ISC2 CC Access Controls Concepts Practice Question
An organization wants to implement defense in depth for its server room. Which THREE controls should be included?
⚠ Common exam trap
CC often tests the distinction between physical, administrative, and technical controls — candidates pick GPO or visitor logs because they sound security-relevant, but the question scopes to the server room, so only physical controls qualify.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cable locks on all servers
A is correct because cable locks are a physical (environmental) control that deters and prevents theft or removal of server hardware, directly supporting defense in depth at the server-room layer. D is correct because CCTV monitoring provides detective and deterrent physical security, recording activity inside the server room so incidents can be identified and investigated. E is correct because biometric access control on the server room door enforces strong, identity-based physical access control (something you are), restricting entry to authorized personnel. B does not belong because Group Policy password complexity is a logical/technical control for user authentication, not a server-room physical control. C does not belong because a visitor sign-in log at the front desk is an administrative control for the building entrance, not a control protecting the server room itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Cable locks on all servers
Why this is correct
Physical tamper protection for the servers themselves, satisfying the defense-in-depth requirement for layered physical safeguards. Cable locks deter and delay removal or theft of server hardware, complementing perimeter, door and surveillance controls rather than duplicating them.
- ✗
Group Policy to enforce password complexity
Why it's wrong here
Group Policy password complexity is a logical control applied to user accounts in the directory, not a control protecting the server room's physical space. It would be correct when hardening domain authentication, but the scenario requires physical controls such as locks, badges and cameras.
- ✗
Visitor sign-in log at the front desk
Why it's wrong here
A visitor sign-in log records people entering the building, not the server room itself, so it provides no control over physical access to the servers. It is tempting because visitor logging is a genuine administrative control for reception areas, and would be correct where the requirement is tracking building entrants rather than restricting server-room entry.
- ✓
CCTV monitoring inside the server room
Why this is correct
Provides continuous detective monitoring of activity inside the server room, satisfying defense in depth through a layer distinct from preventive door controls. Recorded footage supports incident investigation and deters insider tampering that access control alone cannot address.
- ✓
Biometric access control on the server room door
Why this is correct
Restricts server room entry to verified individuals, satisfying the defense-in-depth requirement for a preventive physical access layer. Biometrics authenticate something inherent to the person, unlike badges or PINs, which can be shared, lost or stolen.
Go deeper
Related to this question
Learn chapter
Authentication and Authorization Methods
Key term
Physical control
Physical controls are tangible security measures like locks, fences, and biometric scanners used to protect buildings, hardware, and sensitive data from unauthorized physical access or harm.
Key term
Technical control
A technical control is a security mechanism implemented through hardware, software, or firmware that protects the confidentiality, integrity, and availability of IT systems and data.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.