CISSP Security Architecture and Engineering Practice Question
A security architect is evaluating physical security controls for a facility handling sensitive data. Which of the following are examples of layered physical security controls? (Choose THREE)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Perimeter fence
Layered security uses multiple barriers: perimeter (fence), external (lighting), building (locks), secure area (mantrap), and IT area (cage). Biometrics and guards are also layers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Perimeter fence
Why this is correct
A perimeter fence serves as a foundational deterrent and delay mechanism, establishing the outermost boundary of a secured area. It acts as a primary physical control, designed to discourage unauthorized entry and provide early detection of intrusion attempts by forcing an attacker to spend time breaching it. This initial barrier is crucial for defining the property line and channeling legitimate access through controlled entry points.
- ✓
Server rack locks
Why this is correct
Server rack locks are an essential physical control for securing critical IT assets within a data center or server room. These locks prevent unauthorized individuals from gaining direct physical access to servers, network devices, and storage arrays, thereby mitigating risks of data theft, tampering, or denial-of-service attacks through physical manipulation. They represent a granular layer of protection, even within an already secured IT environment.
- ✓
Mantrap at the entrance to the secure area
Why this is correct
A mantrap is a sophisticated physical access control system consisting of two interlocking doors, designed to permit only one person to enter a secure area at a time. It prevents "tailgating" or "piggybacking" by requiring authentication at both doors, effectively isolating individuals between entry points until their identity and authorization are verified. This robust control significantly enhances security for highly sensitive zones by ensuring strict one-to-one access.
- ✗
Single-factor authentication for all doors
Why it's wrong here
Single-factor authentication, such as a simple key card or PIN, provides only one layer of verification for physical access, making it inherently less secure. This approach is vulnerable to compromise if the single factor is lost, stolen, or easily guessed, failing to meet the robust requirements of a layered security strategy. A security architect would typically advocate for multi-factor authentication (e.g., card + PIN + biometric) to enhance the strength of access controls for critical areas.
- ✗
Unsecured windows on ground floor
Why it's wrong here
Unsecured windows on the ground floor represent a significant physical security vulnerability, offering an easy point of entry for unauthorized individuals rather than a control. Such windows bypass other security measures, providing direct access to the interior of a facility without requiring the attacker to breach more robust defenses like doors or fences. A security architect would identify this as a critical weakness requiring remediation, not a protective measure.
Go deeper
Related to this question
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.