View Full ASIS PSP Exam Dumps and Practice Test Dumps
Question 61.
A security professional is assessing the protection of a facility’s rooftop equipment. What should receive particular attention?
- Only the appearance of rooftop structures
2. Access routes, ladders, adjacent structures, roof hatches, critical equipment, detection, and unauthorized climbing opportunities
3. Only the building’s interior doors
4. Employee parking assignments
Correct Answer: 2
Explanation:
Rooftops can provide alternative access paths that may receive less attention than ground-level entrances. The security professional should examine ladders, fire escapes, adjacent buildings, trees, roof hatches, maintenance routes, and other means of reaching the roof. Critical communications, HVAC, power, or security equipment located there may also require protection. Controls should reflect the assessed risk and may include locks, barriers, access restrictions, detection, surveillance, or procedural measures. A complete physical security assessment considers all practical approaches to protected assets.
Question 62.
What is the primary purpose of natural surveillance within CPTED principles?
- To increase opportunities for legitimate users and observers to see activities occurring in an area
2. To eliminate the need for lighting
3. To conceal entrances from public view
4. To replace all security cameras
Correct Answer: 1
Explanation:
Natural surveillance uses environmental design to improve visibility and increase the likelihood that inappropriate activity can be observed. Clear sightlines, appropriate lighting, window placement, landscaping, and thoughtful positioning of legitimate activities can contribute to this objective. Natural surveillance can discourage some unwanted behavior because individuals perceive a greater likelihood of observation. It does not replace electronic surveillance, guards, or other controls where those measures are justified. Instead, it complements the broader physical security strategy through thoughtful environmental design.
Question 63.
An access control system repeatedly grants access after employees present credentials that should have been deactivated. What should the security manager investigate first?
- Exterior landscaping
2. Employee parking capacity
3. Credential revocation, database synchronization, system configuration, and access-control processing
4. Security officer uniforms
Correct Answer: 3
Explanation:
If revoked credentials continue to work, the organization has a potentially serious access-control failure. The security manager should determine whether credentials were properly deactivated, whether databases synchronized correctly, and whether controllers received updated authorization information. Configuration, communications, software, or administrative processes may be involved. Testing should confirm that corrective action actually prevents further unauthorized use. Effective access control depends not only on issuing credentials correctly but also on promptly modifying and revoking privileges when authorization changes.
Question 64.
A critical facility uses electronic locks that default to unlocked during certain system failures. What should the security professional evaluate?
- Only whether employees prefer electronic locks
2. Only the purchase price
3. Only the lock’s appearance
4. Fail-safe versus fail-secure requirements based on security, life safety, emergency egress, and operational needs
Correct Answer: 4
Explanation:
Lock behavior during power or system failure must balance physical security with life-safety requirements. Fail-safe hardware typically unlocks under specified failure conditions, while fail-secure hardware remains locked from the controlled side while still supporting required egress arrangements. The correct choice depends on the location, occupancy, risk, applicable codes, emergency plans, and operational requirements. Security professionals should coordinate with qualified life-safety, facilities, and engineering personnel. Applying one failure mode indiscriminately throughout a facility can create either security vulnerabilities or safety problems.
Question 65.
What is an important reason to establish a security baseline before implementing major improvements?
- It provides a reference point for comparing conditions and evaluating whether changes improve security performance.
2. It guarantees that future threats will remain unchanged.
3. It eliminates the need for testing.
4. It determines which vendor must be selected.
Correct Answer: 1
Explanation:
A baseline documents relevant conditions before changes are implemented. Depending on the security objective, it may include incident frequency, alarm performance, response times, access violations, vulnerabilities, equipment availability, or other measures. After improvements are implemented, performance can be compared with the baseline to determine whether intended results are being achieved. Without a reliable starting point, organizations may have difficulty demonstrating whether investments actually improved protection. Baselines should use meaningful measures that relate directly to identified security objectives and risks.
Question 66.
A facility receives thousands of visitors each week. What should a scalable visitor management process emphasize?
- Permanent unrestricted credentials for frequent visitors
2. Identity and authorization verification, appropriate access limitations, efficient processing, recordkeeping, and credential expiration
3. Elimination of visitor records
4. Allowing visitors to select their own access areas
Correct Answer: 2
Explanation:
High visitor volume requires controls that provide appropriate security without unnecessarily disrupting legitimate operations. The process should verify identity and business purpose as required by risk, establish host or sponsor authorization, limit access appropriately, and ensure temporary credentials expire or are recovered. Pre-registration and automated visitor systems can improve efficiency where suitable. Sensitive areas may require escorts or additional screening. The visitor process should be designed according to facility risk and periodically reviewed to ensure that operational convenience does not gradually weaken security.
Question 67.
A security professional identifies a large tree next to a perimeter fence that could help an intruder bypass the barrier. What should this be classified as?
- A security objective
2. A response resource
3. A vulnerability that could reduce the effectiveness of the perimeter
4. A risk transfer mechanism
Correct Answer: 3
Explanation:
A feature that makes it easier to bypass a protective measure represents a vulnerability. The tree may provide climbing assistance or otherwise reduce the delay created by the fence. The professional should assess the significance of the condition based on the protected assets, threat environment, surrounding terrain, and other controls. Possible corrective actions could include vegetation management, barrier modification, detection, or surveillance. Physical security assessments should consider how environmental features interact with protective systems rather than evaluating barriers in isolation.
