Courseiva
easyMultiple Select

Physical Access Controls — Examples

Which two of the following are examples of physical access controls? (Select TWO)

Quick Answer

The answer is biometric door locks and security guards. Biometric door locks are a physical access control because they use unique biological traits, such as fingerprints or retinal scans, to verify identity before granting entry, directly preventing unauthorized physical access to a facility or server room. Security guards serve as a human barrier to unauthorized entry, monitoring and challenging individuals who attempt to access restricted areas, enforcing physical security policies through observation, verification, and intervention. On the ISC2 Certified in Cybersecurity CC exam, this question tests your ability to distinguish physical controls from logical or administrative controls; a common trap is mistaking a firewall or password policy for a physical control. Remember the memory tip: if you can touch it or it blocks a door, it’s physical—think “biometric badge and badge-wearing guard.”

⚠ Common exam trap

ISC2 often tests the distinction between physical, administrative, and logical/technical controls, and the trap here is that candidates confuse encryption or firewall rules as 'physical' because they are tangible in implementation, but they are actually logical controls that protect data, not physical assets or premises.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security guards

Security guards (A) are a physical access control because they are personnel who monitor and restrict entry to a facility, directly controlling who physically enters a protected area. Biometric door locks (E) are a physical access control because they use physiological traits such as fingerprints or retina patterns to authenticate a person and physically unlock a door. Encryption (B) is a logical/technical control that protects data confidentiality, not physical entry. Password policies (C) are administrative controls governing authentication credentials, not physical access. Firewall rules (D) are technical network controls that filter traffic, not physical access controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Security guards

    Why this is correct

    Security guards satisfy the physical access control requirement because they regulate entry to premises through direct human presence and intervention. Unlike logical controls such as passwords or Microsoft Entra ID authentication, guards physically verify identity and can deny or permit access at the perimeter, which is precisely the tangible, on-site enforcement the question demands.

  • ✗

    Encryption

    Why it's wrong here

    Encryption protects data confidentiality by transforming it into ciphertext, so it is a logical or cryptographic control, not a physical one. It is tempting because it controls who can read data, but it operates on the data itself. Physical controls include locks, fences and guards.

  • ✗

    Password policies

    Why it's wrong here

    Password policies are logical controls governing authentication, not physical controls restricting access to facilities or hardware. They are tempting because they do restrict access, but logically rather than physically. Password policies would be the correct choice when the question asks about logical or technical access controls.

  • ✗

    Firewall rules

    Why it's wrong here

    Firewall rules filter network traffic by IP address, port and protocol, so they are logical rather than physical controls. They are tempting because they do restrict access, but at the network layer. A physical control would be a locked door, turnstile or badge reader guarding a room.

  • ✓

    Biometric door locks

    Why this is correct

    Biometric door locks regulate entry to a facility by verifying a physiological trait before releasing the door, making them a physical access control. They satisfy the stem's requirement for a physical mechanism, unlike logical controls such as passwords or permissions that protect systems and data rather than premises.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CC

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO of the following are examples of physical access controls?

easy
  • A.Encryption
  • ✓ B.Biometric scanners
  • ✓ C.Smart cards
  • D.Intrusion Prevention Systems (IPS)
  • E.Firewalls

Why B: Biometric scanners (B) are physical access controls because they authenticate a person via a physical characteristic such as a fingerprint, iris, or retina before granting entry to a facility or device. Smart cards (C) are also physical access controls since they are tangible tokens used with a card reader to authenticate and unlock doors or restricted areas. Encryption (A) is a logical/technical control that protects data confidentiality, not physical entry. Intrusion Prevention Systems (D) and firewalls (E) are network-based technical controls that monitor or filter traffic, so they are not physical access controls.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.