Courseiva
Access Controls Concepts →hardMultiple Select

ISC2 CC Access Controls Concepts Practice Question

An organization wants to implement layered physical security for its data center. Which THREE of the following controls would be considered part of a defense-in-depth physical security strategy?

⚠ Common exam trap

Candidates often confuse logical/administrative controls (like passwords and logs) with physical controls; candidates often select password complexity because it sounds like security, but it does not address physical access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cable locks on laptop computers

Option A (cable locks on laptop computers) is correct because a cable lock is a physical deterrent that secures a portable asset to a fixed object, adding a layer of physical defense against theft. Option D (biometric reader at the server room door) is correct because it is a physical access control that authenticates identity via a biological characteristic before granting entry to a restricted area. Option E (fencing and bollards around the building) is correct because perimeter barriers such as fences and bollards are classic physical controls that deter, delay, and prevent unauthorized access or vehicle-borne threats. Option B (password complexity requirements) is not a physical control but a logical/administrative authentication control, and Option C (visitor sign-in log) is an administrative control that records entry rather than physically preventing or deterring access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Cable locks on laptop computers

    Why this is correct

    Cable locks physically tether laptops to a fixed anchor, preventing opportunistic theft of endpoint devices. This satisfies the layered strategy by extending physical protection beyond the data centre perimeter to the assets themselves, complementing door, fence and bollard controls.

  • ✗

    Password complexity requirements

    Why it's wrong here

    Password complexity governs logical authentication, not physical barriers such as fences, locks, or badge readers, so it adds no physical layer. It is tempting because it is a genuine defence-in-depth control, but at the administrative layer; it would be correct when hardening account credentials against brute-force or credential-stuffing attacks.

  • ✗

    Visitor sign-in log

    Why it's wrong here

    A visitor sign-in log records entries after someone has already passed the perimeter, so it provides no preventive physical barrier. It is tempting because it is a recognised physical security control; it would be correct as an administrative detective measure supporting accountability and audit trails for non-employees entering a facility.

  • ✓

    Biometric reader at the server room door

    Why this is correct

    A biometric reader authenticates a unique physical trait at the server room door, satisfying the layered strategy's requirement for a control at the innermost boundary. It prevents entry by anyone lacking an enrolled trait, even if they hold a stolen badge or key.

  • ✓

    Fencing and bollards around the building

    Why this is correct

    Fencing and bollards form the outermost physical layer, deterring and blocking vehicles and intruders before they reach the building. This satisfies the layered strategy by adding a perimeter control outside the data centre walls, ahead of door and room-level controls.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.