(ISC)2 Certified in Cybersecurity Practice Exam

Disable ads (and more) with a membership for a one time $2.99 payment

Prepare for the (ISC)2 Certified in Cybersecurity Exam with comprehensive quizzes and extensive question banks. Enhance your skills with detailed explanations and practice tests designed to improve your expertise for the certification exam. Get exam-ready now!

Each practice test/flash card set has 50 randomly selected questions from a bank of over 500. You'll get a new set of questions each time!

Practice this question and more.


Which of the following statements about access control mechanisms is accurate?

  1. Biometric systems are always accurate

  2. Physical controls can be the only method needed

  3. Administrative controls are redundant

  4. Multiple control types enhance security

The correct answer is: Multiple control types enhance security

The selected answer highlights the importance of using a combination of different types of access control mechanisms to strengthen overall security. When multiple control types are implemented—such as physical, administrative, and technical controls—they create a layered defense approach. This is known as defense in depth, where each layer serves as a safeguard against potential breaches. This approach is beneficial because if one control fails or is compromised, other controls can still provide protection. For instance, if a biometric authentication system is bypassed, other methods, like security personnel or surveillance cameras, can help prevent unauthorized access. Additionally, using multiple control types can address various vulnerabilities and threats, ensuring that security is not overly reliant on a single mechanism. Other options do not accurately represent the nuances of access control mechanisms. For example, biometric systems, while often highly reliable, are not infallible and can sometimes produce false positives or negatives. Physical controls, like locks and barriers, are important but may not be sufficient alone without complementary administrative and technical measures. Lastly, administrative controls—such as policies and procedures—are fundamental to establishing guidelines and responsibilities, rather than being seen as redundant. Therefore, recognizing the value of integrating various control types is essential for effective security management.