ASIS PSP Practice Test Questions and Exam Dumps Part11 Q201-220

View Full ASIS PSP Exam Dumps and Practice Test Dumps

 

Question 201.

A security professional is evaluating a building where a public stairwell provides access to several restricted floors. What is the most appropriate security consideration?

  1. Whether the stairwell has decorative finishes
    2. Whether floor access from the stairwell is appropriately controlled while preserving required emergency egress
    3. Whether employees prefer elevators
    4. Whether every stairwell door uses identical signage

Correct Answer: 2

Explanation:

Stairwells can provide vertical movement that bypasses lobby or elevator access controls if floor-entry doors are not properly secured. The security professional should evaluate which floors require controlled access and how stairwell doors behave during normal operation, emergencies, fire alarms, and system failures. Any solution must preserve applicable life-safety and egress requirements. Access-control hardware, monitoring, alarms, and procedures may be appropriate depending on risk. The objective is to prevent unauthorized movement without creating unsafe conditions for occupants who need to evacuate.

Question 202.

What is the primary purpose of a security master plan?

  1. To provide a coordinated long-term framework for security objectives, priorities, systems, projects, standards, and investments
    2. To list only currently installed cameras
    3. To replace individual security procedures
    4. To guarantee that security requirements never change

Correct Answer: 1

Explanation:

A security master plan helps an organization coordinate physical security improvements over time rather than implementing isolated projects without a common direction. It can connect risk assessments, protection objectives, design standards, technology strategies, operational requirements, budgets, and implementation priorities. The plan should be sufficiently flexible to accommodate changes in threats, facilities, technology, and business operations. Individual projects and procedures may still require detailed documentation. The master plan provides the broader framework that helps those efforts remain consistent with organizational security goals.

Question 203.

A facility uses smart cards for employee access, but employees routinely lend their cards to coworkers. Which security principle is being undermined?

  1. Natural surveillance
    2. Perimeter standoff
    3. Individual accountability and reliable association between a credential and its authorized holder
    4. Lighting uniformity

Correct Answer: 3

Explanation:

Access credentials are normally issued to specific individuals so transactions can support authorization and accountability. Sharing credentials makes it difficult to determine who actually entered an area and may allow individuals to obtain privileges they were not granted. The organization should reinforce credential-use policies, investigate why sharing occurs, and address operational processes that encourage it. Depending on risk, additional authentication or entrance controls may also be appropriate. Technology cannot provide reliable accountability when users intentionally exchange the credentials on which the system depends.

Question 204.

A critical facility has two backup communication links, but both cables travel through the same underground conduit. What should concern the security professional?

  1. The cables have different manufacturers
    2. The conduit is underground
    3. The links use different labels
    4. A single physical event could disable both supposedly redundant communication paths

Correct Answer: 4

Explanation:

Redundancy is weakened when backup systems share a common vulnerability. Two communication circuits may appear independent logically while using the same conduit, building entrance, network room, or service provider infrastructure. Damage at that shared point could disable both simultaneously. The security professional should evaluate physical and logical path diversity when resilience is required. Appropriate separation depends on the consequences of communication loss and the threats or hazards being addressed. Effective redundancy reduces common-mode failures rather than merely duplicating equipment.

Question 205.

Why should a security risk assessment consider residual risk after controls are implemented?

  1. Controls usually reduce risk rather than eliminating every possibility of loss or disruption.
    2. Residual risk exists only when no controls are installed.
    3. Residual risk is always acceptable.
    4. It represents only the cost of security equipment.

Correct Answer: 1

Explanation:

Security controls generally change the likelihood, vulnerability, consequence, or overall exposure associated with a risk, but complete elimination is uncommon. Residual risk is the risk remaining after relevant controls or treatments are considered. Management should understand this remaining exposure so it can decide whether additional mitigation, transfer, avoidance, or formal acceptance is appropriate. The analysis also helps demonstrate that installing a control does not automatically resolve the underlying risk. Residual risk should be reconsidered when threats, vulnerabilities, consequences, or control effectiveness change.

Question 206.

A security manager is concerned that employees are entering restricted areas by following closely behind authorized personnel through turnstiles. Which issue should be evaluated?

  1. Camera storage capacity only
    2. Piggybacking or tailgating controls, user behavior, turnstile configuration, monitoring, and enforcement
    3. Parking lot landscaping
    4. Building exterior paint

Correct Answer: 2

Explanation:

Controlled entrances can be undermined when multiple individuals pass using one authorization. Depending on the circumstances, the behavior may involve deliberate piggybacking or unintentional tailgating. The manager should evaluate entrance hardware, throughput, employee practices, surveillance, alarms, guard procedures, and awareness. Controls should be proportionate to risk because highly restrictive solutions may affect accessibility and traffic flow. The objective is to maintain individual authorization at the boundary without creating operational conditions that encourage users to bypass the process.

Question 207.

A facility stores confidential records in an unlocked room accessible to numerous employees who have no business need for them. What is the most appropriate improvement?

