セキュリティインシデントの影響を最小限に抑えるため、サイバーセキュリティアナリストは組織のクラウドサービスで監査設定を構成しました。アナリストが構成したセキュリティ制御は次のうちどれですか?
正解:D
Audit settings provide visibility into user actions and system events. These are classified as detective controls because they enable the detection of anomalies, policy violations, or unauthorized access by generating logs or alerts. They do not prevent actions (Preventive) or reverse harm (Corrective), nor do they provide policy guidance (Directive).