ISC2-CC - Access Controls Concepts - Section 3.1

Understand physical access controls and monitoring, including badges, locks, guards, and the use of defence in depth for facilities.

Identify physical access controls that protect facilities and assets - badge readers, mantraps, fences, lighting, guards, and surveillance cameras - and the monitoring that detects intrusion attempts. Recognise that layered physical controls implement defence in depth, and that logging physical access supports later investigation.

Physical access controlsBadgesMantrapSurveillanceDefence in depth

Practice question for this objective

Free sampleAccess Controls Conceptseasy

Delmere Logistics is designing a new distribution centre and wants no single physical failure to expose the goods vault. They plan a perimeter fence, a badge-controlled lobby, an interior locked corridor and a final vault door. Which security principle are they applying by layering these independent controls?

  • ADefence in depth, layering several independent controls so no single failure grants entry Correct
  • BLeast privilege, granting each worker only the access their job requires
  • CSeparation of duties, splitting a sensitive task across two different people
  • DFail-safe defaults, ensuring a door reverts to a locked state on power loss
Defence in depth layers multiple independent physical controls so no single failure grants access to the asset. The design forces an intruder to overcome the fence, then the lobby, then the corridor, then the vault door in sequence. Because each layer is independent, defeating one still leaves the others intact, which is the essence of defence in depth for facilities.

Why A is correct: Defence in depth stacks independent controls so an attacker must defeat each in turn, which is exactly what the fence, lobby, corridor and vault door achieve.

Why B is wrong: Least privilege limits what an individual may access, but it does not describe stacking multiple independent physical barriers around one asset.

Why C is wrong: Separation of duties is tempting because both aim to reduce risk, but it divides responsibility for a task rather than layering barriers around a facility.

Why D is wrong: Fail-safe defaults concern the state a single control adopts on failure, not the strategy of arranging many controls in successive layers.

See more ISC2-CC practice questions with worked answers.

More in this domain

Back to all Access Controls Concepts objectives, or the ISC2-CC cert hub.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.