712-50 exam dumps

712-50 practice question 269 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 269

Single answerPhysical Security (5 questions)

A global manufacturing company is consolidating two regional data centers into a single flagship facility that will host ERP systems, plant telemetry aggregation, and sensitive design repositories. During a pre-opening walkthrough, the CISO learns that facilities management plans to use standard employee badges for data center entry, allow operations staff to hold the mantrap door open during shift changes to reduce delays, and rely primarily on CCTV review after incidents occur. The board has asked the CISO to recommend the MOST effective physical security control improvement to reduce the risk of unauthorized access while preserving operational continuity. Which option should the CISO recommend first?

  1. A

    Implement layered access controls for the data center, including role-based badge access, anti-tailgating mantraps that must not be bypassed, and real-time monitoring with alerting for forced or propped doors

  2. B

    Increase the retention period for CCTV recordings from 30 days to 180 days so investigations can reconstruct physical access events in greater detail

  3. C

    Replace all badge readers with biometric-only access to eliminate the risk of lost or shared access cards

  4. D

    Require security guards to manually verify every employee entering the data center during shift changes, regardless of role or preapproved access

Show answer and explanation

Correct answer: A

Explanation

The best answer is the implementation of layered physical access controls because the scenario highlights failures in preventive and real-time detective measures, not just investigative capability. Physical security for critical facilities should follow defense-in-depth principles: restrict access based on business need, enforce controlled entry procedures such as mantraps and anti-tailgating measures, and generate immediate alerts for anomalous events like forced or propped doors. This aligns with widely accepted practices in ISO/IEC 27001 Annex A physical security controls, NIST SP 800-53 physical and environmental protection controls, and common data center security standards emphasizing least privilege, segregation of access, monitored entry points, and prompt incident response. From a CCISO perspective, the recommendation must balance risk reduction, governance, and operational continuity. Option 1 best addresses that balance by strengthening policy enforcement and technical controls at the highest-risk point: physical ingress to the data center.

  • A. Correct.

    Correct. This is the strongest risk-based recommendation because it applies defense in depth at the point of entry and directly addresses the identified weaknesses: overly broad badge use, bypassing mantrap procedures, and reactive-only CCTV usage. Role-based access supports least privilege, anti-tailgating controls reduce piggybacking risk, and real-time monitoring enables immediate response rather than post-incident discovery. For a CISO, this is the most balanced recommendation because it reduces unauthorized entry risk without creating unnecessary operational bottlenecks.

  • B. Incorrect.

    Incorrect. Longer CCTV retention may improve forensic investigation, but it does not materially prevent unauthorized entry. The scenario's primary issue is weak preventive and detective controls at ingress, not insufficient historical evidence. This is a common misconception: improving after-the-fact visibility is not the same as reducing the likelihood of a physical breach.

  • C. Incorrect.

    Incorrect. Biometric-only access may appear stronger, but using it as a single control introduces operational and privacy concerns and does not by itself address tailgating, propped doors, or layered authorization. In practice, many mature facilities use biometrics as an additional factor for high-security zones, not necessarily as a universal replacement for all badge readers. The weakness in the scenario is the absence of layered controls and enforcement, not merely the credential technology.

  • D. Incorrect.

    Incorrect. Manual guard verification for every entry is labor-intensive, error-prone, and likely to disrupt operations during shift changes. While guards are an important compensating control, relying on manual checks as the primary mechanism is less scalable and less consistent than engineered controls such as role-based access, mantraps, and alarmed door monitoring. This option may be chosen by candidates who overvalue visible security presence over sustainable control design.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam