Courseiva
Access Controls Concepts →mediumMultiple Select

ISC2 CC Access Controls Concepts Practice Question

A data center manager wants to strengthen physical access control at the main entrance while keeping the process practical for employees arriving each morning. Which two measures BEST align with sound physical access control practices? (Choose two.)

⚠ Common exam trap

The trap here is accepting signage or convenience shortcuts as equivalent to actual access enforcement mechanisms.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Require employees to display a visible badge at all times while inside the facility.

Effective physical access control combines preventive enforcement with accountability. A mantrap ensures each entrant authenticates individually, eliminating tailgating, while mandatory visible badges let anyone on site verify that a person is authorized. Together they admit legitimate employees efficiently while making unauthorized entry difficult to conceal, which is exactly what a well-designed entrance control should achieve.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Place a sign on the door stating that the area is restricted to authorized personnel only.

    Why it's wrong here

    A warning sign is a deterrent at best and provides no actual enforcement or verification of identity. Anyone can walk past a sign, and it generates no record of entry. While signage is a reasonable supporting element, it does not control access and cannot substitute for authentication mechanisms such as a mantrap or badge requirement.

  • ✗

    Disable the door alarm and logging functions to speed up employee entry during peak hours.

    Why it's wrong here

    Alarms and logs are detective controls that reveal forced entry attempts and record who entered and when. Disabling them to reduce delays removes the ability to detect and investigate incidents, undermining the entire control environment. Convenience never justifies eliminating detection and audit capability at a sensitive entrance.

  • ✓

    Require employees to display a visible badge at all times while inside the facility.

    Why this is correct

    Visible badges let staff and security personnel quickly distinguish authorized individuals from visitors or intruders, which reinforces the effectiveness of the entrance control. Badge display supports accountability and makes unauthorized presence easier to challenge. It is a widely accepted physical control that complements authentication at the door without impeding normal employee movement.

  • ✓

    Install a mantrap that admits one authenticated person at a time between two interlocking doors.

    Why this is correct

    A mantrap uses two doors that cannot open simultaneously, so each person must authenticate and be admitted individually before the next door releases. This prevents tailgating and piggybacking, where unauthorized individuals follow an employee through a single door. It directly strengthens entrance control while still allowing normal authenticated entry, making it a sound physical control.

  • ✗

    Publish the entrance door code on the company intranet so employees can memorize it.

    Why it's wrong here

    Sharing a door code broadly destroys its value as a credential because anyone with intranet access, including compromised accounts, can obtain it. Codes also cannot identify who entered, eliminating accountability. This practice weakens physical access control rather than strengthening it, and it conflicts with the goal of admitting only authenticated individuals.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.