Assess physical layers on premises you own, and tune a biometric threshold

applied · 50 min · Objective 3.2

Task

Walk the layers of physical security -- perimeter, building, room and the equipment itself -- on premises you are entitled to assess, and record the control at each layer and its weakest point. Then take a set of biometric match scores, compute the false acceptance and false rejection rates at several thresholds, and find the crossover error rate.

Steps

  1. Write lab/physical/layers.csv with header layer,control,who_can_pass,weakest_point for perimeter, building entrance, the room your computers are in, and the equipment itself.
  2. Record in lab/physical/tailgating.txt where, at your chosen premises, someone could follow an authorised person through, and what control would prevent it.
  3. Create lab/physical/scores.csv with header who,score and these synthetic rows: genuine users scoring 91, 88, 95, 72, 84, 90, 67, 93, 86, 79, and impostors scoring 35, 52, 61, 44, 70, 28, 58, 75, 40, 49.
  4. Write lab/physical/rates.sh that, for thresholds 50 to 90 in steps of 5, prints the threshold, the false acceptance rate (impostors at or above it) and the false rejection rate (genuine users below it), as percentages, one threshold per line separated by spaces, such as 70 20 10. Save its output to lab/physical/rates.txt.
  5. Record in lab/physical/crossover.txt the threshold where the two rates are closest, and which threshold you would choose for a server room and why.

Verify

These checks run in a POSIX shell: Terminal on macOS or Linux, and on Windows Git Bash (it comes with Git for Windows) or WSL. A stock Windows PowerShell or Command Prompt has no awk or grep, so there the first line fails.

awk -F, 'NR>1 && NF==4 {n++} END {print n" layer(s) assessed"}' lab/physical/layers.csv
grep -c . lab/physical/tailgating.txt
awk -F, 'NR>1 {c[$1]++} END {for (w in c) print w": "c[w]}' lab/physical/scores.csv
grep -E '^70[^0-9]' lab/physical/rates.txt
grep -Eic 'false accept|FAR|lower|stricter|higher' lab/physical/crossover.txt

Four layers assessed, ten genuine and ten impostor scores. At a threshold of 70, two impostors (70 and 75) are accepted and one genuine user (67) is rejected: FAR 20 per cent, FRR 10 per cent. The rates cross between 70 and 75. A server room would choose a stricter threshold, accepting more false rejections to keep false acceptances down.

Notes

Real systems publish FAR and FRR curves from far larger test sets, and the CER is how products are compared. The trade-off is the same at any scale: sensitivity moves errors from one column to the other and never removes them.

This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.