Soru

Zorluk: OrtaSecurity Program Elements and Physical Access Controls

An enterprise network operations center is aligning its infrastructure security framework with Cisco security baseline recommendations. Match each security program element or access control type on the left to its corresponding operational implementation on the right.

  • Physical Access ControlDeploying biometric scanners, badge readers, and mantrap portals to secure entry into data centers.
  • Security Awareness TrainingConducting regular user education sessions regarding phishing risks, password hygiene, and tailgating prevention.
  • Incident Response PlanDefining structured escalation workflows and containment procedures to follow immediately after a security event.
  • Administrative Policy ControlEstablishing formal corporate documentation defining acceptable use policies and password requirements.

Cevap

Physical Access Control pairs with biometric scanners and mantrap portals; Security Awareness Training pairs with user education on phishing and tailgating; Incident Response Plan pairs with structured escalation workflows and containment procedures; Administrative Policy Control pairs with corporate documentation establishing acceptable use policies.
Physical access control directly limits physical proximity to network infrastructure using devices like mantrap portals and biometrics. Security awareness training educates users on recognizing threats like tailgating and phishing. Incident response plans outline emergency response steps following a breach. Administrative controls establish corporate rules, governance, and written security guidelines.

Adım Adım Çözüm

1
Identify physical security measures.
Biometric readers, mantraps, locks, and badges directly restrict physical access to facilities.
Physical access control measures deal directly with spatial access to facilities and network hardware.
2
Differentiate human-focused educational controls from administrative rules.
Training sessions target user behavior (phishing, tailgating awareness), whereas administrative policies set the formal written rules (acceptable use).
User training is an operational program element, while governance rules represent administrative controls.
3
Categorize reactive security procedures.
Escalation workflows and containment procedures belong to incident management.
Incident response plans guide organizational actions during and after a security event.

Anahtar Kavram

Classification of Enterprise Security Program Elements and Controls
Bu soruyu puanla