ISFS · Question #56
A company moves into a new building. A few weeks after the move, a visitor appears unannounced in the office of the director. An investigation shows that visitors passes grant the same access as the…
The correct answer is A. A physical security measure. Option A is correct because the core failure is one of physical access control - the building lacks differentiated physical entry zones. A proper physical security measure, such as zoned access with barriers (e.g., locked doors, turnstiles, or security checkpoints that only…
Question
A company moves into a new building. A few weeks after the move, a visitor appears unannounced in the office of the director. An investigation shows that visitors passes grant the same access as the passes of the companys staff. Which kind of security measure could have prevented this?
Options
- AA physical security measure
- BAn organizational security measure
- CA technical security measure
How the community answered
(43 responses)- A84% (36)
- B9% (4)
- C7% (3)
Explanation
Option A is correct because the core failure is one of physical access control - the building lacks differentiated physical entry zones. A proper physical security measure, such as zoned access with barriers (e.g., locked doors, turnstiles, or security checkpoints that only open for staff-level badges), would have physically stopped the visitor from reaching the director's office regardless of what their pass was programmed to allow.
Option B (organizational) is wrong because organizational measures - such as a policy requiring visitors to be escorted - depend on humans consistently following procedures. They don't inherently prevent unauthorized movement through a building, and no policy is described as missing here; the access system itself is the problem.
Option C (technical) is wrong because in security frameworks, "technical" measures refer to logical/IT controls like firewalls, encryption, or authentication systems. Physical access control badges and building zones, while they use technology, are classified as physical security controls.
Memory tip: Map the three categories to their domains - Physical = barriers and spaces (doors, locks, zones), Organizational = people and policies (rules, training, procedures), Technical = IT systems (software, encryption, network controls). If the threat involves someone physically going somewhere they shouldn't, think physical first.
Topics
Community Discussion
No community discussion yet for this question.