712-50 Question 268
Single answerPhysical Security (5 questions)A global financial services company is consolidating two regional offices into a single headquarters. During a security review, the CISO learns that the new facility will house an on-premises trading platform in a server room adjacent to a loading dock. The building landlord controls the main lobby and perimeter guards, while the company is responsible for security from the office entrance inward. Recent incidents at another company site included unauthorized visitors following employees through badge-controlled doors and a contractor entering a restricted IT area using a temporarily shared badge. The board has asked for a practical control improvement that most effectively reduces the risk of unauthorized physical access to the trading platform without causing major disruption to daily operations. Which control should the CISO prioritize?
- A
Implement a mantrap with badge plus biometric authentication at the entrance to the server room, integrated with visitor escort procedures and access logging
- B
Rely on the landlord's lobby security and add more CCTV cameras inside the office to deter unauthorized access attempts
- C
Issue all employees higher-visibility ID badges so staff can more easily identify whether a person belongs in the building
- D
Require security awareness training reminding employees not to hold doors open for others entering restricted areas
Show answer and explanation
Correct answer: A
Explanation
The best answer is the implementation of a mantrap with badge plus biometric authentication at the server room entrance. In this scenario, the organization has a shared-responsibility boundary with the landlord and must secure the space from the office entrance inward. The most effective response is therefore to apply layered, preventive controls closest to the critical asset. A mantrap helps prevent tailgating and piggybacking, while biometric verification reduces the risk of badge sharing or misuse by contractors. Logging and visitor escort procedures add governance, auditability, and operational discipline.
This reflects common physical security best practices: defense in depth, zoning of facilities by sensitivity, least privilege for physical access, and combining preventive, detective, and administrative controls. Industry guidance such as ISO/IEC 27001 Annex A physical security controls, NIST SP 800-53 physical and environmental protection controls, and data center security practices all support using stronger access restrictions for sensitive processing areas rather than relying primarily on awareness or general surveillance. From a CCISO perspective, the decision balances risk reduction, operational practicality, and ownership of controls within the organization's direct span of responsibility.
- A. Correct.
Correct. A mantrap combined with two-factor physical access controls such as badge plus biometric verification directly addresses tailgating, badge sharing, and unauthorized entry into a high-value restricted area. Integrating the control with visitor escort procedures and access logging strengthens accountability, supports investigations, and aligns with layered physical security principles for sensitive environments such as server rooms and data centers.
- B. Incorrect.
Incorrect. CCTV is a useful detective control, and landlord-operated lobby security provides some outer-layer protection, but neither sufficiently mitigates the specific risk to a restricted internal area under the company's responsibility. Cameras may record an event after it occurs, but they do not reliably prevent tailgating or badge misuse at the server room entrance.
- C. Incorrect.
Incorrect. More visible ID badges may improve general awareness, but they are a weak administrative measure for protecting a critical asset. They do not prevent a contractor from using a shared badge or an intruder from following an employee into a restricted space. This option addresses identification at a superficial level rather than enforcing access control.
- D. Incorrect.
Incorrect. Security awareness training is important and should be part of the program, especially to reduce courtesy-based tailgating. However, training alone is less effective than a technical and procedural control at the point of entry to a sensitive area. For a high-risk environment hosting a trading platform, the CISO should prioritize a preventive control with stronger enforcement.