Question

Difficulty: HardPhysical Security Controls

An IT security team must update physical security controls at a satellite office based on a recent vulnerability audit. The report mandates deploying controls to specifically address two vulnerabilities: preventing the physical theft of unattended desktop computers located in open work areas, and physically blocking unauthorized media insertion into unused Ethernet and USB ports on network switches. Which of the following physical security controls should the IT team deploy to fulfill these requirements? (Select TWO.)

  1. Cable locksAnswer
  2. Port locksAnswer
  3. C
    Privacy filters
  4. D
    Asset tags
  5. E
    Faraday bags

Answer

Cable locks and port locks should be deployed to satisfy the audit requirements.
Cable locks physically tether workstation computers to stationary objects to mitigate theft in accessible work environments. Port locks are physical plugs inserted into empty USB or Ethernet ports that require a proprietary key to remove, preventing unauthorized physical access to network infrastructure.

Step-by-Step Solution

1
Analyze the first requirement: preventing physical theft of unattended desktop computers in open areas.
Identify that cable locks (such as Kensington locks) tether the desktop chassis directly to desks or structural fixtures, preventing hardware theft.
Cable locks provide a direct physical restraint against unauthorized equipment removal.
2
Analyze the second requirement: physically blocking unauthorized media/connections into unused Ethernet and USB ports on network switches.
Identify that port locks plug into unused RJ-45 and USB sockets and require a specialized key to remove, blocking unauthorized physical connections.
Port locks secure open interface ports from unauthorized physical flash drive insertion or rogue device attachment.
3
Evaluate the non-selected options to confirm they do not satisfy either requirement.
Privacy filters address visual security, asset tags address tracking, and Faraday bags address RF shielding.
None of the alternative options physically anchor hardware or lock down network ports.

Key Concept

Physical Security Controls for Device Anchoring and Interface Locking
Estimated Time:2m 0s
Rate this question