Courseiva
Security Architecture and EngineeringmediumMultiple SelectObjective-mapped

CISSP Security Architecture and Engineering Practice Question

A security architect is evaluating physical security controls for a facility handling sensitive data. Which of the following are examples of layered physical security controls? (Choose THREE)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Perimeter fence

Layered security uses multiple barriers: perimeter (fence), external (lighting), building (locks), secure area (mantrap), and IT area (cage). Biometrics and guards are also layers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Perimeter fence

    Why this is correct

    A perimeter fence serves as a foundational deterrent and delay mechanism, establishing the outermost boundary of a secured area. It acts as a primary physical control, designed to discourage unauthorized entry and provide early detection of intrusion attempts by forcing an attacker to spend time breaching it. This initial barrier is crucial for defining the property line and channeling legitimate access through controlled entry points.

  • Server rack locks

    Why this is correct

    Server rack locks are an essential physical control for securing critical IT assets within a data center or server room. These locks prevent unauthorized individuals from gaining direct physical access to servers, network devices, and storage arrays, thereby mitigating risks of data theft, tampering, or denial-of-service attacks through physical manipulation. They represent a granular layer of protection, even within an already secured IT environment.

  • Mantrap at the entrance to the secure area

    Why this is correct

    A mantrap is a sophisticated physical access control system consisting of two interlocking doors, designed to permit only one person to enter a secure area at a time. It prevents "tailgating" or "piggybacking" by requiring authentication at both doors, effectively isolating individuals between entry points until their identity and authorization are verified. This robust control significantly enhances security for highly sensitive zones by ensuring strict one-to-one access.

  • Single-factor authentication for all doors

    Why it's wrong here

    Single-factor authentication, such as a simple key card or PIN, provides only one layer of verification for physical access, making it inherently less secure. This approach is vulnerable to compromise if the single factor is lost, stolen, or easily guessed, failing to meet the robust requirements of a layered security strategy. A security architect would typically advocate for multi-factor authentication (e.g., card + PIN + biometric) to enhance the strength of access controls for critical areas.

  • Unsecured windows on ground floor

    Why it's wrong here

    Unsecured windows on the ground floor represent a significant physical security vulnerability, offering an easy point of entry for unauthorized individuals rather than a control. Such windows bypass other security measures, providing direct access to the interior of a facility without requiring the attacker to breach more robust defenses like doors or fences. A security architect would identify this as a critical weakness requiring remediation, not a protective measure.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.