ISC2 CC Access Controls Concepts Practice Question
A security analyst is reviewing physical security controls. Which TWO are considered layered physical security measures for external perimeter protection?
⚠ Common exam trap
CC often tests whether candidates can distinguish between external perimeter controls and internal or endpoint controls, so the trap is selecting an internal control (like biometric readers) as an external perimeter measure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Fencing around the property
Fencing around the property (A) is a correct answer because it is a perimeter-layer physical control that establishes a physical boundary and delays or deters intruders before they reach the facility. Lighting in parking lots (B) is also correct because exterior lighting is a classic layered perimeter control that deters intruders, removes concealment, and supports CCTV or guard surveillance. Together, fencing and lighting represent complementary external perimeter defenses that support defense in depth. The unmarked options do not belong because a biometric reader on a server room door (C) is an interior access control for a specific high-security room, not an external perimeter measure, while cable locks on laptops (D) and chassis locks on servers (E) are asset-level physical controls that protect individual devices rather than the external perimeter.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Fencing around the property
Why this is correct
Fencing establishes a physical barrier at the property boundary, delaying or deterring intruders before they reach the building. It satisfies the external perimeter constraint by providing the outermost layer of physical protection, which lighting and interior controls then reinforce.
- ✓
Lighting in parking lots
Why this is correct
Parking lot lighting removes concealment and increases the chance of observation, deterring intruders approaching the facility. It satisfies the external perimeter constraint as a layered measure complementing fencing, extending detection and deterrence beyond the building itself.
- ✗
Biometric reader on server room door
Why it's wrong here
A biometric reader on a server room door is an internal, logical-or-physical authentication control at a single point, not a layered external perimeter measure. It is tempting because biometrics strengthen access control, but external perimeter layering uses bollards, lighting, fences and guards.
- ✗
Cable locks on laptops
Why it's wrong here
Cable locks secure individual portable devices to a fixed point, so they protect assets already inside a facility rather than forming an external perimeter layer. They are tempting because they do deter opportunistic theft of laptops in shared or public spaces, which is a genuine physical control, but not perimeter protection.
- ✗
Chassis locks on servers
Why it's wrong here
Chassis locks prevent removal of a server's internal components or cover, protecting hardware within a secured room rather than the external perimeter. They are tempting because they are a legitimate physical control against component theft in data centres, but they operate inside the perimeter, not as a layered external measure.
Go deeper
Related to this question
Learn chapter
Physical Access Controls
Key term
Defense in depth
Defense in depth is a cybersecurity strategy that uses multiple layers of security controls to protect information and systems, so if one layer fails, another layer is already in place to stop the attack.
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.