ISC2 CISSP (Certified Information Systems Security Professional)Security Architecture and EngineeringEasy
A security engineer is evaluating the physical security of a data center. The primary goal is to prevent unauthorized access to sensitive server racks, even if an intruder manages to bypass the perimeter and building access controls. Which of the following physical security controls would be most effective at this specific point?
- ABiometric locks on individual server rack cabinets.
- BFencing around the entire data center property.
- CMantraps at the building's loading dock.
- DCCTV cameras monitoring the main entrance.
Show answer & explanationAnswer & explanation
Correct answer: A. Biometric locks on individual server rack cabinets.
Biometric locks on individual server rack cabinets provide granular, last-line-of-defense access control directly at the point of the sensitive assets. This prevents unauthorized access to the racks even if other layers of physical security have been compromised.
Why the other options are wrong
- B. Fencing is a perimeter control, far from the individual server racks.
- C. Mantraps control building entry, not internal rack access.
- D. CCTV monitors, but doesn't prevent access at the rack level.
Physical Access Controls
Mechanisms designed to restrict physical access to sensitive areas, equipment, or data.
- Can include locks, fences, mantraps, biometric readers, and security guards.
- Implemented in layers (defense in depth) from perimeter to internal assets.
- Crucial for protecting hardware, data storage, and critical infrastructure.
Memory trick: Layered security for data centers: from fence to rack.