hardMultiple Select
CISA Practice Question: Which TWO of the following are the MOST effective…
Which TWO of the following are the MOST effective controls to prevent unauthorized access to a data center's server room? (Choose two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mantrap entry
Mantrap entry (B) and biometric authentication (E) are the most effective preventive controls for unauthorized access to a server room. Mantraps prevent tailgating, and biometrics provide strong authentication. CCTV (C) is a detective control, visitor logbook (D) is an administrative control, and server rack locks (A) are secondary to room access controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Server rack locks
Why it's wrong here
Rack locks protect individual cabinets, not the room; an intruder who defeats the door still reaches cabling, power and network gear outside racks. It tempts because racks are the direct housing of servers, and rack locks would be appropriate as a secondary layer inside an already restricted room.
- ✓
Mantrap entry
Why this is correct
A mantrap enforces single-person, interlocked entry, so each individual is authenticated and visually verified before the inner door releases. This directly satisfies the stem's prevention constraint by physically blocking tailgating and piggybacking, the primary routes for unauthorised server room access.
- ✗
CCTV monitoring
Why it's wrong here
CCTV is detective, not preventive: cameras record an intrusion but do not deny a door, turnstile or lock. It tempts because continuous surveillance deters casual intruders and supports investigations, and would be the right control for monitoring an already access-controlled room or evidencing incidents.
- ✗
Visitor logbook
Why it's wrong here
A logbook records who entered after the fact; it neither authenticates identity nor physically stops tailgating, so it cannot prevent unauthorised entry. It tempts because it is cheap, auditable and satisfies documentation requirements, and would be a valid detective or compliance control once layered behind an actual access-control mechanism.
- ✓
Biometric authentication on door
Why this is correct
Biometric authentication verifies a unique physical characteristic, so credentials cannot be shared, copied or guessed. It enforces strict identity assurance at the server room door, directly preventing unauthorised entry by anyone lacking an enrolled biometric.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CISA
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO of the following are physical security controls to prevent unauthorized access to a data center?
medium- A.Uninterruptible power supply
- B.Cable locks
- ✓ C.Mantrap
- ✓ D.Biometric readers
- E.Fire suppression system
Why C: A mantrap (C) is a physical access control consisting of a small vestibule with two interlocking doors, where the first door must close and authenticate before the second opens, preventing tailgating and trapping intruders between zones, so it directly prevents unauthorized access to the data center. Biometric readers (D) are physical authentication controls that verify a unique human trait (fingerprint, iris, retina, or palm vein) before granting entry, making them a primary means of restricting data center access to authorized personnel. The uninterruptible power supply (A) and fire suppression system (E) are availability and life-safety controls that protect equipment from power loss and fire, not access controls, and cable locks (B) secure portable devices such as laptops rather than controlling entry to a facility.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.