ISC2-CC - Access Controls Concepts (22% of the exam) - Section 3.1

Understand physical access controls and monitoring, including badges, locks, guards, and the use of defence in depth for facilities.

Identify physical access controls that protect facilities and assets - badge readers, mantraps, fences, lighting, guards, and surveillance cameras - and the monitoring that detects intrusion attempts. Recognise that layered physical controls implement defence in depth, and that logging physical access supports later investigation.

Physical access controlsBadgesMantrapSurveillanceDefence in depth

Practice question for this objective

Free sampleAccess Controls Conceptseasy

Delmere Logistics is designing a new distribution centre and wants no single physical failure to expose the goods vault. They plan a perimeter fence, a badge-controlled lobby, an interior locked corridor and a final vault door. Which security principle are they applying by layering these independent controls?

  • ADefence in depth, layering several independent controls so no single failure grants entry Correct
  • BLeast privilege, granting each worker only the access their job requires
  • CSeparation of duties, splitting a sensitive task across two different people
  • DFail-safe defaults, ensuring a door reverts to a locked state on power loss
Defence in depth layers multiple independent physical controls so no single failure grants access to the asset. The design forces an intruder to overcome the fence, then the lobby, then the corridor, then the vault door in sequence. Because each layer is independent, defeating one still leaves the others intact, which is the essence of defence in depth for facilities.

Why A is correct: Defence in depth stacks independent controls so an attacker must defeat each in turn, which is exactly what the fence, lobby, corridor and vault door achieve.

Why B is wrong: Least privilege limits what an individual may access, but it does not describe stacking multiple independent physical barriers around one asset.

Why C is wrong: Separation of duties is tempting because both aim to reduce risk, but it divides responsibility for a task rather than layering barriers around a facility.

Why D is wrong: Fail-safe defaults concern the state a single control adopts on failure, not the strategy of arranging many controls in successive layers.

See more ISC2-CC practice questions, answers explained.

Exam traps in Access Controls Concepts

Answers that look right on this material and are not. Each one is a distractor from a different question in the ISC2-CC bank for this domain.

  • Least privilege, granting each subject only the minimum access required

    Why it is wrong: Least privilege is a real principle, but it governs how much access a subject is granted, not the layering of independent physical barriers.

  • Preventive, because the cameras physically stop an intruder from reaching the entrance

    Why it is wrong: Cameras rarely block entry on their own, so labelling them purely preventive misreads how surveillance works even though a visible camera can deter.

  • Concentrating the budget on a single high-specification electronic lock on the records room door

    Why it is wrong: A strong lock is worth having, but relying on one measure means a single bypass exposes everything, which is the outcome the partners want to avoid.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.