hardMultiple Choice
220-1102 Practice Question: A data center manager wants to implement a…
A data center manager wants to implement a physical security control that can detect if a server chassis has been opened without authorization. Which control should they use?
⚠ Common exam trap
The trap here is that candidates might consider tamper-evident seals (which provide visual evidence after the fact) but overlook the more active and often integrated electronic detection provided by a chassis intrusion switch, which is a direct physical security control designed for immediate detection of chassis opening.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Chassis intrusion switch
A chassis intrusion switch is a physical security control, typically a microswitch inside the server chassis, that detects when the chassis cover is opened. Upon detection, it can trigger an alert, log an event in the system's management controller (like IPMI or BMC), or prevent the system from booting. This provides an immediate and active detection mechanism for unauthorized access. While tamper-evident seals provide visual evidence of tampering, a chassis intrusion switch offers a more direct and often automated method of detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Intrusion detection system (IDS) on the network
Why it's wrong here
An Intrusion Detection System (IDS) is a logical security control primarily designed to monitor network traffic for malicious activity, policy violations, or anomalous patterns. It operates by analyzing packet headers and payloads, looking for known attack signatures or deviations from baseline behavior. However, an IDS functions exclusively within the network domain and possesses no capability to detect physical tampering with server chassis or other hardware components, making it ineffective for identifying a physical breach.
- ✓
Chassis intrusion switch
Why this is correct
A chassis intrusion switch can detect when the case is opened, but it requires a connection to the motherboard and may be bypassed if the system is off; tamper-evident seals are more reliable for detection.
- ✗
Tamper-evident seals
Why it's wrong here
Tamper-evident seals are physical security devices specifically engineered to provide clear, undeniable evidence of unauthorized access to equipment. These seals are strategically placed across chassis seams, screw heads, or access panels. Any attempt to open the case or access internal components will visibly break, distort, or leave a residue from the seal, immediately indicating that a physical breach has occurred. They serve as a highly effective detective control for physical security.
- ✗
Video surveillance
Why it's wrong here
Video surveillance systems utilize cameras to record activities within a data center environment, providing a visual log that is invaluable for auditing and post-incident investigation. While cameras can capture footage of someone opening a server, they do not inherently *detect* the act of a chassis opening in real-time or automatically trigger an alert based on this specific event. Such systems typically require constant, active human monitoring or sophisticated video analytics to identify and flag such an occurrence, making them an indirect rather than a direct detection mechanism for chassis tampering.
Go deeper
Related to this question
Learn chapter
Data Destruction and Disposal
Key term
Alert
An alert is a notification that something unusual or potentially harmful has happened in a computer system or network.
Key term
Authorization
Authorization determines what an authenticated user is allowed to do within a system, such as accessing files, running programs, or changing settings.
About these practice questions
Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.