Soru

Zorluk: ZorSecurity Program Elements and Physical Access Controls

An organization is updating its enterprise security program policy for network edge enclosures located in multi-tenant facilities. The Chief Information Security Officer (CISO) requires a security architecture that combines an administrative security program element with a physical access control mechanism to prevent unauthorized physical hardware tampering by facility personnel. Which set of measures correctly pairs an administrative security program element with a physical access control to fulfill this mandate?

  1. Establishing a formal access authorization policy requiring pre-approved visitor lists and badge verification, paired with installing chassis intrusion sensors and lockable rack enclosures.Cevap
  2. B
    Configuring AAA authorization profiles on a centralized TACACS+ server, paired with establishing site-to-site IPsec VPN tunnels between remote sites.
  3. C
    Enabling Port Security with sticky MAC address learning on edge switch ports, paired with configuring extended IPv4 Access Control Lists (ACLs) on default gateways.
  4. D
    Deploying DHCP Snooping to validate incoming network leases, paired with implementing an explicit deny statement at the end of interface filtering lists.

Cevap

Establishing a formal access authorization policy requiring pre-approved visitor lists and badge verification, paired with installing chassis intrusion sensors and lockable rack enclosures.
Developing a formal access authorization policy with visitor verification represents an administrative control (governance, policy, and procedure). Installing lockable enclosures with chassis intrusion detection represents a physical access control that directly prevents and monitors physical contact with hardware components.

Adım Adım Çözüm

1
Identify the requested security control categories from the problem statement.
The scenario specifically asks for one administrative security program element paired with one physical access control mechanism.
Security programs classify controls into administrative (policies, procedures, personnel controls), physical (barriers, locks, environmental sensors), and technical/logical (passwords, ACLs, encryption).
2
Analyze each proposed pairing to classify its control types.
Creating an access authorization policy is administrative (governance/policy), and using lockable rack enclosures with chassis intrusion sensors is physical (hardware boundary/detection).
Administrative controls dictate rules and operational procedures, whereas physical controls protect physical assets from direct human intervention.
3
Differentiate administrative/physical controls from technical/logical controls present in wrong choices.
Measures involving TACACS+, IPsec VPNs, Port Security, ACLs, and DHCP Snooping are strictly technical/logical controls implemented in software or network device configurations.
Confusing technical network security mechanisms with administrative policies or physical barriers is a common conceptual mistake.

Anahtar Kavram

Classification of Enterprise Security Controls (Administrative vs. Physical vs. Technical)
Bu soruyu puanla