Question

Difficulty: EasySecurity Program Elements and Physical Access Controls

Security controls in an enterprise network fall into physical access controls, user security awareness elements, or administrative policies. Which of the following correctly matches each security control to its corresponding security program element or physical control function?

  • Mantrap vestibule with interlocking doorsPhysical access control designed to prevent unauthorized physical entry and tailgating into sensitive areas.
  • Simulated phishing exercises and user trainingUser-focused security program element aimed at reducing human vulnerability to social engineering.
  • Formal incident response planAdministrative security program element defining structured procedures for reporting and mitigating breaches.

Answer

Mantrap vestibules correspond to physical access control preventing tailgating; simulated phishing and user training correspond to human-focused security awareness against social engineering; formal incident response plans correspond to administrative policy elements for breach mitigation.
Each item maps directly to its core function: mantraps physically control facility access to stop tailgating; phishing campaigns build human security awareness against social engineering; and incident response plans provide administrative governance for managing security breaches.

Step-by-Step Solution

1
Analyze the function of the mantrap vestibule control.
Identified as a physical barrier preventing piggybacking or tailgating into restricted areas.
Physical access controls regulate physical entry to server rooms and data centers.
2
Analyze the function of user training and phishing simulation.
Identified as a security program element aimed at personnel awareness.
User awareness programs mitigate social engineering risks by training humans.
3
Analyze the function of an incident response plan.
Identified as an administrative policy defining organizational response procedures.
Administrative controls consist of policies, governance frameworks, and operational guidelines.

Key Concept

Classification of physical access controls, security awareness elements, and administrative security policies.
Rate this question