ASIS PSP Practice Test Questions and Exam Dumps Part2 Q21-40

View Full ASIS PSP Exam Dumps and Practice Test Dumps

 

Question 21.

A security professional is designing protection for a facility where vehicle-borne threats are a significant concern. What should be considered when establishing an appropriate standoff distance?

  1. Only the number of employee vehicles
    2. Threat characteristics, asset vulnerability, site conditions, barrier capabilities, and required separation from critical assets
    3. Only the appearance of the property
    4. The shortest possible distance between parking and the building

Correct Answer: 2

Explanation:

Standoff distance creates separation between a potential vehicle-borne threat and a protected asset. The appropriate distance should be based on credible threat scenarios, building vulnerability, site geometry, operational requirements, and the performance of protective barriers. Security professionals should also consider legitimate traffic, emergency access, parking, and surrounding property limitations. Greater distance can reduce exposure in some scenarios, but site constraints may require additional protective measures. Standoff should therefore be determined through risk-based design rather than by applying an arbitrary distance to every facility.

Question 22.

What is the primary security purpose of a mantrap or security vestibule at a high-security entrance?

  1. To control passage so individuals can be authenticated before gaining access beyond the secured entrance
    2. To increase the speed of unrestricted visitor entry
    3. To replace all identity verification procedures
    4. To provide emergency parking

Correct Answer: 1

Explanation:

A mantrap or security vestibule uses sequentially controlled doors to regulate movement through a high-security entrance. Typically, an individual enters the controlled space and must satisfy authentication or authorization requirements before the second door permits further access. Properly designed systems can help reduce tailgating and unauthorized passage. Procedures must also address life safety, emergency egress, accessibility, and operational requirements. A mantrap is one component of layered access control and does not eliminate the need for appropriate credential management, monitoring, or response procedures.

Question 23.

A security manager discovers that employees who transferred to new departments still retain access to sensitive areas required by their previous jobs. What should be done?

  1. Leave the privileges unchanged for convenience
    2. Give the employees additional access
    3. Review and adjust access privileges to match current job responsibilities
    4. Replace all access control equipment

Correct Answer: 3

Explanation:

Physical access privileges should reflect current business responsibilities. When employees transfer, change roles, or no longer require access to a sensitive area, unnecessary privileges should be removed promptly. A well-managed credential lifecycle includes periodic access reviews and event-driven reviews following personnel changes. Retaining obsolete privileges violates least-privilege principles and increases exposure because more individuals can enter sensitive locations than operationally necessary. Coordination among security, human resources, managers, and access-control administrators can help keep authorization information current.

Question 24.

An organization wants its perimeter intrusion detection system to provide useful protection. Which arrangement is most important?

  1. Detection without any alarm monitoring
    2. Sensors installed without testing
    3. Alarms that are recorded but never assessed
    4. Detection integrated with timely assessment, communication, and an appropriate response capability

Correct Answer: 4

Explanation:

Detection provides value when an alarm leads to assessment and, when appropriate, an effective response. Sensors alone cannot determine whether an event represents an actual intrusion, and an alarm that nobody evaluates may provide little practical protection. The security system should therefore connect detection with monitoring, assessment tools such as surveillance, reliable communications, and response procedures. The complete protection timeline should provide enough opportunity for responders to intervene before an adversary achieves the intended objective. Integration is fundamental to effective physical protection.

Question 25.

What is the primary purpose of a threat assessment within physical security planning?

  1. To identify and evaluate credible sources and types of harm that could affect organizational assets
    2. To determine employee salaries
    3. To select a camera manufacturer
    4. To guarantee that every possible threat is eliminated

Correct Answer: 1

Explanation:

Threat assessment helps the organization understand potential sources of intentional, accidental, or environmental harm relevant to its assets and operations. Depending on the context, the analyst may consider adversary capabilities and intent, historical incidents, local conditions, intelligence, crime information, natural hazards, and other indicators. Threat information is combined with vulnerability and consequence considerations to support risk decisions. A threat assessment cannot guarantee that every future event will be predicted, so it should be periodically reviewed as conditions and available information change.

