Protecting Physical Spaces
Topic 2.2 found the weaknesses. Now you're in the control studio: choosing the managerial policies and physical controls that prevent, deter, and limit physical attacks — and deciding which to fund first.
Physical access is a master key. If an adversary can stand in front of a device, many digital defenses no longer matter. This topic is about mitigation: matching the right control to a specific physical vulnerability, then layering controls so that defeating one still leaves several more in the way.
Two families of control do the work here — managerial controls (the rules and habits people follow) and physical controls (the hardware in the building). The exam expects you to tell them apart and to justify each choice.
Set the Rules
Awareness training, a workstation security policy, and a clean desk policy are managerial controls — they shape behavior.
2.3.A · ManagerialHarden the Building
Fencing, gates, bollards, locks, card readers, vestibules, and turnstiles control who gets where.
2.3.B · PhysicalSpend Wisely
Prioritize mitigations by the severity of the risk and the cost of the fix — favor cost-effective wins.
2.3.B.8 · PrioritizeXtensr Labs just finished assessing its physical vulnerabilities. As the mitigation lead, your job is to design the protections: write the workstation policy, plan the layered building defenses, train the staff, and recommend a funding order to leadership. Everything you build here ships in the security plan.
AP Learning Objectives
- 2.3.AIdentify managerial controls related to physical security (training, workstation & clean desk policies).
- 2.3.BDetermine mitigation strategies for risks from physical vulnerabilities, and prioritize them by severity and cost.
No single control is enough. A strong physical defense layers managerial rules and physical hardware from the perimeter inward, so an adversary who beats the fence still faces a locked door, a vestibule, a privacy screen, and a secured device — each one buying defenders time and limiting damage.
What you'll be able to do: classify a control as managerial or physical, match any control to the vulnerability it closes, build a workstation policy, design a layered building defense, choose the right access control for a space, and rank mitigations by cost and severity.
Choosing & Layering Controls
Mitigation isn't guesswork. There's a repeatable logic for picking a control, and a layering principle for arranging them.
To choose a control, a defender asks one question: how could an adversary take advantage of this vulnerability — and can I prevent, detect, or correct that attack? The answer points to the right control. A fence deters; a lock prevents; a card-reader log helps detect; a UPS corrects for a power loss.
Notice that controls also split by type. The rules people follow — training, the workstation policy, the clean desk policy — are managerial controls. The hardware in the walls — locks, bollards, vestibules — are physical controls. Disabling USB ports is a technical control that happens to close a physical attack path.
Diagram · Control selection logic
The second principle is layering. Imagine an adversary heading for a server. They should have to cross the perimeter, enter the building, pass into a restricted area, reach the workstation, and finally the device itself — with a control standing guard at every boundary.
Diagram · Layered physical security
Employee Awareness Training Lab
Lab · Managerial controlPeople are the first managerial control. For each moment at Xtensr Labs, choose the response trained employees should give.
Concept Check
30 secEmployee security awareness training is best classified as which type of control?
The Control Catalog
Every control Xtensr Labs can deploy, grouped by what it does. Know the name, the purpose, and the type.
| Control | Purpose |
|---|---|
| Security awareness training | Teaches staff to spot phishing, refuse to badge others into restricted areas, and prevent device theft. |
| Workstation security policy | Defines how to protect a workspace; may set tiers based on the sensitivity of data handled there. |
| Clean desk policy | Requires clearing sensitive documents off desks before leaving them unattended. |
| Control | What it does |
|---|---|
| Fencing · gates · bollards | Deter adversaries from physically approaching or ramming the building. |
| Locks | Prevent doors, server cabinets, and computers from being opened or stolen. |
| Card readers | Deny unauthorized badges and record which badge entered where and when. |
| Access control vestibules · turnstiles | Stop an authorized person from admitting an unauthorized one (tailgating/piggybacking). |
| Privacy screen | Physical barrier that blocks others from viewing on-screen information. |
| Disabled USB ports | Technical control preventing external drives from loading malware onto a computer. |
| UPS · generators | Provide backup power so critical devices stay available during an outage. |
Physical Control Matcher
Lab · 7 casesA vulnerability has been found at Xtensr Labs. Choose the control that most directly addresses it.
What the Exam Rewards
This topic is pure Mitigate Risk — skills 2.A (identify controls and explain how they mitigate) and 2.B (determine layered controls that address a vulnerability).
Skill 2.A. Don't just name a control — explain how it mitigates the specific risk. "A vestibule helps" is weak; "a vestibule stops a badged employee from accidentally admitting an unauthorized person, closing the tailgating path to the lab" earns the point.
