records conditions, such as scanning, logging, or alerting, and does not itself change the vulnerable state. A compensating control provides alternative protection when the preferred remediation cannot be implemented, such as isolating a legacy host or adding a WAF rule, whereas the scenario says the actual patch was applied. Exam caveat: classify by timing and purpose, not by tool name, because scanners detect while remediation corrects. Operational check: after patching, rerun the scanner or validate the specific indicator to prove the vulnerable condition is gone.