Which of the Following Poses a Physical Security Risk

Which of the Following Poses a Physical Security Risk

Posting an access roster in public view is the answer supported by the Cyber Awareness flashcard results. It creates a physical security risk because people who should not have access may learn who is authorized to enter a place, work area, or facility.

The key idea is simple: a security problem does not need to involve a hacked computer. Information displayed in a public place can also help someone gain access, watch a person, or target a sensitive location.

The answer: posting an access roster in public view

The answer

An access roster is a list of people allowed to enter or use a particular area. It may include names, work details, access levels, or other information about authorized personnel.

Posting that list where anyone can see it exposes information that should be protected. An unauthorized person could read the roster, take a photo, or use it to learn who belongs in a restricted space.

That is why the answer to which of the following poses a physical security risk is:

> Posting an access roster in public view

The supplied Cyber Awareness results repeat this answer. They also explain the reason: public access to the roster can allow unauthorized people to gain sensitive information.

Why a public access roster creates a physical security risk

Physical security protects people, buildings, equipment, documents, and restricted areas. It includes the actions used to control who can enter a place and what information can be seen there.

A public roster weakens that control. Even if the roster is posted on paper and no computer is involved, it can reveal useful details to someone who should not have them.

For example, a person looking at the roster may learn:

  • Who is authorized to enter a room
  • Which employees work in a sensitive area
  • Who may be expected at a facility
  • Which names or badges could appear legitimate
  • Which people might be approached, followed, or impersonated

The roster itself may not contain passwords or computer data. It can still support a physical security problem by showing how access is organized.

This is the security principle to remember: public visibility can expose access information. A computer system does not have to be attacked for sensitive information to be misused.

Keeping the list away from public view is a practical best practice for physical security. The goal is to limit access information to people who have a valid need to see it.

How access rosters can expose sensitive information

A roster can seem harmless because it is only a list of names. Its risk comes from the context around those names.

If the list is posted near an entrance, reception desk, shared hallway, or other public location, someone may connect the names to a specific area. That person could then use the information to appear familiar with the workplace or to identify employees who have access.

The supplied results support the point that a public roster can help unauthorized persons gain sensitive information. They do not establish that every roster contains classified information or that every person who sees one will misuse it. The risk is that the information becomes available to people who have no reason to view it.

This is similar to other physical security concerns:

  • Shoulder surfing: watching someone read or enter sensitive information
  • Document capture: photographing or copying a document
  • Badge abuse: using an access badge improperly
  • Unaccounted visitors: allowing visitors to remain without proper control
  • Tailgating: following an authorized person through a secured entrance without using proper access

A roster can make some of these risks easier because it gives an outsider more information before they approach a person or location.

Open office areas and collateral classified spaces in the question wording

Some search results use wording about an open office area and a collateral classified space. That wording appears to be part of a question with answer choices, but the supplied results do not show every option or explain the full scenario.

The results do support one clear answer: posting an access roster in public view is the physical security risk identified by the Cyber Awareness materials.

The terms still help show why the setting matters:

  • An open office area may be visible or accessible to more people than a restricted room.
  • A collateral classified space is an area used for information classified at the collateral level, rather than a special-access area.

Because the complete question and all answer choices are not provided, it would be unsafe to claim more about that specific wording. Do not replace the supported answer with a guess about the room type. Focus on the action: making an access roster visible to the public creates the risk.

Physical security risks compared with cyber risks

Cyber risks usually involve computers, networks, accounts, software, or electronic information. Physical security risks involve the real-world places, objects, and people that support those systems.

The two areas can overlap, but they are not the same.

A malicious code attack, for example, involves harmful software. Malicious code may damage systems, change files, steal information, or interfere with normal operations. That is a cyber-related threat.

Posting an access roster in public view is different. No malicious code is needed. The problem begins when someone can see information about authorized access.

Other examples of physical security risks listed in the supplied results include:

  • Theft of devices
  • Theft or exposure of documents
  • Tailgating
  • Shoulder surfing
  • Badge misuse
  • Workstation tampering
  • Unattended removable media
  • Visitors who are not properly accounted for

These examples all involve something in the physical environment. A device may be stolen. A document may be photographed. A person may follow someone through a secured door. A workstation may be changed while its user is away.

Government-furnished equipment, or GFE, is another related Cyber Awareness topic. GFE refers to equipment provided for official work. Protecting it can involve physical security, such as keeping the device from being stolen or left unattended. That topic should not be confused with the specific access-roster question.

Other physical security risks mentioned in the search results

The broader results describe physical security as more than protecting a door or locking a cabinet.

They mention threats such as:

  • Active shooter attacks
  • Bombing
  • Unmanned aircraft
  • Vehicle ramming
  • Insider threats

They also mention everyday workplace risks, including theft, exposed paperwork, unauthorized entry, and tampering with equipment.

These examples vary in seriousness, but they share one feature: they affect a physical location, person, object, or access point. That is why an exposed roster belongs in the physical-security category even though the information on it may be written or printed.

A useful way to study the topic is to ask, “Could this help someone enter, target, steal from, observe, or interfere with a real place or object?” If the answer is yes, physical security may be involved.

How to remember the correct answer for the Cyber Awareness question

How to remember the correct answer for the Cyber Awareness question

Use the visibility test:

> If an access list is visible to people who do not need it, it creates a physical security risk.

The word public is the main clue. A roster that is kept under proper control is different from one posted where passersby or unauthorized visitors can read it.

You can also remember the connection this way:

Access information + public view = physical security risk.

Do not get distracted by answers that sound more technical. A question about physical security may not mention hacking, malware, or a network. It may focus on a paper list, a badge, a doorway, a visitor, or an unattended device.

For a quick study check:

  1. Identify what is exposed.
  2. Ask who can see or use it.
  3. Decide whether the exposure could help someone reach or target a protected place, person, or object.
  4. If an access roster is publicly displayed, choose that answer.

This reasoning is more useful than memorizing the wording alone. It can help you recognize similar questions that use different examples.

Related Cyber Awareness questions about personnel rosters and malicious code

A question about a personnel roster may sound similar to the access-roster question, but the exact answer depends on what the question asks and how the roster is handled.

The supplied results support keeping an access roster out of public view. They do not provide a complete answer key for every question about personnel rosters. Read the action carefully. A roster that is exposed, posted publicly, or shared with people who do not need it raises a physical-security or information-protection concern.

The same caution applies to questions about a malicious code attack. Malicious code is harmful software, so that question belongs to a different part of Cyber Awareness training. Do not choose it for the access-roster question simply because it sounds like a serious security event.

The supplied results also do not provide the answers to a 2026 Cyber Awareness Challenge exam. They support the answer to this specific question only: posting an access roster in public view. They also do not provide a complete list of 10 physical security measures or a full answer to every “best practice for physical security” quiz question.

Review your official Cyber Awareness training materials for exam-specific guidance. Keep the same rule in mind when you study: access rosters and other sensitive workplace information should not be left where the public can see them.

DH

Written by Dennis Haymon

Dennis Haymon is a security professional and manager at Safe & Sound Security LLC. With experience in security guard and patrol services, he shares practical information about protecting homes, businesses, and properties. Through Safe & Sound Security LLC, Dennis and the team provide security-focused guidance designed to help individuals and businesses better understand their security needs and available protection options.