Question 26.

A security professional is evaluating locks for a sensitive interior area. Which factor should most strongly influence the selection?

  1. The lock’s appearance
    2. Required resistance, access-control needs, life-safety requirements, operating environment, and assessed risk
    3. The manufacturer’s advertising budget
    4. Whether the lock is the least expensive available

Correct Answer: 2

Explanation:

Lock selection should be based on the security function the opening must provide. Relevant factors include required resistance to unauthorized entry, credential or key management, door and frame construction, emergency egress, fire and life-safety requirements, frequency of use, environmental conditions, and integration with monitoring or electronic access control. An expensive lock installed on a weak door or frame may provide little additional protection. The entire opening should therefore be evaluated as a system and aligned with the risk associated with the protected area.

Question 27.

A security manager notices that a camera produces clear images during daylight but unusable images at night. What should be evaluated first?

  1. Employee identification badges
    2. Perimeter fencing height
    3. Nighttime illumination, camera sensitivity, positioning, exposure settings, and scene conditions
    4. Visitor registration forms

Correct Answer: 3

Explanation:

Video surveillance performance depends heavily on lighting and environmental conditions. A camera that performs well during daylight may not provide usable nighttime images if illumination is inadequate, bright lights create glare, or the camera’s low-light capability is unsuitable. The professional should evaluate the complete scene, including light direction, contrast, shadows, camera positioning, lens characteristics, and configuration. Security video should be tested under the actual conditions in which it is expected to operate rather than assuming daytime performance represents around-the-clock effectiveness.

Question 28.

A facility has a high-security door, but the adjacent wall can be penetrated much more easily. What principle should guide corrective action?

  1. Increase only the door’s resistance
    2. Add more identification badges
    3. Ignore the wall because the door is the official entrance
    4. Balance protection so surrounding construction does not provide an easier bypass route

Correct Answer: 4

Explanation:

Physical protection is only as effective as the pathways available to an adversary. Strengthening one component excessively while leaving adjacent walls, ceilings, windows, or other openings substantially weaker can allow the protected element to be bypassed. Security professionals should evaluate the complete boundary and provide protection appropriate to credible attack paths. This does not require every component to be identical, but resistance should be coordinated with detection and response requirements. Balanced protection helps ensure investments contribute meaningfully to the overall protective system.

Question 29.

Why should emergency egress requirements be considered when designing physical access controls?

  1. Security controls must protect assets while still supporting applicable life-safety and emergency evacuation requirements.
    2. Emergency egress is unrelated to physical security.
    3. Restricted areas should never permit emergency exit.
    4. Access control requirements always override life safety.

Correct Answer: 1

Explanation:

Physical security controls should not create unacceptable hazards during fires, emergencies, or evacuations. Doors, locking systems, turnstiles, and other controls must be coordinated with applicable life-safety requirements and operational emergency plans. Security professionals should work with relevant facility, safety, engineering, and code specialists when necessary. The objective is to maintain appropriate protection against unauthorized access while ensuring occupants can evacuate as required. Security and life safety therefore need integrated design rather than independent systems that may conflict during an emergency.

Question 30.

A security professional wants to determine whether a newly installed intrusion sensor detects activity throughout its intended coverage area. What should be done?

  1. Assume factory specifications guarantee site performance
    2. Conduct appropriate acceptance and functional testing under realistic site conditions
    3. Wait for an actual intrusion
    4. Evaluate only the sensor’s purchase price

Correct Answer: 2

Explanation:

Security equipment should be tested after installation to confirm that actual performance meets design requirements. Sensor effectiveness can be affected by mounting, environmental conditions, obstructions, configuration, site geometry, and integration with other systems. Functional testing should verify intended detection coverage and alarm communication while also considering nuisance or false alarm behavior. Results should be documented and deficiencies corrected. Periodic retesting may also be necessary because equipment and site conditions can change after initial acceptance.

