Courseiva
Access Controls Concepts →mediumMultiple Select

ISC2 CC Access Controls Concepts Practice Question

A security administrator is implementing controls to protect a server room. Which TWO physical security layers should be included as part of a defense-in-depth strategy? (Select TWO.)

⚠ Common exam trap

Many exam-takers confuse logical security controls (passwords, session timeouts) with physical security layers, and overlooking that cable locks, while physical, are not a primary layer for server room protection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Fencing around the building

Fencing around the building (A) is a valid physical security layer because it establishes the outermost perimeter control, deterring and delaying unauthorized access before an attacker can reach the facility itself. A biometric reader on the server room door (E) is also correct because it enforces an authentication-based access control at the innermost physical layer, ensuring only authorized personnel can enter the room housing the servers. Together these represent defense-in-depth at the perimeter and at the asset boundary. The remaining options are logical/technical controls rather than physical layers: a complex password policy (B) governs authentication credentials, cable locks on individual servers (C) are a device-level physical tether but not a room/building security layer in this context, and session timeout settings (D) are logical access controls that terminate idle sessions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Fencing around the building

    Why this is correct

    Perimeter fencing establishes the outermost physical boundary, deterring and delaying intruders before they reach the building housing the server room. It forms the first layer of a defence-in-depth strategy, complementing interior controls such as locks and cameras.

  • ✗

    Complex password policy

    Why it's wrong here

    A password policy is a logical control applied to user accounts; it cannot restrict movement into a server room, so it adds no physical layer. It is tempting because defence in depth does include authentication, and it would be correct if the question covered logical layers protecting the servers themselves.

  • ✗

    Cable locks on individual servers

    Why it's wrong here

    Cable locks secure individual server chassis against removal, but they sit inside the room and do nothing to control entry, so they are not a perimeter layer. They are tempting because they are genuinely physical, and they would be correct if the requirement were asset protection within an already secured room.

  • ✗

    Session timeout settings

    Why it's wrong here

    Session timeout settings are a logical control applied to authenticated sessions; they cannot prevent or detect physical intrusion into a server room. They are tempting because they are a recognised defence-in-depth measure, and they would be correct if the question asked about logical layers protecting server access.

  • ✓

    Biometric reader on server room door

    Why this is correct

    A biometric reader verifies a unique physical trait before granting entry, satisfying the requirement for a layered control at the server room door itself. It adds an authentication factor beyond a key or badge, so a stolen credential alone cannot breach the room.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.