Courseiva

CISSP Security Architecture and Engineering Practice Question

A security architect is evaluating physical security controls for a facility handling sensitive data. Which of the following are examples of layered physical security controls? (Choose THREE)

⚠ Common exam trap

CISSP often tests the distinction between actual layered controls and single points of failure or vulnerabilities, so candidates must recognize that unsecured windows and single-factor auth are weaknesses, not layers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Perimeter fence

The question asks for layered physical security controls, meaning multiple defensive measures at different depths. Option A, a perimeter fence, is correct because it establishes the outermost physical boundary and deters or delays unauthorized access before an intruder reaches the building. Option B, server rack locks, is correct because it provides an inner layer of protection directly at the asset, restricting access to the servers even after someone has entered the facility. Option C, a mantrap at the entrance to the secure area, is correct because it is a physical access control vestibule that allows only one person through at a time and prevents tailgating, adding a controlled transition layer between zones. Option D, single-factor authentication for all doors, is not a layered physical control; single-factor authentication is weak and does not add defense in depth, and authentication is more of an access control mechanism than a physical barrier. Option E, unsecured windows on the ground floor, is not a control at all but a vulnerability, since unlocked or unprotected windows provide an easy bypass of other physical defenses.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Perimeter fence

    Why this is correct

    A perimeter fence serves as a foundational deterrent and delay mechanism, establishing the outermost boundary of a secured area. It acts as a primary physical control, designed to discourage unauthorized entry and provide early detection of intrusion attempts by forcing an attacker to spend time breaching it. This initial barrier is crucial for defining the property line and channeling legitimate access through controlled entry points.

  • ✓

    Server rack locks

    Why this is correct

    Server rack locks are an essential physical control for securing critical IT assets within a data center or server room. These locks prevent unauthorized individuals from gaining direct physical access to servers, network devices, and storage arrays, thereby mitigating risks of data theft, tampering, or denial-of-service attacks through physical manipulation. They represent a granular layer of protection, even within an already secured IT environment.

  • ✓

    Mantrap at the entrance to the secure area

    Why this is correct

    A mantrap is a sophisticated physical access control system consisting of two interlocking doors, designed to permit only one person to enter a secure area at a time. It prevents "tailgating" or "piggybacking" by requiring authentication at both doors, effectively isolating individuals between entry points until their identity and authorization are verified. This robust control significantly enhances security for highly sensitive zones by ensuring strict one-to-one access.

  • ✗

    Single-factor authentication for all doors

    Why it's wrong here

    Single-factor authentication, such as a simple key card or PIN, provides only one layer of verification for physical access, making it inherently less secure. This approach is vulnerable to compromise if the single factor is lost, stolen, or easily guessed, failing to meet the robust requirements of a layered security strategy. A security architect would typically advocate for multi-factor authentication (e.g., card + PIN + biometric) to enhance the strength of access controls for critical areas.

  • ✗

    Unsecured windows on ground floor

    Why it's wrong here

    Unsecured windows on the ground floor represent a significant physical security vulnerability, offering an easy point of entry for unauthorized individuals rather than a control. Such windows bypass other security measures, providing direct access to the interior of a facility without requiring the attacker to breach more robust defenses like doors or fences. A security architect would identify this as a critical weakness requiring remediation, not a protective measure.

About these practice questions

This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.