ISC2 CC Access Controls Concepts Practice Question
A retail company is reviewing physical access controls at its data center. Management wants to document measures that restrict who can enter the server hall and record when entries occur. Which TWO of the following are physical access controls that meet these goals? (Choose two.)
⚠ Common exam trap
The trap here is counting any physical safeguard, such as a locked cabinet or privacy filter, as an entry control even though it does not restrict or log who enters the server hall.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A mantrap with interlocking doors that admits one authenticated person at a time into the server hall.
Physical access controls govern movement into protected spaces and often produce an audit trail. A badge reader authenticates the person and logs the entry, while a mantrap enforces one-person-at-a-time passage and prevents tailgating. Together they restrict who reaches the servers and create records of when entry occurred. Firewalls, locked media cabinets, and monitor privacy filters protect other assets or confidentiality but do not control doorway access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A firewall rule that blocks inbound traffic to the server subnet from the corporate network.
Why it's wrong here
A firewall rule is a logical access control that filters network traffic; it does not govern who may physically walk into the server hall. Management specifically asked about restricting entry to the room and recording entries, which a network rule cannot do. This is a plausible distractor because firewalls also restrict access, but the control type and the target are different.
- ✗
A locked cabinet that houses backup tapes and requires a key held by the storage administrator.
Why it's wrong here
Locking a cabinet protects the media stored inside, which is a valid physical safeguard, but it does not control or log entry to the server hall itself. The scenario asks for measures that restrict who enters the room and record when entries occur, and a media cabinet does neither for the doorway. It is a physical control applied to a different asset.
- ✓
A mantrap with interlocking doors that admits one authenticated person at a time into the server hall.
Why this is correct
A mantrap uses two sets of doors with interlocking controls so that only one authenticated individual can pass at a time, preventing tailgating into the server hall. Combined with authentication, it restricts who enters and can be integrated with logging. This directly addresses the goal of controlling physical entry to the protected space.
- ✓
A badge reader at the server hall door that logs the identity and timestamp of each entry.
Why this is correct
A badge reader authenticates the person presenting a credential and grants or denies entry, and it records who entered and when. That directly satisfies both the restriction and the logging goals stated by management. It is a classic physical access control because it governs movement through a doorway rather than logical access to data or systems.
- ✗
A privacy filter applied to the administrator's monitor so bystanders cannot read displayed data.
Why it's wrong here
A privacy filter limits visual eavesdropping on a screen, which protects confidentiality of displayed information but does not restrict or record entry to the server hall. It addresses shoulder surfing rather than doorway access. Although it is a useful physical safeguard, it does not satisfy management's stated goals of controlling and logging room entry.
Go deeper
Related to this question
Learn chapter
Access Control Fundamentals
Key term
Privacy
Privacy in IT is the control over how personal data is collected, stored, used, and shared by systems and organizations.
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.