Question 68.
A security manager wants to reduce the risk of unauthorized vehicles entering through a staffed gate. Which approach is most appropriate?
- Allow every vehicle displaying a company logo to enter
2. Keep the gate open during busy periods
3. Rely solely on verbal recognition by guards
4. Establish vehicle and occupant verification procedures supported by appropriate barriers, credentials, records, and escalation processes
Correct Answer: 4
Explanation:
Vehicle access should be controlled according to facility risk and operational needs. Verification may involve vehicle credentials, driver identification, authorization records, guard procedures, license information, visitor processes, or other measures. Physical gate equipment should support the required level of control and should not be routinely bypassed merely for convenience. Procedures should also address exceptions, denied access, deliveries, emergency vehicles, and suspicious activity. Combining people, procedures, and physical controls provides more reliable protection than relying on a single recognition method.
Question 69.
Why should security professionals evaluate environmental conditions when selecting outdoor intrusion sensors?
- Weather, vegetation, animals, terrain, vibration, and other conditions can affect detection performance and nuisance alarm rates.
2. Outdoor sensors operate identically in every environment.
3. Environmental conditions matter only to cameras.
4. Sensors eliminate environmental influences automatically.
Correct Answer: 1
Explanation:
Outdoor detection environments can be challenging. Rain, snow, temperature changes, wind-driven vegetation, wildlife, vibration, terrain, and other factors may influence sensor performance. A technology that works effectively at one site may produce excessive nuisance alarms or inadequate coverage at another. Security professionals should evaluate site conditions, select appropriate technology, configure it correctly, and test actual performance. Ongoing maintenance is also important because vegetation, structures, and environmental conditions can change and alter the effectiveness of the detection system.
Question 70.
A security professional must protect a sensitive room while allowing authorized personnel to enter quickly during routine operations. What design principle is most appropriate?
- Maximize delay for everyone regardless of authorization
2. Balance required security with legitimate operational access and throughput
3. Eliminate authentication during busy periods
4. Keep the room permanently unlocked
Correct Answer: 2
Explanation:
Physical security should protect assets without unnecessarily preventing legitimate business operations. Controls should provide sufficient authentication, authorization, detection, and delay for the assessed risk while supporting required throughput for authorized personnel. Excessively burdensome controls may encourage users to bypass procedures, while weak controls can expose sensitive assets. The security professional should therefore understand traffic volumes, operational urgency, user population, risk, and emergency requirements. Effective design balances protection and usability rather than treating them as unrelated objectives.
Question 71.
A facility’s security plan depends on local law enforcement responding to serious incidents. What should the security manager do?
- Assume law enforcement response will always be immediate
2. Remove internal response procedures
3. Coordinate expectations, communication methods, access arrangements, roles, and realistic response considerations with appropriate external agencies
4. Contact external responders only after an incident has occurred
Correct Answer: 3
Explanation:
External emergency and law-enforcement support should be incorporated into security planning before an incident. Coordination can clarify communication channels, facility access, responsibilities, staging locations, available information, and realistic response expectations. Exercises or familiarization activities may also improve cooperation where appropriate. Organizations should not assume external responders will arrive within an arbitrary timeframe or automatically understand the site’s layout and risks. Internal security measures and procedures should reflect realistic external response capabilities and identified dependencies.
Question 72.
A security professional discovers that recorded video timestamps differ significantly among cameras. Why is this a concern?
- It affects only the visual appearance of the recordings
2. It increases camera resolution
3. It automatically improves privacy
4. It can make event reconstruction and correlation with access, alarm, or other records difficult
Correct Answer: 4
Explanation:
Accurate time synchronization is important when investigators need to reconstruct events using multiple information sources. If cameras, access-control systems, intrusion alarms, and other systems use inconsistent timestamps, determining the correct sequence of events can become difficult. Synchronization should therefore be included in system design, configuration, maintenance, and testing. The required level of precision depends on operational and investigative needs. Consistent timestamps improve alarm assessment, incident investigation, auditability, and the ability to correlate activity across integrated security systems.
Question 73.
What is the primary purpose of conducting a security vulnerability assessment?
- To identify weaknesses that relevant threats could exploit and evaluate their significance to protected assets
2. To guarantee elimination of every threat
3. To calculate employee compensation
4. To replace incident response planning
Correct Answer: 1
Explanation:
A vulnerability assessment identifies weaknesses in physical features, technology, procedures, personnel practices, or other protective measures. These weaknesses are meaningful when considered in relation to relevant threats and assets. The assessment helps determine how an adversary or hazardous event could exploit existing conditions and supports prioritization of corrective measures. Vulnerability assessment is one component of broader risk management and should be revisited as facilities, operations, threats, and security controls change. Its purpose is informed risk reduction rather than a guarantee of complete protection.
Question 74.
A security manager is deciding whether security officers should perform fixed-post duties or patrols. What should guide the decision?
