ISC2 CC Access Controls Concepts Practice Question
An organization wants to implement layered physical security for its data center. Which THREE of the following controls would be considered part of a defense-in-depth physical security strategy?
⚠ Common exam trap
Candidates often confuse logical/administrative controls (like passwords and logs) with physical controls; candidates often select password complexity because it sounds like security, but it does not address physical access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cable locks on laptop computers
Option A (cable locks on laptop computers) is correct because a cable lock is a physical deterrent that secures a portable asset to a fixed object, adding a layer of physical defense against theft. Option D (biometric reader at the server room door) is correct because it is a physical access control that authenticates identity via a biological characteristic before granting entry to a restricted area. Option E (fencing and bollards around the building) is correct because perimeter barriers such as fences and bollards are classic physical controls that deter, delay, and prevent unauthorized access or vehicle-borne threats. Option B (password complexity requirements) is not a physical control but a logical/administrative authentication control, and Option C (visitor sign-in log) is an administrative control that records entry rather than physically preventing or deterring access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Cable locks on laptop computers
Why this is correct
Cable locks physically tether laptops to a fixed anchor, preventing opportunistic theft of endpoint devices. This satisfies the layered strategy by extending physical protection beyond the data centre perimeter to the assets themselves, complementing door, fence and bollard controls.
- ✗
Password complexity requirements
Why it's wrong here
Password complexity governs logical authentication, not physical barriers such as fences, locks, or badge readers, so it adds no physical layer. It is tempting because it is a genuine defence-in-depth control, but at the administrative layer; it would be correct when hardening account credentials against brute-force or credential-stuffing attacks.
- ✗
Visitor sign-in log
Why it's wrong here
A visitor sign-in log records entries after someone has already passed the perimeter, so it provides no preventive physical barrier. It is tempting because it is a recognised physical security control; it would be correct as an administrative detective measure supporting accountability and audit trails for non-employees entering a facility.
- ✓
Biometric reader at the server room door
Why this is correct
A biometric reader authenticates a unique physical trait at the server room door, satisfying the layered strategy's requirement for a control at the innermost boundary. It prevents entry by anyone lacking an enrolled trait, even if they hold a stolen badge or key.
- ✓
Fencing and bollards around the building
Why this is correct
Fencing and bollards form the outermost physical layer, deterring and blocking vehicles and intruders before they reach the building. This satisfies the layered strategy by adding a perimeter control outside the data centre walls, ahead of door and room-level controls.
Go deeper
Related to this question
Learn chapter
Access Control Fundamentals
Key term
Administrative control
An administrative control is a policy, procedure, or guideline designed to manage and reduce security risk through people and processes rather than technology alone.
Key term
Physical control
Physical controls are tangible security measures like locks, fences, and biometric scanners used to protect buildings, hardware, and sensitive data from unauthorized physical access or harm.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.