Search Header Logo
Physical Security

Physical Security

Assessment

Presentation

Instructional Technology

10th Grade

Practice Problem

Medium

Created by

Charles Carr

Used 10+ times

FREE Resource

17 Slides • 38 Questions

1

Physical Security, Site Security, and Enterprise Security

Make sure to take notes!

2

  • External Perimeter

  • ​Internal Perimeter

  • Secure Areas

Access control measures should be used to keep unauthorized persons out of all three areas.

Three Main Areas

Physical security involves implementing good controls and security practices to secure the site, its surroundings, and the devices inside.

Site Security

Physical Security

3

Multiple Select

What are the 3 areas of a site that should be secured when considering physical security? Choose 3.

1

External perimeter

2

Internal Perimeter

3

Secure Areas

4

Virtual perimeter

5

Secret Areas

4

Multiple Choice

Access control measures should be used to keep unauthorized persons out of all three areas.

1

True

2

False

5

  • Fences

  • ​Guards

  • Gates

  • Security Cameras

  • Sensors

Access Control

Includes all entries to the building and the surrounding area.

External Perimeter

Site Security

6

Secure Areas are different for every organization but includes rooms that have restricted access such as a locked server room to which only certain people have key.

Secure Areas

Includes areas just inside the entrances. Controls could include a guard station, cameras, guide rails, swipeable badges, visitor's logs.

Internal Perimeter

Site Security

7

​People throw away (Personally Identifiable Informaiton) PII and Data all the time. Shred it before disposal to prevent unauthorized access.

​​Dumpster Diving

​Someone unauthorized sneaks in behind an authorized person without their knowledge. Time for a mantrap!

​​Tailgaiting

​An authorized person knowingly lets a person bypass security measures. Employee training and enforcement is needed.

​​Piggybacking

​Pretending to be a person with proper authorization or credentials.

​​Impersonation

media
media
media
media

Common Threats to Site Security

8

Match

Match the following

Digging through trash to find personal information that can be used in future attacks

Closely following an authorized person to gain access to a location without their knowledge.

A authorized person allows you to follow them into a location you have not been authorized to enter.

A person disguises themselves to look a authorized person to gain unauthorized access.

Looking over a person's shoulder without their knowledge while they are on the phone or PC to get personal information.

Dumpster Diving

Tailgaiting

Piggybacking

Impersonaton

Shoulder Surfing

9

Defense in Depth

  • Providing multiple layers of security controls

  • Having controls at the external perimeter, internal perimeter, and Secure Areas of the building can help deter, prevent, or detect and attack.

  • These controls could include door locks, badges, access cards, guard station, log books, and visitor lists. etc.

10

Multiple Choice

A potential attacker could obtain PII through dumpster diving. What is PII stand for?

1

Personally Identifiable Information

2

Private Individual Information

3

Possibly Incriminating Information

4

People Integrity Invitation

11

Multiple Choice

An authorized person knowingly lets a person bypass security measures.

1

Tailgating

2

Piggybacking

3

Impersonation

4

Dumpster Diving

12

Multiple Choice

At a hospital, a visitor slips into a closet and puts on a white coat and stethoscope around their neck. They attempt to enter an area designated for hospital personnel only. This is an example of ______________.

1

Dumpster Diving

2

Impersonation

3

Tailgaiting

4

Piggybacking

13

Fill in the Blanks

14

Multiple Choice

Someone unauthorized sneaks in behind an authorized person without their knowledge.

1

Tailgaiting

2

Piggybacking

3

Dumpster Diving

4

Impersonation

15

  • ​Physical control

  • ​Gateway between external perimeter and internal perimeter or between unsecure and secure parts of the building.

  • ​Used to capture people who enter the building illegally (i.e. through tailgating)

  • ​Person caught in mantrap will need to be released by someone with the proper authority (usually after being questioned.

Mantraps

media

16

17

Multiple Select

Mantraps are designed to prevent what type of threat activities. Pick 2.

1

Piggybacking

2

Impersonation

3

Dumpster Diving

4

Tailgaiting

5

Phishing

18

  • Secure removable devices like thumb drives, memory card reader, flash drives, portable HDs and SSDs.

