Question

Difficulty: Very hardSecurity Program Elements and Physical Access Controls

An enterprise network security team is evaluating its defense-in-depth posture across a multi-tenant facility hosting critical infrastructure. How should each specific security measure be matched to its primary security program element or physical control category?

  • Mandatory quarterly simulated phishing exercises accompanied by automated user reporting drillsUser Security Awareness Program
  • Biometric fingerprint authentication paired with anti-passback electronic turnstiles at facility entry pointsPhysical Access Control Mechanism
  • Formal security incident escalation procedures and documented employee offboarding credential revocation policiesAdministrative Security Governance
  • Locking equipment rack enclosures equipped with micro-switch chassis intrusion sensors connected to an alarm panelPhysical Asset Protection & Tamper Monitoring

Answer

The correct matches align each operational security initiative with its designated classification: (1) Simulated phishing and user reporting drills match the User Security Awareness Program; (2) Biometric turnstiles match Physical Access Control Mechanisms; (3) Escalation workflows and offboarding policies match Administrative Security Governance; (4) Locked equipment cabinets with tamper sensors match Physical Asset Protection & Tamper Monitoring.
Each security measure correctly maps to its standard functional category within Cisco CCNA security program fundamentals: phishing simulations develop human security awareness; biometric turnstiles control physical perimeter entry; incident response and offboarding rules provide administrative governance; and locked cabinets with intrusion alarms provide physical protection for hardware assets.

Step-by-Step Solution

1
Analyze the operational focus of each security measure on the left to determine whether it addresses human behavior, physical entry, administrative policy, or asset containment.
Identified four distinct security domains: human risk reduction, perimeter access restriction, policy governance, and equipment-level physical protection.
Classifying security elements requires differentiating administrative policies, physical barriers, physical asset protection, and educational programs.
2
Associate simulated phishing drills with human defense mechanisms.
Pairs with User Security Awareness Program.
Phishing simulations educate staff and evaluate their ability to spot malicious communications, strengthening the human security perimeter.
3
Associate biometric turnstiles with physical facility entry control.
Pairs with Physical Access Control Mechanism.
Biometric scanners and physical turnstiles physically impede unauthorized entry into building zones.
4
Associate incident escalation guidelines and offboarding revocation procedures with operational governance.
Pairs with Administrative Security Governance.
Administrative controls consist of written policies, standard operating procedures, and management guidelines that govern organizational actions.
5
Associate locking cabinets and chassis tamper switches with hardware protection.
Pairs with Physical Asset Protection & Tamper Monitoring.
Locking racks and tamper sensors physically secure installed networking hardware against unauthorized physical tampering or theft.

Key Concept

Classification of Security Program Elements and Physical Access Controls
Rate this question