Correct Answer: Preventive controls such as restrictive CSS and FAC reduce the initial attack surface, but configuration drift, newly compromised credentials, or unforeseen gaps can still create exposure over time, so ongoing CDR review and monitoring are needed to catch fraud that preventive controls did not stop
Explanation: Preventive controls reduce the attack surface but cannot address configuration drift or unforeseen gaps, so ongoing monitoring catches what prevention misses, unlike treating the two as identical, claiming prevention alone guarantees zero fraud, claiming monitoring alone guarantees zero fraud, claiming risk is eliminated permanently at first configuration, or denying monitoring's value once controls exist.
Correct Answer: Preventive controls such as restrictive CSS and FAC reduce the initial attack surface, but configuration drift, newly compromised credentials, or unforeseen gaps can still create exposure over time, so ongoing CDR review and monitoring are needed to catch fraud that preventive controls did not stop
Explanation: Preventive controls reduce the attack surface but cannot address configuration drift or unforeseen gaps, so ongoing monitoring catches what prevention misses, unlike treating the two as identical, claiming prevention alone guarantees zero fraud, claiming monitoring alone guarantees zero fraud, claiming risk is eliminated permanently at first configuration, or denying monitoring's value once controls exist.