ISC2 CC Access Controls Concepts Practice Question
A security engineer is designing a physical security plan. Which combination of controls best represents defense in depth for a data center?
⚠ Common exam trap
The trap is that candidates might choose a single strong control (like a high-tech lock) thinking it is sufficient, but defense in depth requires multiple, diverse layers; also, they might confuse logical controls with physical controls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Perimeter fencing, access badges at building entrance, biometric reader on server room, and cable locks on servers
Defense in depth involves implementing multiple layers of security controls so that if one layer fails, others still provide protection. The combination of perimeter fencing, access badges at the building entrance, biometric reader on the server room, and cable locks on servers represents multiple physical security layers, from the outer perimeter to the individual server level. This is a classic example of defense in depth.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Visitor sign-in and escort policy only
Why it's wrong here
Sign-in and escorting alone provide only administrative access control at the perimeter, omitting layered deterrents such as fences, locks, badges, cameras and alarms that defence in depth requires. It is tempting because visitor management is a genuine control, and would suffice where the requirement is solely tracking and accompanying non-employees.
- ✗
A single high-tech lock on the server room door
Why it's wrong here
One lock creates a single point of failure; defence in depth demands multiple independent layers so that defeating one control does not grant access. It is tempting because a high-tech lock is a legitimate physical control, and would be adequate where the requirement is protecting a single low-value room.
- ✗
A strong password policy for all employees
Why it's wrong here
A password policy is a logical, not physical, control, so it contributes nothing to the data centre's physical defence layers. It is tempting because strong authentication genuinely strengthens overall security, and would be the right answer if the question asked about logical access controls rather than physical ones.
- ✓
Perimeter fencing, access badges at building entrance, biometric reader on server room, and cable locks on servers
Why this is correct
Each layer compensates if an earlier one fails: fencing delays intrusion, badges filter entrants, biometrics restrict the server room, and cable locks stop physical theft. This satisfies the defence-in-depth requirement by combining deterrence, detection and delay across independent boundaries.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.