SY0-701 General Security Concepts Practice Question
Exhibit
Lobby access review: - 09:14:02 badge swipe accepted for employee j.tan - 09:14:07 an unknown person entered immediately behind j.tan - 09:14:19 CCTV shows the person had no badge visible - 09:16:44 the person exited through the same lobby door Current controls: - Badge reader on main entrance - CCTV camera facing the lobby - Monthly security awareness reminder about badge use
Based on the exhibit, which additional control best reduces the risk of tailgating at the entrance while preserving normal employee flow?
⚠ Common exam trap
CompTIA often tests the distinction between preventive controls (mantraps/turnstiles) and detective or administrative controls (CCTV, emails, guards), leading candidates to choose a familiar but ineffective option like CCTV or security guards.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Install a mantrap or anti-passback turnstile that admits one person per badge authorization.
A mantrap or anti-passback turnstile enforces one-person-per-badge authorization, physically preventing tailgating by only allowing a single individual to pass per valid credential. This preserves normal employee flow because authorized users can enter quickly without manual intervention, unlike guards or awareness campaigns that rely on human compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Post a security guard at the entrance during business hours.
Why it's wrong here
A security guard at the entrance acts mainly as a deterrent and depends on the guard's attention and judgment during busy periods. Because tailgating can occur in a split second as employees stream through the door, a guard cannot reliably enforce one-person-per-badge authentication, and the ongoing labor cost for 24/7 coverage is high. This is a supplementary administrative/detective measure, not a physical control that structurally prevents two people entering on one credential.
- ✓
Install a mantrap or anti-passback turnstile that admits one person per badge authorization.
Why this is correct
This is the best fit because the current controls detect the problem but do not stop it. A mantrap or turnstile is a preventive physical control that enforces single-person entry and directly addresses tailgating while keeping normal employee movement efficient. It reduces reliance on people noticing and reacting in real time.
- ✗
Add more CCTV cameras in the lobby and at the parking lot entrance.
Why it's wrong here
Additional CCTV in the lobby and parking lot improves forensic visibility and may help identify a tailgater after an incident, but cameras are detective controls—they neither block nor alarm in real time to prevent unauthorized entry. Reviewing more footage adds workload without changing the physical entry process, and the parking lot entrance is upstream of the actual badge-controlled door. This option does not address the access-control weakness at the point of entry.
- ✗
Send quarterly emails reminding employees not to hold doors open.
Why it's wrong here
Quarterly security awareness emails are an administrative control that attempts to modify employee behavior, yet they do not constrain the physical environment in any way. Even if every employee remembered to avoid holding the door, a tailgater can enter on the employee's authorized access by impersonating an employee or following closely before the door closes. The exhibit indicates a repeated physical bypass, so the correct improvement must be a device that automates enforcement, not a communication that relies on human compliance.
Go deeper
Related to this question
Learn chapter
Access Control Models (DAC, MAC, RBAC)
Key term
General Data Protection Regulation
A European Union law that gives individuals control over their personal data and sets strict rules for how organizations collect, store, and process that data.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.