mediumMultiple Choice
220-1102 Practice Question: A retail store wants to protect its point-of-sale…
A retail store wants to protect its point-of-sale (POS) terminals from unauthorized physical access during off-hours. The terminals are in an open area with no lockable cabinets. Which control should be prioritized?
⚠ Common exam trap
Many exam-takers confuse logical access controls (smart cards, screensavers, privacy screens) with physical security controls — candidates must recognize that the scenario specifically asks about unauthorized physical access, which only tamper-evident seals address.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use tamper-evident seals on the terminal casings.
Tamper-evident seals on POS terminal casings are the most appropriate control because they provide a physical indication if someone has opened or accessed the terminal's internal components during off-hours. Since the terminals are in an open area with no lockable cabinets, seals offer a low-cost, immediately deployable deterrent and detection mechanism. They alert staff the next morning if tampering occurred, enabling investigation and preventing skimming attacks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Install a privacy screen on each POS terminal.
Why it's wrong here
Installing a privacy screen on a POS terminal is a visual security measure designed to prevent "shoulder surfing" or unauthorized viewing of sensitive information displayed on the screen. However, it offers no protection against physical tampering with the device itself. A privacy screen does not deter or detect attempts to open the terminal casing, access internal components, or connect unauthorized devices to its ports, which are common methods of physical compromise.
- ✓
Use tamper-evident seals on the terminal casings.
Why this is correct
Tamper-evident seals are physical security devices designed to provide a clear visual indication if a device's casing has been opened or manipulated. These seals typically break, tear, or display a "void" message upon removal, immediately alerting staff to potential unauthorized physical access. This proactive detection mechanism allows for timely investigation and mitigation of risks associated with internal hardware modifications or the installation of skimming devices, directly addressing the need to protect against physical tampering.
- ✗
Require a smart card to power on the terminal.
Why it's wrong here
Requiring a smart card to power on a POS terminal is a strong logical access control, ensuring that only authorized personnel can boot and operate the system. While it prevents unauthorized users from accessing the operating system or applications, it does not provide any physical security for the hardware itself. An attacker could still physically open the terminal, access internal components, or connect malicious devices to external ports without ever powering on the system or needing the smart card.
- ✗
Enable a screensaver with a password.
Why it's wrong here
Enabling a screensaver with a password is a logical security control intended to protect an active user session from unauthorized access when the terminal is left unattended. It locks the software interface, requiring re-authentication to resume work. However, this measure provides no physical protection for the POS hardware. It does not prevent an attacker from physically manipulating the device, accessing its ports, or opening the casing to install unauthorized hardware or modify internal components.
Go deeper
Related to this question
Learn chapter
Physical Security: Locks, Cameras, Access Badges
Key term
Alert
An alert is a notification that something unusual or potentially harmful has happened in a computer system or network.
Key term
Terminal
A terminal is a text-based interface that allows users to communicate with a computer's operating system by typing commands.
About these practice questions
This 220-1202 question is part of Courseiva's 687-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.