CompTIA Server+ (SK0-005)Security and Disaster RecoveryMedium
A financial institution is implementing a strict security policy for its server rooms. The policy requires that access to the server racks themselves is restricted to authorized personnel only, even if they have already gained access to the server room. This is to prevent unauthorized tampering with individual servers. Which physical security control would best address this specific requirement?
- AManned security guard at the data center perimeter
- BRack-level access control (e.g., locking cabinets)
- CBiometric access control at the server room entrance
- DCCTV cameras throughout the server room
Show answer & explanationAnswer & explanation
Correct answer: B. Rack-level access control (e.g., locking cabinets)
Rack-level access control, such as locking server cabinets or individual server bays, provides an additional layer of physical security beyond the room itself. This directly addresses the requirement to restrict access to individual server racks even after entry into the main server room.
Why the other options are wrong
- A. Manned security guards secure the perimeter, but not necessarily individual racks within a secured room.
- C. Biometric access control secures the room entrance but does not restrict access to individual racks within the room.
- D. CCTV cameras provide monitoring and evidence, but do not prevent unauthorized physical access to racks.
Rack-Level Physical Security
Physical security measures applied directly to server racks or cabinets to restrict unauthorized access to the servers and equipment contained within them.
- Adds a layer of security inside a secured room.
- Includes locking cabinets, smart racks, and individual bay locks.
- Protects against insider threats and unauthorized tampering.
Memory trick: Think of nested security: Perimeter, Room, then Rack.