Security controls in an enterprise network fall into physical access controls, user security awareness elements, or administrative policies. Which of the following correctly matches each security control to its corresponding security program element or physical control function?
- Mantrap vestibule with interlocking doorsPhysical access control designed to prevent unauthorized physical entry and tailgating into sensitive areas.
- Simulated phishing exercises and user trainingUser-focused security program element aimed at reducing human vulnerability to social engineering.
- Formal incident response planAdministrative security program element defining structured procedures for reporting and mitigating breaches.
Answer
Mantrap vestibules correspond to physical access control preventing tailgating; simulated phishing and user training correspond to human-focused security awareness against social engineering; formal incident response plans correspond to administrative policy elements for breach mitigation.
Each item maps directly to its core function: mantraps physically control facility access to stop tailgating; phishing campaigns build human security awareness against social engineering; and incident response plans provide administrative governance for managing security breaches.
Step-by-Step Solution
Key Concept
Classification of physical access controls, security awareness elements, and administrative security policies.