CISSP Security Architecture and Engineering Practice Question
A security architect is evaluating physical security controls for a facility handling sensitive data. Which of the following are examples of layered physical security controls? (Choose THREE)
⚠ Common exam trap
CISSP often tests the distinction between actual layered controls and single points of failure or vulnerabilities, so candidates must recognize that unsecured windows and single-factor auth are weaknesses, not layers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Perimeter fence
The question asks for layered physical security controls, meaning multiple defensive measures at different depths. Option A, a perimeter fence, is correct because it establishes the outermost physical boundary and deters or delays unauthorized access before an intruder reaches the building. Option B, server rack locks, is correct because it provides an inner layer of protection directly at the asset, restricting access to the servers even after someone has entered the facility. Option C, a mantrap at the entrance to the secure area, is correct because it is a physical access control vestibule that allows only one person through at a time and prevents tailgating, adding a controlled transition layer between zones. Option D, single-factor authentication for all doors, is not a layered physical control; single-factor authentication is weak and does not add defense in depth, and authentication is more of an access control mechanism than a physical barrier. Option E, unsecured windows on the ground floor, is not a control at all but a vulnerability, since unlocked or unprotected windows provide an easy bypass of other physical defenses.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Perimeter fence
Why this is correct
A perimeter fence serves as a foundational deterrent and delay mechanism, establishing the outermost boundary of a secured area. It acts as a primary physical control, designed to discourage unauthorized entry and provide early detection of intrusion attempts by forcing an attacker to spend time breaching it. This initial barrier is crucial for defining the property line and channeling legitimate access through controlled entry points.
- ✓
Server rack locks
Why this is correct
Server rack locks are an essential physical control for securing critical IT assets within a data center or server room. These locks prevent unauthorized individuals from gaining direct physical access to servers, network devices, and storage arrays, thereby mitigating risks of data theft, tampering, or denial-of-service attacks through physical manipulation. They represent a granular layer of protection, even within an already secured IT environment.
- ✓
Mantrap at the entrance to the secure area
Why this is correct
A mantrap is a sophisticated physical access control system consisting of two interlocking doors, designed to permit only one person to enter a secure area at a time. It prevents "tailgating" or "piggybacking" by requiring authentication at both doors, effectively isolating individuals between entry points until their identity and authorization are verified. This robust control significantly enhances security for highly sensitive zones by ensuring strict one-to-one access.
- ✗
Single-factor authentication for all doors
Why it's wrong here
Single-factor authentication, such as a simple key card or PIN, provides only one layer of verification for physical access, making it inherently less secure. This approach is vulnerable to compromise if the single factor is lost, stolen, or easily guessed, failing to meet the robust requirements of a layered security strategy. A security architect would typically advocate for multi-factor authentication (e.g., card + PIN + biometric) to enhance the strength of access controls for critical areas.
- ✗
Unsecured windows on ground floor
Why it's wrong here
Unsecured windows on the ground floor represent a significant physical security vulnerability, offering an easy point of entry for unauthorized individuals rather than a control. Such windows bypass other security measures, providing direct access to the interior of a facility without requiring the attacker to breach more robust defenses like doors or fences. A security architect would identify this as a critical weakness requiring remediation, not a protective measure.
Go deeper
Related to this question
Learn chapter
Physical Security and Environmental Controls
Key term
Asset
In IT and cybersecurity, an asset is anything valuable that an organization owns or controls, including data, hardware, software, people, and intellectual property.
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.