A security administrator is implementing controls to protect a server room. Which TWO physical security layers should be included as part of a defense-in-depth strategy? (Select TWO.)
Perimeter fencing establishes the outermost physical boundary, deterring and delaying intruders before they reach the building housing the server room. It forms the first layer of a defence-in-depth strategy, complementing interior controls such as locks and cameras.
Why this answer
Fencing around the building (A) is a valid physical security layer because it establishes the outermost perimeter control, deterring and delaying unauthorized access before an attacker can reach the facility itself. A biometric reader on the server room door (E) is also correct because it enforces an authentication-based access control at the innermost physical layer, ensuring only authorized personnel can enter the room housing the servers. Together these represent defense-in-depth at the perimeter and at the asset boundary.
The remaining options are logical/technical controls rather than physical layers: a complex password policy (B) governs authentication credentials, cable locks on individual servers (C) are a device-level physical tether but not a room/building security layer in this context, and session timeout settings (D) are logical access controls that terminate idle sessions.
Exam trap
The trap here is confusing logical security controls (passwords, session timeouts) with physical security layers, and overlooking that cable locks, while physical, are not a primary layer for server room protection.