Question 31.

A facility contains several assets with substantially different levels of criticality. How should physical security controls generally be allocated?

  1. Every asset should receive identical protection
    2. The least critical asset should receive the strongest protection
    3. Protection should be proportionate to assessed risk, asset criticality, consequences, and operational requirements
    4. Controls should be assigned randomly

Correct Answer: 3

Explanation:

Risk-based security recognizes that organizational assets do not necessarily require identical protection. Critical assets whose compromise would produce severe consequences may justify stronger or additional safeguards, while lower-risk assets may require fewer controls. This supports efficient use of security resources and can create progressively restricted security zones. The organization should consider threats, vulnerabilities, consequences, operational requirements, and applicable obligations when establishing protection levels. Uniform controls can waste resources in some areas while leaving high-value assets inadequately protected.

Question 32.

A guard receives an alarm from a restricted storage area. What should the guard do according to an effective security program?

  1. Ignore the alarm unless several more occur
    2. Immediately disable the sensor
    3. Assume the alarm is false
    4. Follow established assessment, communication, and response procedures appropriate to the alarm

Correct Answer: 4

Explanation:

Alarm response should follow established procedures rather than assumptions. The guard may need to assess available camera views, communicate with a control center or supervisor, dispatch appropriate personnel, or initiate emergency procedures depending on the event and organizational plan. Standardized response supports consistency and reduces delays during potentially serious incidents. Procedures should also account for responder safety and escalation. After the event, alarm information can be documented and reviewed to determine whether equipment, procedures, or protective measures require improvement.

Question 33.

What is an important security benefit of dividing a facility into progressively restricted zones?

  1. Access can become more restrictive as individuals move closer to increasingly sensitive assets.
    2. Every employee receives unrestricted movement.
    3. Interior access control becomes unnecessary.
    4. Perimeter security can be eliminated.

Correct Answer: 1

Explanation:

Security zoning supports defense in depth by creating layers with different access requirements. A public reception area, employee workspace, restricted operational area, and high-security asset room may each require progressively stronger authorization. This reduces unnecessary access to sensitive assets and creates additional opportunities for detection and control before an unauthorized individual reaches a critical target. Zones should reflect operational needs and risk rather than being created arbitrarily. Access rights, barriers, monitoring, and procedures can then be aligned with each zone’s security level.

Question 34.

A security manager wants to improve key control for a facility that still uses mechanical locks. Which practice is most appropriate?

  1. Allow employees to duplicate keys whenever needed
    2. Maintain controlled issuance, inventories, authorization records, return procedures, and periodic audits
    3. Label every key with the exact sensitive room it opens
    4. Store spare master keys in an unlocked desk

Correct Answer: 2

Explanation:

Mechanical keys require lifecycle controls just as electronic credentials do. The organization should know which keys exist, who is authorized to possess them, when they were issued, and whether they were returned. Duplication should be controlled, and sensitive master or grand-master keys require particularly strong protection. Periodic audits can identify missing or unnecessary keys. When keys are lost or not returned, the organization should assess the resulting exposure and determine whether rekeying or another corrective action is appropriate.

Question 35.

A security professional is reviewing the placement of landscaping near a building. Which physical security concern is most relevant?

  1. Whether every plant has the same height
    2. Whether landscaping is inexpensive to maintain
    3. Whether vegetation creates concealment, blocks surveillance, interferes with lighting, or provides climbing opportunities
    4. Whether employees prefer flowering plants

Correct Answer: 3

Explanation:

Landscaping can influence security by affecting visibility, surveillance, access, and concealment. Dense vegetation near entrances or windows may provide hiding locations, while trees or structures can create climbing opportunities or obstruct cameras and lighting. Security-conscious landscaping should support natural surveillance and clear observation without unnecessarily compromising the appearance or use of the property. Conditions also change as vegetation grows, so periodic maintenance and review are important. Landscaping should be considered as part of the overall site security environment.

Question 36.

