CISA Protection of Information Assets Practice Question
An IS auditor is reviewing physical security controls at a data center. The data center hosts critical servers and uses a badge access system with PINs, CCTV cameras, and a mantrap entry. The auditor observes that employees sometimes hold the door open for others without badging. Which TWO of the following are the MOST effective controls to address this tailgating risk?
⚠ Common exam trap
CISA often tests the difference between preventive and detective controls, and candidates may choose CCTV or PIN complexity as solutions, overlooking that tailgating is best mitigated by physical barriers and employee awareness.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conducting security awareness training on tailgating risks
Option A is correct because security awareness training directly targets the human behavior observed—employees deliberately holding the door for unbadged individuals—by educating staff on tailgating risks and reinforcing the policy that every person must badge individually, which is the root cause of the failure. Option E is correct because upgrading the existing mantrap to biometric authentication enforces one-person-at-a-time entry tied to an immutable physical characteristic, making it technically infeasible to piggyback through on another person's credentials and providing a preventive rather than detective control. Option B does not belong because longer or more complex PINs only strengthen the credential itself and do nothing to stop an unauthorized person from walking through a door held open by an authenticated employee. Option C does not belong because adding access points increases the number of entry portals and thus potentially widens the attack surface rather than preventing piggybacking. Option D does not belong because additional CCTV cameras are a detective control that only records the tailgating after the fact and does not prevent unauthorized entry.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conducting security awareness training on tailgating risks
Why this is correct
Training addresses the human behaviour the auditor observed: staff deliberately holding doors for unbadged individuals. It reinforces badge discipline and challenges social-engineering pretexts, directly reducing tailgating attempts. It complements, rather than replaces, the physical mantrap control.
- ✗
Requiring longer and more complex PINs
Why it's wrong here
Longer, complex PINs strengthen authentication of the person badging, but tailgating bypasses badging entirely, so credential strength is irrelevant. It is tempting because PIN complexity defends against guessing and credential theft, making it correct when the risk is compromised or weak individual credentials.
- ✗
Installing additional access points
Why it's wrong here
More access points multiply the doors requiring badge control, giving tailgaters extra opportunities and diluting supervision. It is tempting because additional entry points improve traffic flow and convenience, making it correct when the requirement is accommodating higher personnel volume, not tightening entry control.
- ✗
Increasing the number of CCTV cameras
Why it's wrong here
Additional cameras only record tailgating after it occurs, providing detective evidence rather than preventing unauthorised entry. It is tempting because CCTV supports investigations and deterrence, so it would be the right choice when the objective is monitoring or forensic reconstruction rather than stopping the tailgating event itself.
- ✓
Implementing a mantrap with biometric authentication
Why this is correct
A mantrap with biometric authentication enforces single-person entry, so a held door cannot admit an unbadged individual. Biometrics removes shared-PIN and badge-passback weaknesses, physically preventing tailgating at the entry point rather than relying on user compliance.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.