pcgizzmo wrote: » Are the questions on the CISSP exam this ambiguous?
secben wrote: » IMO, it should be a corrective control. This is the official guides definitions of a corrective control: "Corrective controls are actions that seek to alter the security posture of an environment to correct any deficiencies and return the environment to a secure state" ... "They can range from “quick fix” changes like new firewall rules, router access control list updates, and access policy changes to more long-term infrastructure changes like the introduction of certificates for wireless 802.1x authentication, movement from single-factor to multifactor authentication, for remote access, or the introduction of smart cards for authentication." - Link: Official (ISC)2 Guide to the CISSP CBK, Second Edition - Harold F. Tipton - Google Books By implementing SSL, you correct an issue with non-compliant to the security policy. So it's the most suitable answer.Not sure if there's anything called "compensating control".