An organization plans to place a security control center in a vulnerable ground-floor room directly accessible from a public lobby. What should the security professional recommend?

  1. Keep the location because public access is convenient
    2. Remove all security monitoring equipment
    3. Display control-center operations to visitors
    4. Evaluate relocation or additional protection based on the control center’s criticality, threats, access, resilience, and operational needs

Correct Answer: 4

Explanation:

A security control center may support alarms, surveillance, communications, access control, and incident coordination, making it a potentially critical asset itself. Its location should therefore be evaluated for unauthorized access, physical attack, environmental hazards, communications reliability, backup power, and operational continuity. A publicly accessible location may require additional protective measures or relocation. The objective is not simply to hide the room but to ensure that the organization’s central security functions remain appropriately protected and available during incidents.

Question 37.

Why should physical security incidents and near misses be analyzed?

  1. They can reveal weaknesses, trends, control failures, and opportunities to improve the security program.
    2. Only incidents involving financial loss provide useful information.
    3. Near misses should never be documented.
    4. Incident analysis eliminates the need for risk assessments.

Correct Answer: 1

Explanation:

Incidents and near misses provide real-world evidence about how threats, vulnerabilities, people, and security controls interact. Analysis can reveal recurring locations, procedural weaknesses, equipment failures, delayed responses, or emerging threat patterns. Near misses are particularly valuable because they may expose weaknesses before a serious loss occurs. Findings can inform corrective actions, training, system modifications, and updated risk assessments. Incident analysis complements broader security planning by providing operational evidence about whether existing protective measures perform as intended.

Question 38.

A company uses temporary badges for contractors. Which control is most important when a contractor’s assignment ends?

  1. Allow the badge to remain active in case the contractor returns
    2. Promptly recover or invalidate the credential and remove access that is no longer authorized
    3. Convert the badge automatically into an employee credential
    4. Transfer the badge to another contractor without updating records

Correct Answer: 2

Explanation:

Access should end when the legitimate business need ends. Contractor credentials that remain active after assignments are completed create unnecessary exposure, particularly if the physical badge is not recovered. Offboarding procedures should ensure that credentials, keys, and other access mechanisms are returned or invalidated promptly and that authorization records are updated. Coordination among contract managers, sponsors, human resources, and security can improve timely termination. Periodic audits can also identify active credentials that no longer correspond to valid personnel or business needs.

Question 39.

A security professional is evaluating a perimeter camera system. Which measure best demonstrates whether the cameras support the intended security objective?

  1. The total number of cameras purchased
    2. The manufacturer’s market share
    3. Whether required areas and targets can be observed with sufficient image quality under expected operating conditions
    4. Whether all cameras use the same model number

Correct Answer: 3

Explanation:

Camera effectiveness should be evaluated against the surveillance task rather than equipment quantity. A system intended to detect activity, assess alarms, recognize individuals, or support investigations requires image quality and coverage appropriate to those objectives. Lighting, distance, angle, obstructions, weather, resolution, lens selection, and recording configuration can all affect performance. Testing under expected day and night conditions provides stronger evidence than specifications alone. A smaller well-designed system may provide better security value than a larger system with poor coverage or unusable images.

Question 40.

A facility’s risk assessment identifies a significant vulnerability, but management decides that the cost of further mitigation exceeds the organization’s risk tolerance considerations and formally accepts the remaining exposure. What has occurred?

  1. Risk avoidance
    2. Risk transfer
    3. Threat elimination
    4. Risk acceptance

Correct Answer: 4

Explanation:

Risk acceptance occurs when authorized management knowingly decides to retain a level of residual risk rather than implement additional mitigation. The decision should be informed by the nature of the threat, vulnerabilities, potential consequences, existing controls, mitigation costs, and organizational risk tolerance. Acceptance does not mean the risk disappears. Significant accepted risks may still require documentation, monitoring, and periodic reassessment because conditions can change. Security professionals provide analysis and recommendations, while appropriate organizational authorities make risk acceptance decisions.