Courseiva
Access Controls Concepts →hardMultiple Select

ISC2 CC Access Controls Concepts Practice Question

An organization wants to implement defense in depth for its server room. Which THREE controls should be included?

⚠ Common exam trap

CC often tests the distinction between physical, administrative, and technical controls — candidates pick GPO or visitor logs because they sound security-relevant, but the question scopes to the server room, so only physical controls qualify.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cable locks on all servers

A is correct because cable locks are a physical (environmental) control that deters and prevents theft or removal of server hardware, directly supporting defense in depth at the server-room layer. D is correct because CCTV monitoring provides detective and deterrent physical security, recording activity inside the server room so incidents can be identified and investigated. E is correct because biometric access control on the server room door enforces strong, identity-based physical access control (something you are), restricting entry to authorized personnel. B does not belong because Group Policy password complexity is a logical/technical control for user authentication, not a server-room physical control. C does not belong because a visitor sign-in log at the front desk is an administrative control for the building entrance, not a control protecting the server room itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Cable locks on all servers

    Why this is correct

    Physical tamper protection for the servers themselves, satisfying the defense-in-depth requirement for layered physical safeguards. Cable locks deter and delay removal or theft of server hardware, complementing perimeter, door and surveillance controls rather than duplicating them.

  • ✗

    Group Policy to enforce password complexity

    Why it's wrong here

    Group Policy password complexity is a logical control applied to user accounts in the directory, not a control protecting the server room's physical space. It would be correct when hardening domain authentication, but the scenario requires physical controls such as locks, badges and cameras.

  • ✗

    Visitor sign-in log at the front desk

    Why it's wrong here

    A visitor sign-in log records people entering the building, not the server room itself, so it provides no control over physical access to the servers. It is tempting because visitor logging is a genuine administrative control for reception areas, and would be correct where the requirement is tracking building entrants rather than restricting server-room entry.

  • ✓

    CCTV monitoring inside the server room

    Why this is correct

    Provides continuous detective monitoring of activity inside the server room, satisfying defense in depth through a layer distinct from preventive door controls. Recorded footage supports incident investigation and deters insider tampering that access control alone cannot address.

  • ✓

    Biometric access control on the server room door

    Why this is correct

    Restricts server room entry to verified individuals, satisfying the defense-in-depth requirement for a preventive physical access layer. Biometrics authenticate something inherent to the person, unlike badges or PINs, which can be shared, lost or stolen.

Go deeper

Related to this question

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.