Question

Difficulty: HardSecurity Program Elements and Physical Access Controls

A network security engineer is reviewing the defense-in-depth posture for a sensitive financial processing facility. The engineer needs to implement controls that belong specifically to the physical security domain or administrative security program elements, distinguishing them from technical and logical network mechanisms. Which two options represent physical access controls or security program elements? (Select two.)

  1. Installing a biometric mantrap vestibule at the data center entrance to prevent unauthorized entry and tailgatingAnswer
  2. Establishing mandatory user security awareness training focused on identifying social engineering and phishing tacticsAnswer
  3. C
    Enforcing TACACS+ authentication and authorization for central administrative command access on infrastructure devices
  4. D
    Configuring Layer 2 switch port security with sticky MAC address learning to restrict unauthorized end-host attachments
  5. E
    Deploying extended IPv4 access control lists (ACLs) on internet-facing edge routers to filter untrusted packet traffic

Answer

Installing biometric mantrap vestibules and establishing user security awareness training programs are the two measures that fall under physical access controls and security program elements.
Physical security controls encompass physical barriers, biometric readers, badge access systems, mantrap vestibules, and surveillance designed to prevent unauthorized physical access to computing hardware. Security program elements include human-centric initiatives such as user security awareness training, security policies, and incident handling protocols. The mantrap vestibule directly secures physical entry, while security awareness training addresses user behavior and social engineering resistance.

Step-by-Step Solution

1
Classify the security requirements
Identify physical security mechanisms (physical barriers/locks/biometrics) and security program elements (policies/awareness/training).
Security controls are categorized into administrative/programmatic, physical, and technical/logical domains.
2
Evaluate the physical control options
Biometric mantrap vestibules physically restrict access to facilities and prevent tailgating, qualifying directly as physical access controls.
Physical controls govern physical entry into facility perimeters, server rooms, and network closets.
3
Evaluate the security program element options
Mandatory security awareness training educates personnel on human threat vectors, qualifying directly as a security program element.
Security program elements include administrative policies, security training, incident response plans, and compliance frameworks.
4
Differentiate technical controls from physical/programmatic controls
TACACS+ AAA authentication, switch port security, and router ACLs are technical (logical) security mechanisms operating on network hardware and protocols.
Technical controls use software and hardware logic to enforce security policies on data traffic and device administration.

Key Concept

Classification of Security Control Types (Physical vs. Programmatic/Administrative vs. Technical/Logical)
Estimated Time:1m 30s
Rate this question