CDCP - Certified Data Centre Professional Physical Security and Access Questions and Answers 1 — Questions and Answers
Question 1: A high-security data center needs to implement an access control system at the entrance to the main data hall that prevents tailgating and ensures only one individual enters per authorization. Which of the following solutions best meets this requirement?
- A full-height turnstile with a card reader.
- A mantrap with interlocking doors and multi-factor authentication. (Correct answer)
- A reinforced steel door with a biometric fingerprint scanner.
- Multiple CCTV cameras with advanced video analytic software.
Correct answer: A mantrap with interlocking doors and multi-factor authentication.
A mantrap is a physical security control system with two sets of interlocking doors where the first set must close before the second set can open. [19, 11] This design physically prevents tailgating by trapping an individual in a small space to be authenticated, ensuring only one person can enter at a time. [24]
Question 2: Which of the following represents the correct order for a multi-layered physical security approach in a data center, starting from the outermost layer and moving to the innermost?
- Room Access Control -> Rack-level Locks -> Building Entrance -> Site Perimeter Fence
- Site Perimeter Fence -> Building Entrance -> Room Access Control -> Rack-level Locks (Correct answer)
- Rack-level Locks -> Site Perimeter Fence -> Building Entrance -> Room Access Control
- Building Entrance -> Rack-level Locks -> Room Access Control -> Site Perimeter Fence
Correct answer: Site Perimeter Fence -> Building Entrance -> Room Access Control -> Rack-level Locks
A proper defense-in-depth or layered security strategy starts with securing the widest area and adds progressively stricter controls as one moves closer to the critical assets. [4, 3] The logical sequence is to first secure the site perimeter (fence), then the building itself (entrance), followed by the specific sensitive room (data hall access), and finally the individual equipment cabinets (rack locks).
Question 3: A data center manager is implementing a two-factor authentication (2FA) policy for accessing secure areas. Which of the following combinations correctly uses two different authentication factors?
- A password and a PIN code.
- A fingerprint scan and an iris scan.
- A key card and a security token.
- A proximity card and a PIN code. (Correct answer)
Correct answer: A proximity card and a PIN code.
True two-factor authentication requires evidence from two of the three distinct categories: something you know (knowledge), something you have (possession), and something you are (inherence). [13] A proximity card is 'something you have,' and a PIN code is 'something you know,' satisfying the 2FA requirement. [17, 18] Options A, B, and C each use two factors from the same category (both knowledge, both inherence, and both possession, respectively).
Question 4: In the context of data center perimeter security, what is the primary function of installing bollards around the building and at key access points?
- To provide mounting points for lighting and security cameras.
- To act as a physical barrier to prevent vehicle ramming and control unauthorized vehicle access. (Correct answer)
- To define designated smoking areas for data center staff.
- To improve the architectural aesthetics of the facility's entrance.
Correct answer: To act as a physical barrier to prevent vehicle ramming and control unauthorized vehicle access.
Bollards are robust vertical posts designed primarily to serve as a protective barrier against vehicular impact, whether accidental or intentional. [1, 2] They are a key component of perimeter security used to prevent unauthorized vehicles from approaching or ramming a building, thereby protecting the structure and its occupants. [7, 14]
Question 5: A third-party contractor requires access to the data hall to perform scheduled maintenance on a cooling unit. According to best practices for operational security, what is the most critical procedure to enforce?
- Providing the contractor with a temporary master access card for the day.
- Requiring the contractor to be continuously escorted by an authorized staff member. (Correct answer)
- Allowing unsupervised access after the contractor signs a non-disclosure agreement.
- Reviewing the contractor's work via CCTV footage after they have left the facility.
Correct answer: Requiring the contractor to be continuously escorted by an authorized staff member.
Best practices for data center security mandate that all non-employee visitors, including contractors and vendors, must be escorted at all times by authorized personnel when inside secure areas. [20, 22] This mitigates the risk of unauthorized access to equipment or data and ensures the contractor only performs the authorized work.
Question 6: When designing a CCTV surveillance system for a data center, which of the following is a primary objective to ensure its effectiveness for security and auditing purposes?
- Ensuring complete coverage without blind spots, particularly at all entry/exit points and in server aisles. (Correct answer)
- Using low-resolution cameras to minimize video storage costs.
- Setting the video retention policy to a maximum of 24 hours.
- Placing monitors only in the main security office to limit who can view them.
Correct answer: Ensuring complete coverage without blind spots, particularly at all entry/exit points and in server aisles.
An effective CCTV system must provide comprehensive visual coverage of all critical areas to detect and record security events. [6] Eliminating blind spots is crucial, especially at doors, corridors, and aisles between racks, to ensure a complete and usable audit trail of all activities within the secure space.
A high-security data center needs to implement an access control system at the entrance to the main data hall that prevents tailgating and ensures only one individual enters per authorization.
Which of the following solutions best meets this requirement?