easyMultiple Choice
SSCP Practice Question: Wants to prevent unauthorized persons from…
An organization wants to prevent unauthorized persons from entering a secure server room. Which control is the MOST effective?
⚠ Common exam trap
It's easy for candidates to choose a keypad with a unique code (Option D) thinking it is 'unique per employee' and therefore secure, but they overlook that codes can be easily shared or stolen via shoulder surfing, whereas biometrics are inherently tied to the individual and cannot be transferred.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require biometric authentication (fingerprint or retina scan) to unlock the door
Biometric authentication (fingerprint or retina scan) is the most effective control because it verifies the unique physiological characteristics of an individual, making it extremely difficult to bypass, share, or forge. Unlike knowledge-based (keypad code) or possession-based (key card) factors, biometrics provide strong, non-repudiable proof of identity, which is critical for high-security areas like a server room.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Install a CCTV camera at the entrance
Why it's wrong here
CCTV records events for later review but performs no access decision, so it cannot stop an unauthorised person entering. Cameras suit monitoring and forensic evidence alongside a locking control, not as the primary preventive mechanism for a server room.
- ✓
Require biometric authentication (fingerprint or retina scan) to unlock the door
Why this is correct
Biometric authentication binds door access to a unique physical trait, satisfying the requirement to prevent unauthorised entry because fingerprints and retina patterns cannot be shared, guessed or borrowed like tokens. Unlike keypads or badges, it resists credential theft and tailgating-assisted impersonation, making it the strongest single-factor physical control for restricting server room access.
- ✗
Post a security guard at the entrance during business hours
Why it's wrong here
A guard provides only intermittent human verification and cannot authenticate every entrant continuously, so tailgating and shift gaps leave the door uncontrolled. Guards suit low-traffic lobbies or after-hours patrols, not a server room needing per-person authentication at every entry.
- ✗
Use a keypad with a unique code for each employee
Why it's wrong here
A shared keypad code is not unique per person once known, and codes can be observed or shared, so it cannot attribute or revoke individual access. Keypads suit low-security interior doors, not a server room requiring per-user authentication and audit trails.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.