hardMultiple ChoiceObjective-mapped
220-1102 Practice Question: During a security audit, you find that a server…
During a security audit, you find that a server room door has a standard key lock, but the key is kept in an unlocked drawer nearby. Which physical security principle is being violated?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Defense in depth
The principle of defense in depth requires multiple layers of security. Storing the key in an unlocked drawer negates the door lock, creating a single point of failure. Proper key management is essential.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Least privilege
Why it's wrong here
Least privilege mandates that users and processes are granted only the minimum necessary access rights to perform their legitimate functions. In this scenario, the problem isn't about a user having excessive digital permissions on the server itself, but rather a physical security lapse where a key, which grants physical access, is poorly secured. Therefore, the principle of least privilege, which primarily concerns authorization levels, does not directly address the insecure storage of a physical access key.
- ✓
Defense in depth
Why this is correct
Defense in depth is a security strategy that employs multiple, overlapping security controls to protect assets. The physical lock on the server cabinet represents one layer of defense, but if the key to that lock is stored insecurely and easily accessible, this critical layer is effectively bypassed. This undermines the entire multi-layered security posture, as a single point of failure (the insecure key) compromises the protection intended by the physical barrier, demonstrating a failure in applying defense in depth.
- ✗
Separation of duties
Why it's wrong here
Separation of duties is an organizational control designed to prevent fraud, error, or malicious activity by distributing critical tasks among multiple individuals. This principle ensures that no single person has complete control over a process that could lead to a security breach or financial impropriety. The scenario, however, describes a physical security vulnerability related to key management, not a failure to divide responsibilities for administrative or operational tasks among different personnel.
- ✗
Change management
Why it's wrong here
Change management is a structured process used to control and document modifications to IT systems, infrastructure, or services, aiming to minimize risks and ensure system stability. Its purpose is to ensure that all changes are properly authorized, tested, and implemented without introducing new vulnerabilities or disruptions. The discovery of an insecurely stored key during an audit points to an existing security flaw in physical access control, not a failure in the process of managing planned system modifications.
Go deeper
Related to this question
Learn chapter
Windows Security Features
Key term
Defense in depth
Defense in depth is a cybersecurity strategy that uses multiple layers of security controls to protect information and systems, so if one layer fails, another layer is already in place to stop the attack.
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
About these practice questions
One of 495 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.