CDCP Physical Security and Access 5 — Questions and Answers
Question 1: Which standard specifically addresses physical security requirements for data centers and IT facilities as part of its controls framework?
- ISO 9001
- ISO/IEC 27001 (Annex A) (Correct answer)
- ANSI/TIA-942
- IEEE 802.3
Correct answer: ISO/IEC 27001 (Annex A)
ISO/IEC 27001 Annex A includes physical and environmental security controls (domain A.11) covering secure areas, equipment protection, and clear desk policies.
Question 2: A data center implements 'two-person integrity' (TPI) for access to certain critical areas. What does this policy require?
- Two separate key cards must be swiped simultaneously
- No individual may enter or work in the area alone (Correct answer)
- Two security guards must escort every visitor
- Dual biometric verification from the same person
Correct answer: No individual may enter or work in the area alone
Two-person integrity requires that at least two authorized individuals be present at all times in a sensitive area to prevent unauthorized or unwitnessed actions.
Question 3: What is the MAIN security concern with raised floor access panels in a data center?
- They reduce airflow efficiency under the floor
- They provide a covert pathway for unauthorized physical access to cabling (Correct answer)
- They are difficult to label correctly for asset tracking
- They increase the risk of electrostatic discharge
Correct answer: They provide a covert pathway for unauthorized physical access to cabling
Unsecured raised floor panels can allow an intruder who gains access to the subfloor space to bypass perimeter controls and access cabling or move between zones.
Question 4: Which CCTV camera placement strategy provides the BEST coverage of a data center's server room entrance?
- Camera facing directly at the door from inside the room
- Camera positioned above and behind the entry point facing outward (Correct answer)
- Camera mounted at floor level to capture badge usage
- Camera aimed at the ceiling to capture reflections of all activity
Correct answer: Camera positioned above and behind the entry point facing outward
Positioning a camera above and behind the entry point captures faces of people entering, the badge reader interaction, and any tailgating without being easily disabled by someone entering.
Question 5: A vendor arrives to replace failed hardware in a colocation data center. Which procedure BEST protects the facility's security?
- Allow the vendor to enter freely as they are a trusted third party
- Escort the vendor at all times and limit their access to only the necessary cage or cabinet (Correct answer)
- Issue the vendor a permanent access badge for the duration of the contract
- Have the vendor submit work orders that facility staff fulfill without vendor entry
Correct answer: Escort the vendor at all times and limit their access to only the necessary cage or cabinet
Escorting vendors and limiting their physical access to only the specific equipment prevents unauthorized access to other customers' equipment and sensitive areas.
Question 6: What physical security risk is MOST associated with improperly decommissioned hard drives removed from a data center?
- Increased weight on transport vehicles
- Potential data recovery and sensitive information disclosure (Correct answer)
- Loss of hardware warranty coverage
- Compatibility issues with recycling equipment
Correct answer: Potential data recovery and sensitive information disclosure
Improperly decommissioned drives may still contain recoverable data; secure erasure or physical destruction is required to prevent sensitive data from being accessed by unauthorized parties.
Question 7: In a tiered data center security model, which zone typically requires the HIGHEST level of access control authentication?
- Parking lot and vehicle gate
- Building lobby and reception
- Network Operations Center (NOC)
- Individual server cabinet or cage (Correct answer)
Correct answer: Individual server cabinet or cage
Individual server cabinets or cages represent the innermost security perimeter and require the most stringent controls since they contain the actual hardware and data assets.
Which standard specifically addresses physical security requirements for data centers and IT facilities as part of its controls framework?