Skill 2.B. Strong answers layer controls. For a sensitive server, pair a deterrent (bollards/fence), an access control (card reader + vestibule), and a device-level control (cabinet lock, disabled USB).
Common MCQ traps
Calling training a "physical" control.
Training, workstation policy, and clean desk are managerial controls — they govern behavior, not the building.
"A card reader prevents tailgating."
A reader checks one badge; it can't stop a second person slipping through. Use a vestibule or turnstile for that.
"Spend on the most expensive fix first."
Prioritize by severity × cost. High-severity, low-cost fixes (a $20 lock) come before costly, low-severity ones.
Analyst note — Xtensr Labs: "Reception PC has open USB ports and connects to the internal network." A strong mitigation pairs a technical control (disable the USB ports to block malicious drives) with a managerial one (train reception staff not to accept unknown drives) — defense in depth across control types.
Access Control Decision Lab
Lab · DecideEach entry point at Xtensr Labs needs the right control. Pick the single best fit for the requirement.
Build a Layered Physical Defense
The studio's flagship build. Add protection layers from the perimeter to the asset, then run a simulated intruder to see exactly where your defense holds.
Layered Physical Protection Builder
Lab · Mitigate (2.B)Toggle each zone's controls on, then launch a simulated intruder. They're stopped at the outermost active zone — and every active zone behind it is a backup.
Misconceptions That Cost Points
Each is a planted wrong answer. Learn to see the trap.
"A lock and a vestibule do the same job."
A lock stops an unauthorized person from opening a door. A vestibule stops an authorized person from letting an unauthorized one in behind them.
"Card readers are a detection-only control."
They both prevent (deny bad badges) and aid detection (log who entered when). Many controls do more than one thing.
"A UPS protects data confidentiality."
A UPS protects availability — it keeps a device powered through an outage. Generators do the same at building scale.
"Disabling USB ports is a physical control."
It's a technical control (a device setting) that closes a physical attack path — malicious external drives.
"Clean desk policy is about tidiness."
It's a security measure: clearing sensitive documents so no one can read or steal them from an unattended desk.
"Fund the priciest control first for safety."
Prioritize by severity and cost. A cost-effective control should cost less than the expected loss it prevents.
Policies, Power & Priorities
Your quick-reference board, plus three labs to turn it into instinct.
| Control | Type | Primary function |
|---|---|---|
| Awareness training | Managerial | Preventative |
| Workstation / clean desk policy | Managerial | Preventative |
| Fencing · gates · bollards | Physical | Preventative (deterrent) |
| Locks | Physical | Preventative |
| Card readers | Physical | Preventative + Detective |
| Vestibules · turnstiles | Physical | Preventative |
| Privacy screen | Physical | Preventative |
| Disabled USB ports | Technical | Preventative |
| UPS · generators | Physical | Corrective (availability) |
Diagram · Workstation protection flow
Workstation Security Policy Builder
Lab · BuildSelect every measure that belongs in Xtensr Labs' workstation security policy, then generate it. Leave out anything that would weaken security.
Cost vs Severity Prioritization Board
Lab · Prioritize (2.3.B.8)Leadership funds mitigations by severity of the risk and cost of the fix. Select a mitigation, then drop it in the right priority bin.
Do First
High severity · low cost
Schedule & Budget
High severity · high cost
Defer
Low severity
Prove the Mitigation Plan
Five AP-style questions with instant feedback, then a snapshot to lock it in.
Mini AP-Style Quiz
Lab · 5 questionsChoose one answer per question, then submit for scored feedback with explanations.
Five Takeaways
Two control families. Managerial controls govern behavior (training, workstation & clean desk policies); physical controls harden the building.
Match control to attack path. Ask how the vulnerability could be exploited, then prevent, detect, or correct it.
Vestibules beat tailgating. Card readers check one badge; vestibules and turnstiles stop a second person slipping through.
Layer from perimeter to asset. Fence → locks → vestibule → workstation → device, so one failure isn't fatal.
Prioritize by severity and cost. Favor cost-effective fixes whose price is below the expected loss they prevent.
Final AP exam tip: when asked to mitigate a physical vulnerability, name the control, state its type (managerial / physical / technical), and explain how it closes the specific attack path. For full credit on layered-control prompts, give controls at more than one boundary.
One mistake to avoid: never assume one strong control is enough. A locked door is useless if an employee badges a stranger in — that's why managerial and physical controls must work together.
Practice — attempt these now.
AP-style assessments aligned to this lesson. Time them.