โ† All ATP Flashcard Decks

Physical & Cyber Security Integration Flashcards

7 cards from real ATP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Physical & Cyber Security Integration flashcards as text
  1. A water treatment facility classifies its operational technology (OT) network as critical infrastructure. Which approach BEST represents converged physical-cyber resilience for this environment?

    Answer: Air-gapped OT network with physically controlled jump servers and logged USB usage for data transfer

    Air-gapping OT networks with tightly controlled, monitored physical access points reduces both cyber and insider-threat attack surfaces.

  2. Video surveillance footage is subpoenaed as evidence after a physical breach that also involved data exfiltration. Which chain-of-custody principle is MOST critical when handling this digital evidence?

    Answer: Maintaining a documented, unbroken log of who accessed, copied, and transferred the footage from collection to courtroom

    An unbroken chain of custody documents every person who handled the evidence, preserving its integrity and admissibility in legal proceedings.

  3. A company's security policy requires all visitors to be escorted and wear temporary badges. A visitor is discovered in a restricted server room unescorted with their badge obscured. Which term describes this type of insider threat scenario?

    Answer: Unintentional or intentional policy violation enabling physical reconnaissance or data exfiltration

    An unescorted visitor in a restricted area may represent a policy violation enabling physical reconnaissance or theft of data/hardware.

  4. Which encryption standard is recommended for protecting data on removable media that may leave a physically secure facility?

    Answer: AES-256 in XTS mode

    AES-256 in XTS mode (IEEE P1619) is the industry standard for full-disk and removable-media encryption due to its strength and sector-level diffusion.

  5. A Security Operations Center (SOC) analyst notices that a card reader alarm triggered at 2:47 AM correlates with an outbound data transfer spike on the SIEM at 2:49 AM. This is an example of:

    Answer: Physical-cyber event correlation detecting a coordinated insider attack or breach

    Temporal correlation between a physical access event and a network anomaly strongly suggests a coordinated attack combining physical and cyber vectors.

  6. Under HSPD-12 / FIPS 201, what is the primary purpose of the Personal Identity Verification (PIV) card for federal employees?

    Answer: To provide a single interoperable credential for both physical access to buildings and logical access to IT systems

    HSPD-12 mandates PIV cards as a common interoperable credential enabling both physical access control and PKI-based logical access across federal agencies.

  7. An attacker cuts the fiber connecting a building's IP camera system to the security server just before breaching the facility. Which resilience design would BEST mitigate this tactic?

    Answer: Cameras with onboard SD card storage and cellular backup uplink that continue recording and alerting independently

    Local onboard storage combined with an independent cellular uplink ensures continuous recording and alerting even when primary network connectivity is severed.