An enterprise network security team is evaluating its defense-in-depth posture across a multi-tenant facility hosting critical infrastructure. How should each specific security measure be matched to its primary security program element or physical control category?
- Mandatory quarterly simulated phishing exercises accompanied by automated user reporting drillsUser Security Awareness Program
- Biometric fingerprint authentication paired with anti-passback electronic turnstiles at facility entry pointsPhysical Access Control Mechanism
- Formal security incident escalation procedures and documented employee offboarding credential revocation policiesAdministrative Security Governance
- Locking equipment rack enclosures equipped with micro-switch chassis intrusion sensors connected to an alarm panelPhysical Asset Protection & Tamper Monitoring
Cevap
The correct matches align each operational security initiative with its designated classification: (1) Simulated phishing and user reporting drills match the User Security Awareness Program; (2) Biometric turnstiles match Physical Access Control Mechanisms; (3) Escalation workflows and offboarding policies match Administrative Security Governance; (4) Locked equipment cabinets with tamper sensors match Physical Asset Protection & Tamper Monitoring.
Each security measure correctly maps to its standard functional category within Cisco CCNA security program fundamentals: phishing simulations develop human security awareness; biometric turnstiles control physical perimeter entry; incident response and offboarding rules provide administrative governance; and locked cabinets with intrusion alarms provide physical protection for hardware assets.
Adım Adım Çözüm
Anahtar Kavram
Classification of Security Program Elements and Physical Access Controls