2.3
Unit 2 · Securing Spaces

Protecting Physical Spaces

Topic 2.2 found the weaknesses. Now you're in the control studio: choosing the managerial policies and physical controls that prevent, deter, and limit physical attacks — and deciding which to fund first.

Physical access is a master key. If an adversary can stand in front of a device, many digital defenses no longer matter. This topic is about mitigation: matching the right control to a specific physical vulnerability, then layering controls so that defeating one still leaves several more in the way.

Two families of control do the work here — managerial controls (the rules and habits people follow) and physical controls (the hardware in the building). The exam expects you to tell them apart and to justify each choice.

Set the Rules

Awareness training, a workstation security policy, and a clean desk policy are managerial controls — they shape behavior.

2.3.A · Managerial

Harden the Building

Fencing, gates, bollards, locks, card readers, vestibules, and turnstiles control who gets where.

2.3.B · Physical

Spend Wisely

Prioritize mitigations by the severity of the risk and the cost of the fix — favor cost-effective wins.

2.3.B.8 · Prioritize
Scenario · Xtensr Labs Mitigation Planning

Xtensr Labs just finished assessing its physical vulnerabilities. As the mitigation lead, your job is to design the protections: write the workstation policy, plan the layered building defenses, train the staff, and recommend a funding order to leadership. Everything you build here ships in the security plan.

AP Learning Objectives

  • 2.3.AIdentify managerial controls related to physical security (training, workstation & clean desk policies).
  • 2.3.BDetermine mitigation strategies for risks from physical vulnerabilities, and prioritize them by severity and cost.
Big Idea

No single control is enough. A strong physical defense layers managerial rules and physical hardware from the perimeter inward, so an adversary who beats the fence still faces a locked door, a vestibule, a privacy screen, and a secured device — each one buying defenders time and limiting damage.

What you'll be able to do: classify a control as managerial or physical, match any control to the vulnerability it closes, build a workstation policy, design a layered building defense, choose the right access control for a space, and rank mitigations by cost and severity.

01
Core Concept

Choosing & Layering Controls

Mitigation isn't guesswork. There's a repeatable logic for picking a control, and a layering principle for arranging them.

To choose a control, a defender asks one question: how could an adversary take advantage of this vulnerability — and can I prevent, detect, or correct that attack? The answer points to the right control. A fence deters; a lock prevents; a card-reader log helps detect; a UPS corrects for a power loss.

Notice that controls also split by type. The rules people follow — training, the workstation policy, the clean desk policy — are managerial controls. The hardware in the walls — locks, bollards, vestibules — are physical controls. Disabling USB ports is a technical control that happens to close a physical attack path.

Diagram · Control selection logic

Vulnerability a physical weakness How could an adversary exploit it? Preventlocks, vestibules Detectcard-reader logs CorrectUPS, generators Chosen control A control should map to a real attack path — not be added at random.

The second principle is layering. Imagine an adversary heading for a server. They should have to cross the perimeter, enter the building, pass into a restricted area, reach the workstation, and finally the device itself — with a control standing guard at every boundary.

Diagram · Layered physical security

Adversary starts outside 1 Perimeter fencing · gates · bollards 2 Building Entry locks · card readers 3 Restricted Area vestibule · turnstile 4 Workstation privacy screen · lock device 5 Device cabinet lock · disabled USB Asset the target Each boundary is a chance to stop or slow the adversary.

Employee Awareness Training Lab

Lab · Managerial control

People are the first managerial control. For each moment at Xtensr Labs, choose the response trained employees should give.

On the floor

Score: 0 / 4

Concept Check

30 sec

Employee security awareness training is best classified as which type of control?

02
Key Vocabulary

The Control Catalog

Every control Xtensr Labs can deploy, grouped by what it does. Know the name, the purpose, and the type.

Managerial Controls (2.3.A)
ControlPurpose
Security awareness trainingTeaches staff to spot phishing, refuse to badge others into restricted areas, and prevent device theft.
Workstation security policyDefines how to protect a workspace; may set tiers based on the sensitivity of data handled there.
Clean desk policyRequires clearing sensitive documents off desks before leaving them unattended.
Physical & Related Controls (2.3.B)
ControlWhat it does
Fencing · gates · bollardsDeter adversaries from physically approaching or ramming the building.
LocksPrevent doors, server cabinets, and computers from being opened or stolen.
Card readersDeny unauthorized badges and record which badge entered where and when.
Access control vestibules · turnstilesStop an authorized person from admitting an unauthorized one (tailgating/piggybacking).
Privacy screenPhysical barrier that blocks others from viewing on-screen information.
Disabled USB portsTechnical control preventing external drives from loading malware onto a computer.
UPS · generatorsProvide backup power so critical devices stay available during an outage.
Tailgating Piggybacking Vestibule Clean Desk UPS Privacy Screen

Physical Control Matcher

Lab · 7 cases

A vulnerability has been found at Xtensr Labs. Choose the control that most directly addresses it.

Vulnerability report

Matched: 0 / 7
03
AP Exam Focus

What the Exam Rewards

This topic is pure Mitigate Risk — skills 2.A (identify controls and explain how they mitigate) and 2.B (determine layered controls that address a vulnerability).

Skill 2.A. Don't just name a control — explain how it mitigates the specific risk. "A vestibule helps" is weak; "a vestibule stops a badged employee from accidentally admitting an unauthorized person, closing the tailgating path to the lab" earns the point.

