ISC2 CC Access Controls Concepts Practice Question
Which TWO are examples of logical access controls? (Select TWO.)
⚠ Common exam trap
CC often tests the confusion between physical and logical controls by including biometrics, which can be either depending on context — the trap is assuming biometrics is always logical when the scenario describes a door lock.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Password complexity requirements
Password complexity requirements (B) are a logical access control because they are enforced in software by the operating system or directory service (e.g., via Group Policy password policy or /etc/security/pwquality.conf) to govern how a user authenticates, not to physically restrict movement. Account lockout policy (E) is likewise logical: it is a software-enforced setting that disables an account after a defined number of failed logon attempts within a set window, mitigating brute-force attacks against the authentication process. Both operate on the logical layer of identity and authentication rather than on physical barriers. By contrast, fencing around the property (A), a guard at the building entrance (C), and a biometric door lock (D) are physical access controls, since they restrict who can physically enter a location or structure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Fencing around the property
Why it's wrong here
Fencing is a physical access control, restricting bodily entry to a perimeter, whereas logical controls govern access to systems and data. It is tempting because perimeter security often underpins logical controls, but fencing satisfies no authentication, authorisation or auditing requirement that logical access demands.
- ✓
Password complexity requirements
Why this is correct
Password complexity requirements are a logical access control because they govern authentication through software-enforced rules on the credential itself, restricting who can gain system access. No physical barrier is involved, satisfying the question's requirement for a logical, rather than physical, control.
- ✗
Guard at building entrance
Why it's wrong here
A guard is a physical control, verifying people at a location rather than mediating system or data access. It is tempting because guards perform identification and authorisation checks, but those checks apply to physical entry; logical controls operate through credentials, permissions and audit logs within IT systems.
- ✗
Biometric door lock
Why it's wrong here
A biometric door lock is physical: it authenticates a body to open a barrier, not a subject to a system resource. It is tempting because biometrics also appear in logical authentication, but the door lock's mechanism controls physical entry, so it is not a logical access control.
- ✓
Account lockout policy
Why this is correct
An account lockout policy is a logical access control: it is enforced by the authentication system, temporarily disabling an account after repeated failed logins to defeat brute-force guessing. This restricts access through software logic rather than physical means, matching the question's logical-control criterion.
Go deeper
Related to this question
Learn chapter
Authentication and Authorization Methods
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
Group
A group is a collection of users, devices, or other objects that are assigned permissions and policies together for simplified management in identity and governance systems like Microsoft Entra ID.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.