Physical Security Controls: A+ Core 2 Study Guide
Physical security controls are tangible measures designed to prevent unauthorized access to hardware and facilities. For the CompTIA A+ Core 2 exam, this includes mantraps, badge readers, biometric locks, and surveillance systems. Implementing these layered defenses ensures that only authorized personnel can access critical infrastructure like server rooms.
Why do physical security controls matter for the A+ exam?
Look, you can have the most sophisticated firewall in the world, but if a random person can walk into your server room and pull the power plug or steal a hard drive, your digital security is worthless. That is why CompTIA emphasizes physical security in the 220-1102 objectives. It is all about 'defense in depth'—creating multiple layers of security that an intruder must penetrate before reaching the crown jewels of the organization.
When you're studying for the Core 2, don't just memorize a list of devices. Think about them in terms of deterrence, detection, and prevention. A fence deters, a camera detects, and a locked door prevents. Understanding this hierarchy is key to answering the scenario-based questions that often trip up students. We always tell our students to visualize a real-world office layout to make these concepts stick.
How do mantraps and badge readers prevent unauthorized access?
One of the biggest threats to physical security is 'tailgating'—when an unauthorized person follows an authorized employee through a secure door. This is where the mantrap comes in. A mantrap is a small space with two interlocking doors; the first door must close and lock before the second one opens. This forces a one-person-at-a-time flow and allows security personnel to verify the identity of the person inside before letting them into the secure area.
Pairing mantraps with badge readers (using RFID or NFC technology) adds another layer of verification. Badge readers are practical for high-traffic areas, but they have a weakness: badges can be stolen or cloned. To pass the exam, you need to recognize that while badge readers provide convenience and an audit trail, they are most effective when combined with other controls like mantraps or security guards who can spot a fake ID.
Which biometric lock types should you know and what are their failure rates?
Biometrics are the gold standard for identity verification because they rely on 'something you are' rather than 'something you have.' For the A+ exam, focus on fingerprint scanners, retina scans, iris recognition, and facial recognition. Each has a different level of accuracy and cost. Retina scans are incredibly secure but invasive, while facial recognition is faster but can be fooled by high-quality photos in older systems.
You also need to understand two critical metrics: the False Acceptance Rate (FAR) and the False Rejection Rate (FRR). FAR is the percentage of time the system incorrectly grants access to an unauthorized user—this is a massive security risk. FRR is when the system locks out a legitimate user—this is a productivity nightmare. Finding the 'crossover error rate' (CER) is how admins balance security and usability. If you're struggling with these concepts, hitting our practice exams is the best way to see how these metrics are tested in real exam scenarios.
How do you secure a server room's environment and access?
The server room is the heart of the operation, so it requires specialized controls. Beyond the locks, you have to manage the environment. HVAC systems are critical; if your servers overheat, your uptime drops to zero. You should also be familiar with fire suppression systems—specifically clean-agent systems (like FM-200) that put out fires without spraying water and destroying the electronics.
From an access standpoint, locking server racks is a must. Even if someone gets into the room, they shouldn't have open access to the hardware. Furthermore, access logs are non-negotiable. Every time a door opens or a badge is swiped, a log is created. In a real-world audit, these logs are the first thing a security officer checks after a breach. Make sure you can identify which control solves a specific problem: for example, if the problem is 'unauthorized hardware tampering,' the answer is likely locking the racks.
What role do security cameras and guards play in a security strategy?
Not all security is high-tech. Physical guards are one of the most effective controls because they can make real-time decisions and react to anomalies that a sensor might miss. Guards provide a human element of deterrence and can perform manual identity checks. However, they are expensive and subject to human error, which is why they are almost always paired with technical controls.
CCTV (Closed-Circuit Television) serves as both a deterrent and a forensic tool. Cameras don't necessarily stop a crime in progress, but they provide the evidence needed to investigate after the fact. When you see a question about 'monitoring' or 'auditing' physical access, think cameras and logs. Combining guards, cameras, and electronic locks creates a comprehensive security posture that covers all the bases from prevention to post-incident analysis.
How can practice exams help you master these concepts?
Reading a guide is a great start, but the CompTIA A+ exam doesn't just ask you to define a mantrap—it asks you how to implement one in a specific corporate scenario. This is where active recall becomes your best friend. You need to encounter as many different phrasing styles as possible to avoid being blindsided on exam day.
At Cert Sensei, we provide 1,000 expert-curated practice questions specifically for the CompTIA A+ Core 2 (220-1102). We don't just give you a 'correct' answer; we provide detailed expert reasoning for every single choice, explaining why the right answer is right and why the distractors are wrong. Plus, our domain-level analytics show you exactly where you're weak—whether it's physical security or OS troubleshooting—so you can stop wasting time on what you already know and focus on the gaps.
❓ Frequently Asked Questions
What is the difference between tailgating and piggybacking?
Tailgating occurs when an unauthorized person follows an authorized person through a door without their knowledge. Piggybacking is similar, but the authorized person knowingly lets the other person in (e.g., holding the door for a colleague). Both are major physical security risks that mantraps are designed to prevent.
Which biometric control is generally considered the most accurate?
Retina and iris scans are typically the most accurate with the lowest False Acceptance Rates (FAR). While fingerprinting is more common and cheaper, ocular biometrics are much harder to spoof, making them ideal for high-security areas like data centers.
Why use a clean-agent fire suppression system instead of water sprinklers?
Water is conductive and destructive; using it in a server room would likely destroy the hardware you're trying to save. Clean-agent systems use gases to extinguish fire by removing heat or oxygen without leaving a residue or damaging electronic components.