Skill 2.B. Strong answers layer controls. For a sensitive server, pair a deterrent (bollards/fence), an access control (card reader + vestibule), and a device-level control (cabinet lock, disabled USB).

Common MCQ traps

Calling training a "physical" control.

Training, workstation policy, and clean desk are managerial controls — they govern behavior, not the building.

"A card reader prevents tailgating."

A reader checks one badge; it can't stop a second person slipping through. Use a vestibule or turnstile for that.

"Spend on the most expensive fix first."

Prioritize by severity × cost. High-severity, low-cost fixes (a $20 lock) come before costly, low-severity ones.

Analyst note — Xtensr Labs: "Reception PC has open USB ports and connects to the internal network." A strong mitigation pairs a technical control (disable the USB ports to block malicious drives) with a managerial one (train reception staff not to accept unknown drives) — defense in depth across control types.

Access Control Decision Lab

Lab · Decide

Each entry point at Xtensr Labs needs the right control. Pick the single best fit for the requirement.

Requirement

Correct: 0 / 5
04
Worked Example

Build a Layered Physical Defense

The studio's flagship build. Add protection layers from the perimeter to the asset, then run a simulated intruder to see exactly where your defense holds.

Layered Physical Protection Builder

Lab · Mitigate (2.B)

Toggle each zone's controls on, then launch a simulated intruder. They're stopped at the outermost active zone — and every active zone behind it is a backup.

ReadyAll five zones are protected. Launch an intruder to test the layering.
AP reasoningThis is skill 2.B in action: layered controls that address a vulnerability. The value isn't any single zone — it's that defeating one still leaves the rest, so the asset stays protected and defenders gain time.
05
Common Mistakes

Misconceptions That Cost Points

Each is a planted wrong answer. Learn to see the trap.

"A lock and a vestibule do the same job."

A lock stops an unauthorized person from opening a door. A vestibule stops an authorized person from letting an unauthorized one in behind them.

"Card readers are a detection-only control."

They both prevent (deny bad badges) and aid detection (log who entered when). Many controls do more than one thing.

"A UPS protects data confidentiality."

A UPS protects availability — it keeps a device powered through an outage. Generators do the same at building scale.

"Disabling USB ports is a physical control."

It's a technical control (a device setting) that closes a physical attack path — malicious external drives.

"Clean desk policy is about tidiness."

It's a security measure: clearing sensitive documents so no one can read or steal them from an unattended desk.

"Fund the priciest control first for safety."

Prioritize by severity and cost. A cost-effective control should cost less than the expected loss it prevents.

06
Reference & Labs

Policies, Power & Priorities

Your quick-reference board, plus three labs to turn it into instinct.

Control · Type · Function
ControlTypePrimary function
Awareness trainingManagerialPreventative
Workstation / clean desk policyManagerialPreventative
Fencing · gates · bollardsPhysicalPreventative (deterrent)
LocksPhysicalPreventative
Card readersPhysicalPreventative + Detective
Vestibules · turnstilesPhysicalPreventative
Privacy screenPhysicalPreventative
Disabled USB portsTechnicalPreventative
UPS · generatorsPhysicalCorrective (availability)

Diagram · Workstation protection flow

Leaving your desk? Lock deviceno unauthorized use Clear deskhide sensitive docs Privacy screenblock shoulder-surfing On UPS / securepower + protected The everyday managerial routine that closes the most common physical gaps.

Workstation Security Policy Builder

Lab · Build

Select every measure that belongs in Xtensr Labs' workstation security policy, then generate it. Leave out anything that would weaken security.

Cost vs Severity Prioritization Board

Lab · Prioritize (2.3.B.8)

Leadership funds mitigations by severity of the risk and cost of the fix. Select a mitigation, then drop it in the right priority bin.

Do First

High severity · low cost

Schedule & Budget

High severity · high cost

Defer

Low severity

Placed: 0 / 6
07
Practice & Recall

Prove the Mitigation Plan

Five AP-style questions with instant feedback, then a snapshot to lock it in.

Mini AP-Style Quiz

Lab · 5 questions

Choose one answer per question, then submit for scored feedback with explanations.

You scored 0 / 5

Five Takeaways

1

Two control families. Managerial controls govern behavior (training, workstation & clean desk policies); physical controls harden the building.

2

Match control to attack path. Ask how the vulnerability could be exploited, then prevent, detect, or correct it.

3

Vestibules beat tailgating. Card readers check one badge; vestibules and turnstiles stop a second person slipping through.

4

Layer from perimeter to asset. Fence → locks → vestibule → workstation → device, so one failure isn't fatal.

5

Prioritize by severity and cost. Favor cost-effective fixes whose price is below the expected loss they prevent.

Managerial Control Physical Control Workstation Policy Clean Desk Bollards Card Reader Vestibule UPS Cost vs Severity

Final AP exam tip: when asked to mitigate a physical vulnerability, name the control, state its type (managerial / physical / technical), and explain how it closes the specific attack path. For full credit on layered-control prompts, give controls at more than one boundary.

One mistake to avoid: never assume one strong control is enough. A locked door is useless if an employee badges a stranger in — that's why managerial and physical controls must work together.

09
Section · 09

Practice — attempt these now.

AP-style assessments aligned to this lesson. Time them.

Topic Quiz 40 min 30 marks Pending

Ap Cyber U2 T3 Sec1 Topic

AP-style topic practice assessment

Start
FRQ Practice 18 min 8 marks Pending

Ap Cyber U2 T3 Sec2 Topic Frq

AP-style topic practice assessment

Start