easyMultiple Select
Physical Access Controls — Examples
Which two of the following are examples of physical access controls? (Select TWO)
Quick Answer
The answer is biometric door locks and security guards. Biometric door locks are a physical access control because they use unique biological traits, such as fingerprints or retinal scans, to verify identity before granting entry, directly preventing unauthorized physical access to a facility or server room. Security guards serve as a human barrier to unauthorized entry, monitoring and challenging individuals who attempt to access restricted areas, enforcing physical security policies through observation, verification, and intervention. On the ISC2 Certified in Cybersecurity CC exam, this question tests your ability to distinguish physical controls from logical or administrative controls; a common trap is mistaking a firewall or password policy for a physical control. Remember the memory tip: if you can touch it or it blocks a door, it’s physical—think “biometric badge and badge-wearing guard.”
⚠ Common exam trap
ISC2 often tests the distinction between physical, administrative, and logical/technical controls, and the trap here is that candidates confuse encryption or firewall rules as 'physical' because they are tangible in implementation, but they are actually logical controls that protect data, not physical assets or premises.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security guards
Security guards (A) are a physical access control because they are personnel who monitor and restrict entry to a facility, directly controlling who physically enters a protected area. Biometric door locks (E) are a physical access control because they use physiological traits such as fingerprints or retina patterns to authenticate a person and physically unlock a door. Encryption (B) is a logical/technical control that protects data confidentiality, not physical entry. Password policies (C) are administrative controls governing authentication credentials, not physical access. Firewall rules (D) are technical network controls that filter traffic, not physical access controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Security guards
Why this is correct
Security guards satisfy the physical access control requirement because they regulate entry to premises through direct human presence and intervention. Unlike logical controls such as passwords or Microsoft Entra ID authentication, guards physically verify identity and can deny or permit access at the perimeter, which is precisely the tangible, on-site enforcement the question demands.
- ✗
Encryption
Why it's wrong here
Encryption protects data confidentiality by transforming it into ciphertext, so it is a logical or cryptographic control, not a physical one. It is tempting because it controls who can read data, but it operates on the data itself. Physical controls include locks, fences and guards.
- ✗
Password policies
Why it's wrong here
Password policies are logical controls governing authentication, not physical controls restricting access to facilities or hardware. They are tempting because they do restrict access, but logically rather than physically. Password policies would be the correct choice when the question asks about logical or technical access controls.
- ✗
Firewall rules
Why it's wrong here
Firewall rules filter network traffic by IP address, port and protocol, so they are logical rather than physical controls. They are tempting because they do restrict access, but at the network layer. A physical control would be a locked door, turnstile or badge reader guarding a room.
- ✓
Biometric door locks
Why this is correct
Biometric door locks regulate entry to a facility by verifying a physiological trait before releasing the door, making them a physical access control. They satisfy the stem's requirement for a physical mechanism, unlike logical controls such as passwords or permissions that protect systems and data rather than premises.
Go deeper
Related to this question
Learn chapter
Physical Access Controls
Key term
Technical control
A technical control is a security mechanism implemented through hardware, software, or firmware that protects the confidentiality, integrity, and availability of IT systems and data.
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CC
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO of the following are examples of physical access controls?
easy- A.Encryption
- ✓ B.Biometric scanners
- ✓ C.Smart cards
- D.Intrusion Prevention Systems (IPS)
- E.Firewalls
Why B: Biometric scanners (B) are physical access controls because they authenticate a person via a physical characteristic such as a fingerprint, iris, or retina before granting entry to a facility or device. Smart cards (C) are also physical access controls since they are tangible tokens used with a card reader to authenticate and unlock doors or restricted areas. Encryption (A) is a logical/technical control that protects data confidentiality, not physical entry. Intrusion Prevention Systems (D) and firewalls (E) are network-based technical controls that monitor or filter traffic, so they are not physical access controls.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.