SSCP Security Operations and Administration Practice Question
A security administrator is designing physical security for a high-security area. Which TWO controls are most effective for preventing unauthorized entry? (Select TWO)
⚠ Common exam trap
Many candidates confuse administrative/detective controls (visitor logs, clean desk, screen locks) with preventive physical controls — SSCP often tests whether candidates can classify controls by function (preventive vs. detective vs. administrative) rather than just recognizing security-sounding terms.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Biometric reader
A biometric reader (A) is correct because it authenticates identity using a unique physical trait such as a fingerprint or iris pattern, which cannot be easily shared, stolen, or forged like a badge or password, making it a strong preventive access control for a high-security area. A mantrap (D) is correct because it is an interlocking double-door vestibule that admits only one person at a time and prevents tailgating or piggybacking, directly stopping unauthorized individuals from following an authorized person into the secured space. Together these controls enforce both identity verification and single-person entry, which is why they are the most effective preventive measures listed. A visitor log (B) is only a detective/administrative record and does nothing to stop someone from entering. A clean desk policy (C) protects information from casual observation or theft but does not control physical entry. Screen locks (E) are a logical access control that secures a workstation session, not a barrier to entering a room.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Biometric reader
Why this is correct
A biometric reader verifies a unique physiological trait, so credentials cannot be shared, copied or lost like badges and PINs. This satisfies the high-security constraint by binding entry to a specific enrolled person, preventing unauthorised individuals from gaining access with stolen or borrowed credentials.
- ✗
Visitor log
Why it's wrong here
A visitor log records who entered, when, and whom they visited, providing accountability after the fact. Recording an entry does not deny it; the visitor still passes through. Visitor logs are correct when the requirement is auditing and escort tracking rather than physically blocking unauthorised entry.
- ✗
Clean desk policy
Why it's wrong here
A clean desk policy requires sensitive documents to be secured when workspaces are vacated, limiting exposure to someone already inside. It cannot prevent an unauthorised person from entering the area. Clean desk is correct when the risk is document or media theft by insiders, not entry control.
- ✓
Mantrap
Why this is correct
A mantrap admits one person into an interlocking vestibule, where the first door must close before the second opens, preventing tailgating and piggybacking. This satisfies the high-security constraint by enforcing single-person transit and allowing visual or biometric verification before granting inner-area entry.
- ✗
Screen locks
Why it's wrong here
Screen locks activate after a workstation is left idle, protecting the session from someone at the desk. They do nothing to stop a person physically entering the high-security area through a door. Screen locks are correct when the threat is unattended-terminal access, not perimeter intrusion.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.