  • Bitlocker To Go - an app that can encrypt portable drives

Removable Drives

  • Physical locks

  • Kensingtion Locks - Used to block the use of USB ports and other peripheral ports

  • No external media allowed

  • Bitlocker - Encrypt drives

PCs and Laptops

Computer Security

19

Fill in the Blanks

20

Multiple Choice

This can be used to encrypt portable drives

1

Bitlocker to go

2

Mobile Crypt

3

Moving Shadow

4

Cellblock To Go

21

Mobile Device Security

  • Laptops

    • Locking Stations and Security Cables

    • Docking Station

  • Mobile Phones

    • Should be Password/Pin Protected

    • Mobile Device Management Software (i.e. MS Intune)

      • Device can be wiped remotely if lost or stolen

22

Multiple Choice

______________ is an example of Mobile Device Management Software.

1

MS Azure

2

MS Defender

3

MS Intune

4

MS Outlook

23

Antivirus software will usually catch a software based keylogger.

Security Controls

  • Wireless keyboards may be vulnerable to this type of malware

  • Can be used to record keystrokes of Usernames/Passwords which can lead to unauthorized access

Be Aware

Keylogger

24

Multiple Choice

Wireless keyboards are susceptible to what type of malware?

1

Trojan Horse Viruses

2

Qwerty Worms

3

Keyloggers

4

Backdoor Viruses

5

DDOS attacks

25

Administrative Controls

Examples of Administrative Policies

  • Policies

    • Acceptable Use Policy (AUP)

    • Clean Desk Policy (CDP)

  • Procedures

    • Incident Response Procedure (IRP)

  • Guidelines

​Policies, Procedures and Guidelines designed and enforced to reduce risk.

26

Administrative Controls

Mitigate the Human Risk

  • Employees are the biggest risk related to the Cybersecurity of an organization.

  • Policies, procedures, and guidelines are designed to mitigate human risk.

  • Many attacks are designed to take advantage of human error. (i.e. Phishing attack)

  • Communication, Training, and Consistent Implementation are ways to reduce human error.

27

Multiple Choice

Policies, procedures, and guidelines are designed to eliminate human risk

1

True

2

False

28

Secure this Space

What is wrong with this desk?

On the next slide you will see the desk of an employee who is putting his organization at risk. Describe each security risk caused by this employee's desk then on the next slide suggest ways to mitigate the risk (fix the problem).

media

29

media

30

Open Ended

Question image

Describe the security risk marked as #1.

31

Open Ended

Question image

How would you mitigate risk #1.

32

Open Ended

Question image

Describe the security risk marked as #2.

33

Open Ended

Question image

How would you mitigate risk #2.

34

Open Ended

Question image

Describe the security risk marked as #3.

35

Open Ended

Question image

How would you mitigate risk #3.

36

Open Ended

Question image

Describe the security risk marked as #4.

37

Open Ended

Question image

How would you mitigate risk #4.

38

Open Ended

Question image

Describe the security risk marked as #5.

39

Open Ended

Question image

How would you mitigate risk #5.

40

Open Ended

Question image

Describe the security risk marked as #6.

41

Open Ended

Question image

How would you mitigate risk #6.

42

Open Ended

Question image

Describe the security risk marked as #7.

43

Open Ended

Question image

How would you mitigate risk #7.

44

Open Ended

Question image

Describe the security risk marked as #8.

45

Open Ended

Question image

How would you mitigate risk #8?

46

Open Ended

Question image

Describe the security risk marked as #9.

47

Open Ended

Question image

How would you mitigate risk #9?

48

Open Ended

Question image

Describe the security risk marked as #10.

49

Open Ended

Question image

How would you mitigate risk #10?

50

media
media
media

Intrusion Detection System

​Can detect unauthorized access and alert security personnel.

IDS

Intrusion Prevention System​

Can detect an intrusion like and IDS but can also automatically take steps to prevent further access by attacker.

​​IPS

​Can be used to filter incoming and outcoming traffic by limiting certain ports and protocols

​​Firewall

Technical Controls

51

Multiple Choice

Can detect unauthorized access and alert security personnel, but cannot take steps to stop the attacker.

1

IDS

2

DSI

3

Firewall

4

IPS

5

SPI

52

Multiple Choice

Can be used to filter incoming and outcoming traffic by limiting certain ports and protocols

1

IDS

2

DSI

3

Firewall

4

IPS

5

VPN

53

Multiple Choice

Can detect unauthorized access and alert security personnel, and can also take steps to stop the attacker.

1

IDS

2

DSI

3

Firewall

4

IPS

5

Sunflower

54

Open Ended

Describe the main difference between and IDS and an IPS.

55

media

Congratulations. You have completed this lesson. Did you take notes?

Lesson Completed!

Physical Security, Site Security, and Enterprise Security

Make sure to take notes!

Show answer

Auto Play

Slide 1 / 55

SLIDE