Courseiva

CISA Protection of Information Assets Practice Question

An IS auditor is reviewing physical security controls at a data center. The data center hosts critical servers and uses a badge access system with PINs, CCTV cameras, and a mantrap entry. The auditor observes that employees sometimes hold the door open for others without badging. Which TWO of the following are the MOST effective controls to address this tailgating risk?

⚠ Common exam trap

CISA often tests the difference between preventive and detective controls, and candidates may choose CCTV or PIN complexity as solutions, overlooking that tailgating is best mitigated by physical barriers and employee awareness.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conducting security awareness training on tailgating risks

Option A is correct because security awareness training directly targets the human behavior observed—employees deliberately holding the door for unbadged individuals—by educating staff on tailgating risks and reinforcing the policy that every person must badge individually, which is the root cause of the failure. Option E is correct because upgrading the existing mantrap to biometric authentication enforces one-person-at-a-time entry tied to an immutable physical characteristic, making it technically infeasible to piggyback through on another person's credentials and providing a preventive rather than detective control. Option B does not belong because longer or more complex PINs only strengthen the credential itself and do nothing to stop an unauthorized person from walking through a door held open by an authenticated employee. Option C does not belong because adding access points increases the number of entry portals and thus potentially widens the attack surface rather than preventing piggybacking. Option D does not belong because additional CCTV cameras are a detective control that only records the tailgating after the fact and does not prevent unauthorized entry.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Conducting security awareness training on tailgating risks

    Why this is correct

    Training addresses the human behaviour the auditor observed: staff deliberately holding doors for unbadged individuals. It reinforces badge discipline and challenges social-engineering pretexts, directly reducing tailgating attempts. It complements, rather than replaces, the physical mantrap control.

  • ✗

    Requiring longer and more complex PINs

    Why it's wrong here

    Longer, complex PINs strengthen authentication of the person badging, but tailgating bypasses badging entirely, so credential strength is irrelevant. It is tempting because PIN complexity defends against guessing and credential theft, making it correct when the risk is compromised or weak individual credentials.

  • ✗

    Installing additional access points

    Why it's wrong here

    More access points multiply the doors requiring badge control, giving tailgaters extra opportunities and diluting supervision. It is tempting because additional entry points improve traffic flow and convenience, making it correct when the requirement is accommodating higher personnel volume, not tightening entry control.

  • ✗

    Increasing the number of CCTV cameras

    Why it's wrong here

    Additional cameras only record tailgating after it occurs, providing detective evidence rather than preventing unauthorised entry. It is tempting because CCTV supports investigations and deterrence, so it would be the right choice when the objective is monitoring or forensic reconstruction rather than stopping the tailgating event itself.

  • ✓

    Implementing a mantrap with biometric authentication

    Why this is correct

    A mantrap with biometric authentication enforces single-person entry, so a held door cannot admit an unbadged individual. Biometrics removes shared-PIN and badge-passback weaknesses, physically preventing tailgating at the entry point rather than relying on user compliance.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.