Physical & Cyber Security Integration Flashcards
7 cards from real ATP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Physical & Cyber Security Integration flashcards as text
An organization wants to implement a Unified Security Management (USM) platform. Which capability is the defining characteristic of a true USM versus separate physical and cyber tools?
Answer: Single-pane-of-glass visibility that correlates physical sensor events with cyber telemetry in real time to generate unified alerts
A true USM platform ingests and correlates physical (PACS, video, sensors) and cyber (SIEM, EDR, network) data streams to produce unified, context-rich security alerts.
A risk assessment identifies that an unlocked utility closet provides access to network patch panels. Which risk treatment option directly addresses the convergence of physical and cyber risk?
Answer: Installing an electronic lock on the closet, logging access, and disabling unused switch ports inside
Combining a logged electronic lock with port-level network controls addresses the physical access risk and the cyber exploitation risk simultaneously.
A security architect is evaluating OSDP (Open Supervised Device Protocol) to replace legacy Wiegand wiring. What is the primary security benefit of OSDP?
Answer: OSDP supports AES-128 encrypted, mutually authenticated, bidirectional communication between readers and controllers
OSDP v2 provides AES-128 encryption and mutual authentication, eliminating the cleartext credential transmission vulnerability inherent in Wiegand.
During a business continuity drill, the primary data center is declared unavailable. Physical security staff must redirect badge readers to a backup authentication server. This scenario tests which BCM concept?
Answer: Resilience of converged identity infrastructure, specifically PACS failover to a secondary authentication endpoint
PACS failover testing validates that physical access authentication remains operational when the primary server is unavailable, a core converged BCM requirement.
Which term describes an attack where a threat actor manipulates environmental controls (HVAC, power) to cause hardware failures that then expose data or disrupt cyber systems?
Answer: Physical layer attack or environmental attack targeting cyber availability and integrity
Environmental attacks target physical infrastructure supporting IT systems, such as overheating servers by disabling cooling, to cause data loss or availability failures.
A classified government facility requires a TEMPEST-compliant workstation. What threat does TEMPEST shielding specifically address?
Answer: Electromagnetic emanation eavesdropping, where unintentional radio-frequency signals from electronic equipment are intercepted to reconstruct processed data
TEMPEST standards (e.g., NSA NSTISSAM TEMPEST/1-92) specify shielding requirements to prevent adversaries from capturing compromising electromagnetic emanations from classified systems.
An ATP candidate is asked to recommend a converged security metric. Which KPI BEST demonstrates the effectiveness of a unified physical-cyber security program?
Answer: Mean Time to Detect and Contain (MTTDC) for incidents that span both physical and cyber domains, trended over time
MTTDC for cross-domain incidents directly measures the speed and effectiveness of a converged security team in detecting and containing blended attacks.