easyMultiple Choice
CISSP Practice Question: Which security control is most effective for…
Which security control is most effective for preventing unauthorized access to a data center?
⚠ Common exam trap
CISSP often tests the distinction between preventive physical controls (mantrap, bollards, locks) and detective controls (logs, CCTV), tempting candidates to pick biometrics or surveillance when the question asks for the most effective prevention of unauthorized access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mantrap
A mantrap is a physical security control consisting of two interlocking doors with a small vestibule between them, allowing only one person through at a time and preventing tailgating. It is the most effective control for preventing unauthorized physical access to a data center because it enforces one-person-at-a-time entry and can integrate with authentication and detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Biometric authentication
Why it's wrong here
While biometric authentication is a preventive control that verifies an individual's identity using unique biological characteristics (e.g., fingerprint, iris scan), its primary function is identity verification for access authorization. It does not inherently provide a physical barrier to entry. Without a robust physical mechanism like a mantrap, an authenticated individual could potentially hold a door open for an unauthorized person, or the biometric system itself could be bypassed through sophisticated spoofing techniques, failing to physically prevent unauthorized access.
- ✓
Mantrap
Why this is correct
A mantrap is a highly effective physical security control designed to prevent unauthorized physical access by creating a controlled entry point with two interlocking doors. This system ensures that one door must be securely closed and locked before the other can open, physically preventing tailgating or piggybacking. It enforces a one-person-at-a-time policy, verifying authorization before allowing passage into a secure area, thereby directly impeding unauthorized entry.
- ✗
Access logs
Why it's wrong here
Access logs are a crucial component of an organization's security posture, serving as a detective control rather than a preventive one. These logs meticulously record events such as entry attempts, successful accesses, and user activities, providing an audit trail. While invaluable for post-incident analysis, forensics, and identifying unauthorized events after they have occurred, access logs do not actively impede or prevent an unauthorized individual from gaining physical entry in the first place.
- ✗
Video surveillance
Why it's wrong here
Video surveillance systems are primarily detective controls that capture and record visual information of an area, which can serve as a deterrent and provide crucial evidence for investigations. While the visible presence of cameras might discourage some unauthorized activity, the system itself does not physically block or prevent an unauthorized individual from entering a restricted area. Its main function is to document events as they happen or after they have occurred, aiding in identification and accountability rather than direct prevention.
Go deeper
Related to this question
Learn chapter
Identity and Access Management (IAM)
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
About these practice questions
Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.