Physical security, and the controls that come before every other one
Why this matters
Security domains usually open with passwords, and that is the wrong place to start. Every control in the rest of this domain — encryption, permissions, authentication, malware defence — assumes that an attacker does not have the machine in their hands. When they do, most of those controls become negotiable.
The exam treats physical security as a first-class topic for that reason, and it asks about it in a specific way: given a scenario, which physical control addresses it. So this lesson is organised around what each control is actually for, and around the ways each one is defeated — because the defeats are what the scenario questions describe.
The lesson
Why physical access defeats most of what follows, stated plainly once
Here is the claim, stated once and plainly: physical access defeats most software controls, given time.
- A machine that is not encrypted gives up all its data to anyone who removes the disk. The account password protects the session, not the storage.
- A machine that is running and unlocked gives up everything immediately, and no amount of policy helps.
- Firmware passwords, boot order restrictions and secure boot raise the cost and can often be reset by someone with the case open and a service manual.
- A device left in a taxi is a breach whose technical controls were all decided weeks earlier.
The one control that genuinely survives physical possession is encryption at rest with a key the attacker does not have — which is why full disk encryption gets its own lesson in this domain and why it is the answer to a large class of scenario questions.
What this means for a technician's daily behaviour is small and concrete: lock the screen every time you walk away, do not leave a machine open on a customer site, do not leave equipment in a car, and treat a machine you have been handed as something whose data you are now responsible for.
That last one is worth dwelling on. A repair bench holds other people's unencrypted data, and the physical security of that bench is a real control rather than a formality.
Locks, cable locks, server locks and the entry controls above them
Physical controls are layered, and each layer has a specific job.
At the device:
- Cable locks attach a laptop to something immovable. They defeat opportunistic theft and nothing else — the slot can be broken out with effort — which is exactly what they are for.
- Locking enclosures and server locks protect the parts of a machine that matter: the drives, the front panel, the power button.
- Port blockers and disabled ports stop devices being attached. Disabling unused ports in firmware or policy is the software half of the same idea.
At the room:
- Locked doors, keyed or electronic. Electronic locks add per-person access and a log, which is the reason organisations move to them.
- Equipment racks with locking doors, because a locked room with an open rack protects nothing from a visitor with a reason to be there.
At the site:
- Fences, bollards and gates control vehicles and the approach.
- Lighting, which is a genuine deterrent rather than a symbolic one.
- Cameras, which are detective rather than preventive — they record what happened and deter people who expect to be recognised.
- Guards, the only control that can exercise judgement.
The pattern the exam wants you to recognise is the layering: a control at one layer is not a substitute for one at another, and the question usually describes a gap between two layers.
Badge readers, biometrics, mantraps and tailgating as the defeat of all three
Entry controls are where the interesting failures are, and all three of these have a named defeat.
Badge readers authenticate a card, not a person. Defeats: a borrowed or stolen badge, a cloned card (older proximity technologies are trivially cloneable), and the badge left in a coat pocket in the pub. Mitigations are a PIN alongside the badge, photo badges that someone actually looks at, and technology that resists cloning.
Biometrics authenticate a body part. Defeats: failure rates in both directions — a false rejection annoys the legitimate user, a false acceptance admits the wrong person, and tuning one worsens the other. Systems also degrade with dirty sensors, gloves and injuries, and every biometric system needs a fallback, which becomes the real attack surface.
Mantraps (access control vestibules) admit one person at a time between two interlocked doors, and exist specifically to defeat the next item.
Tailgating — following an authorised person through a door — defeats badge readers and biometrics completely, because the door was opened legitimately. It is the single most effective physical attack there is, it requires no equipment, and it is socially very hard to challenge. That is why the controls against it are structural (a vestibule, a turnstile) or procedural (a culture where challenging is normal, and a guard whose job it is).
For the exam: a scenario describing someone entering behind an employee is tailgating, and the control is an access control vestibule or a guard — not a better badge reader, because the reader worked exactly as designed.
Screen locks, privacy filters and the desk nobody thinks of as an attack surface
The controls closest to the user are the ones most often left out, and they cover a real gap.
Screen locks. A short timeout plus lock-on-close, enforced by policy rather than by asking. The examinable point is that this is the control against the unattended unlocked machine, which is the most common way an insider gets access to something they should not have.
Privacy filters narrow the viewing angle so a screen is readable only from in front. They are for public places — trains, cafés, open reception areas — and they are the control against shoulder surfing.
The desk itself is an attack surface, and a clear-desk policy is a real control rather than a tidiness rule:
- Passwords written on notes, which remain extremely common.
- Documents containing personal or regulated data left face up.
- Removable media left in drawers or in the machine.
- Printed output left on the printer, which is why secure release printing exists.
And the two that technicians create: an unlocked machine left mid-repair, and a bench where a customer's disk sits visible to whoever walks past.
The habit that covers most of it is one keystroke — lock the screen — and it is worth building to the point of being automatic, because the situations where it matters are exactly the ones where you are distracted.
Securing equipment in transit and at a customer site
Equipment moves, and it is least protected while it is moving.
In transit:
- Carry devices in something that does not advertise what it is.
- Never leave equipment visible in a vehicle, and prefer not to leave it in a vehicle at all.
- Keep devices as hand luggage rather than checked baggage.
- Encrypt before travelling, not after. A device that is encrypted at rest and powered off is genuinely protected; one that is suspended is much less so, because the key is in memory.
- Know what the device holds. A laptop carrying a copy of a customer database is a different risk from one carrying a browser.
At a customer site:
- Keep your own equipment with you or locked away. A technician's toolkit and spare drives are attractive and portable.
- Treat their equipment as theirs: do not move it, open it, or connect to it beyond what you were asked to do.
- Be conscious of what is visible. You will see screens, papers and conversations that are not yours, and the professional response is to not look and not repeat.
- When you leave, leave it locked — their machine and yours.
There is an operational procedures point here too, which the last domain of this course develops: equipment that moves needs a record of where it is and who has it. An asset register that says a laptop is "with IT" eighteen months after it left is not a record, and the first anyone knows about a missing device is often an audit.
Practise what you just read
1. Why is physical access treated as defeating most software controls?
Select one
Show answer
A. The account password protects the session rather than the storage. The one control that genuinely survives physical possession is encryption at rest with a key the attacker does not have.
2. Someone enters a controlled door behind an authorised employee. What is this called?
Select one
Show answer
B. The badge reader worked exactly as designed, which is why a better reader is not the answer. The controls are structural, such as an access control vestibule, or procedural, such as a guard.
3. Which control is designed specifically to prevent more than one person entering at once?
Select one
Show answer
C. Two interlocked doors admit one person at a time. Cameras are detective rather than preventive: they record what happened and deter people who expect to be recognised.
7 more questions on this objective are part of the full course.
Hands-on labs
Part of the free CompTIA A+ Core 2 220-1202 course — 50 lessons and 62 hands-on labs.
This is an independent study companion for CompTIA A+ Core 2 220-1202 and is not produced by or endorsed by CompTIA.