- Officer preference alone
2. Security objectives, threat conditions, facility layout, response requirements, observation needs, and available resources
3. The shortest possible walking distance
4. Whether patrols require uniforms
Correct Answer: 2
Explanation:
Fixed posts and patrols serve different security purposes. Fixed posts may provide continuous control or observation at critical locations, while patrols can provide broader coverage, deterrence, inspection, and unpredictable presence. The appropriate combination depends on the site’s layout, risk, access points, critical assets, alarm response requirements, and staffing. Security professionals should define required functions first and then determine deployment. Staffing patterns should also be periodically evaluated using incident information, observations, exercises, and changing operational conditions.
Question 75.
A high-security facility requires two authorized employees to be present before a critical storage area can be opened. What type of control is this?
- Single sign-on
2. Natural surveillance
3. Dual-control or two-person authorization
4. Risk transfer
Correct Answer: 3
Explanation:
Dual control requires participation by two authorized individuals before a sensitive action or access event can occur. This reduces dependence on a single individual and can strengthen accountability for high-value or high-risk assets. Implementation may involve separate credentials, keys, combinations, or procedural approvals. The requirement should be based on risk and operational needs because unnecessary dual control can create delays and administrative burden. The system should also address emergencies, personnel availability, audit records, and attempts to bypass the control.
Question 76.
A facility is replacing an old access control system. What should be included in transition planning?
- Only the installation date
2. Only the new badge design
3. Only removal of the old readers
4. Credential migration, testing, temporary access arrangements, user communication, rollback or contingency measures, and system acceptance
Correct Answer: 4
Explanation:
Replacing an access-control system can temporarily affect the organization’s ability to regulate entry. Transition planning should address how existing users and permissions will migrate, how new components will be tested, and how access will be maintained during conversion. Temporary credentials or manual procedures may be required. Communication helps users understand changes, while contingency or rollback measures provide options if the new system fails. Final acceptance should confirm that required functionality, authorization, alarms, integrations, and records operate correctly before the old system is fully retired.
Question 77.
Why should a security manager monitor trends in alarm activity rather than reviewing only individual alarms?
- Trends can reveal recurring vulnerabilities, equipment problems, environmental effects, or suspicious patterns that isolated events may not show.
2. Trend analysis makes alarm response unnecessary.
3. Only false alarms should be recorded.
4. Historical alarm information has no security value.
Correct Answer: 1
Explanation:
Individual alarms provide information about specific events, while trend analysis can reveal broader patterns. Repeated alarms from one location may indicate failing equipment, environmental interference, user behavior, attempted intrusion, or poor configuration. Changes in alarm frequency by time or location may also identify emerging concerns. Security managers can use this information to improve maintenance, procedures, staffing, detection configuration, or protective measures. Trend analysis should complement immediate alarm response rather than replacing the need to assess individual events appropriately.
Question 78.
A facility uses an intercom to communicate with visitors before remotely unlocking an entrance. What additional control would most improve verification?
- Louder speakers only
2. Visual assessment through appropriately positioned video surveillance
3. Removing the access control reader
4. Keeping the entrance unlocked
Correct Answer: 2
Explanation:
Voice communication can help establish a visitor’s purpose, but visual assessment provides additional information about the individual and surrounding conditions. Integrating an intercom with appropriately positioned video allows security personnel to compare the person with available information, observe whether additional individuals are present, and assess unusual behavior before releasing the door. Depending on risk, identity verification and host authorization may also be required. Remote entry procedures should provide enough information for informed access decisions rather than relying solely on verbal claims.
Question 79.
A security professional identifies a critical exterior camera whose view is frequently blocked by delivery trucks. What is the most appropriate response?
- Accept the obstruction because deliveries are legitimate
2. Disable the camera during deliveries
3. Modify camera placement, vehicle positioning, procedures, or complementary coverage to maintain required surveillance
4. Stop recording all delivery areas
Correct Answer: 3
Explanation:
A surveillance system should provide the required coverage during realistic operating conditions, including routine deliveries. If legitimate activities repeatedly block a critical camera, the design or operational arrangement should be reconsidered. Possible solutions include repositioning the camera, adding complementary coverage, changing designated vehicle locations, or modifying delivery procedures. The selected approach should maintain operational efficiency while preserving the required security function. Testing should confirm that the revised arrangement provides adequate observation under normal and challenging conditions.
Question 80.
Following a significant security incident, what should management do after immediate response and stabilization activities are complete?
- Restore operations without documenting anything
2. Assume existing controls remain adequate
3. Replace every security system regardless of cause
4. Conduct an appropriate post-incident review to identify causes, control performance, lessons, and corrective actions
Correct Answer: 4
Explanation:
A post-incident review helps the organization understand what happened, why it occurred, and how effectively existing controls and response procedures performed. The review may examine detection, assessment, communications, decisions, response times, physical controls, procedures, and recovery activities. Findings can support corrective actions, updated training, revised procedures, system modifications, or risk reassessment. The purpose should be organizational learning and improved protection rather than simply assigning blame. Significant lessons should be tracked until appropriate corrective actions are addressed.