  1. Increase hallway lighting only
    2. Move the records closer to the entrance
    3. Restrict physical access and storage according to authorization and information sensitivity
    4. Remove all record inventories

Correct Answer: 3

Explanation:

Physical protection of sensitive information should reflect legitimate business need and the consequences of unauthorized access, loss, or disclosure. Secure rooms, cabinets, access-control measures, key management, or other controls may be appropriate depending on sensitivity. Authorization should be limited to personnel who require access for their responsibilities. Records should also be handled, retained, and disposed of according to applicable organizational and legal requirements. Physical security therefore supports information protection by controlling who can reach sensitive documents and storage locations.

Question 208.

An organization plans to connect its video surveillance system to the corporate network. What should be considered before integration?

  1. Only camera resolution
    2. Only the number of network cables
    3. Only monitor dimensions
    4. Network security, segmentation, authentication, bandwidth, availability, administrative access, updates, and system dependencies

Correct Answer: 4

Explanation:

Modern physical security systems often rely on network infrastructure and therefore inherit cybersecurity and availability concerns. The organization should coordinate physical security and information technology requirements, including network segmentation, administrative authentication, communications protection, bandwidth, system updates, monitoring, and recovery. Security devices should not be assumed safe simply because they serve a physical protection function. Integration should also consider what happens when the corporate network experiences congestion, maintenance, cyber incidents, or outages that could affect surveillance availability.

Question 209.

What is an important advantage of using tamper detection on critical security equipment enclosures?

  1. It can provide notification when someone attempts unauthorized opening or interference with protected equipment.
    2. It makes the enclosure physically indestructible.
    3. It eliminates the need for access restrictions.
    4. It prevents every equipment malfunction.

Correct Answer: 1

Explanation:

Critical panels, controllers, communication equipment, and other security components may be targets for unauthorized manipulation. Tamper detection can generate an alarm when an enclosure is opened or otherwise disturbed, allowing personnel to investigate. It should complement physical locks, restricted access, surveillance, and appropriate installation rather than replace them. Tamper alarms also require suitable monitoring and response procedures. The level of protection should reflect equipment criticality and the consequences that unauthorized manipulation could have on the broader security system.

Question 210.

A security manager is reviewing a proposal for video analytics that claims virtually perfect detection under all conditions. What is the best response?

  1. Purchase the system based solely on the claim
    2. Define required performance and validate the technology under representative site and environmental conditions
    3. Assume analytics eliminate the need for assessment
    4. Remove all conventional security controls

Correct Answer: 2

Explanation:

Analytics performance can vary with lighting, weather, camera angle, scene complexity, target behavior, configuration, and other environmental factors. Marketing claims should therefore be evaluated against defined operational requirements and realistic site conditions. Pilot testing or acceptance testing can measure detection and nuisance alarm performance before full reliance is placed on the technology. Analytics can help direct operator attention, but detections may still require assessment and response. Technology should be incorporated into the overall security system based on demonstrated performance rather than unsupported expectations.

Question 211.

A security professional discovers a drainage culvert passing underneath the perimeter fence. What should be evaluated?

  1. Only water-flow capacity
    2. Whether the culvert is visible from the office
    3. Whether the culvert creates a potential bypass route and what protection can be applied without compromising drainage requirements
    4. The number of vehicles entering the facility

Correct Answer: 3

Explanation:

Drainage structures can create openings beneath otherwise effective perimeter barriers. The security professional should evaluate dimensions, accessibility, terrain, expected water flow, maintenance requirements, and whether the opening could permit unauthorized entry. Appropriate measures may include grilles, barriers, detection, surveillance, or other controls designed so they do not create unacceptable flooding or maintenance problems. Perimeter assessments should examine utility and drainage penetrations because adversaries may exploit less obvious routes instead of attempting to defeat the main fence directly.

Question 212.

A facility is installing an emergency lockdown capability. Which issue is most important during design?

  1. Making every door behave identically
    2. Preventing anyone from overriding the system under any circumstances
    3. Eliminating emergency egress
    4. Defining which openings lock, who can initiate or override lockdown, life-safety behavior, communications, and failure conditions

Correct Answer: 4

Explanation:

Lockdown functionality can significantly affect occupant movement, emergency response, and life safety. The organization should define exactly what lockdown is intended to accomplish, which areas are affected, who has authority to activate it, and how doors behave during fires, evacuations, power failures, or responder access. Communications and training are also essential so personnel understand expected actions. Integrated testing should verify actual system behavior. Lockdown should be engineered as a controlled emergency capability rather than simply applying a universal lock command to every door.

Question 213.

Why should access privileges be reviewed when an employee changes job responsibilities?

  1. The employee may no longer require previous access or may need different privileges for the new role.
    2. Every transferred employee should retain all previous access permanently.
    3. Access should be reviewed only at termination.
    4. Job responsibilities are unrelated to physical access.

Correct Answer: 1

Explanation:

Physical access should generally correspond to current business responsibilities. When employees transfer, receive promotions, change departments, or take on different duties, previous access may become unnecessary while new privileges may be required. If old permissions accumulate, employees can retain access far beyond legitimate need. A structured change process involving appropriate managers, human resources, and security can help maintain accurate authorization. Periodic access reviews provide an additional safeguard for permissions that were not adjusted correctly during organizational changes.

Question 214.

A security manager wants to improve the reliability of incident evidence obtained from access logs and video recordings. What practice is most important?

  1. Allow all employees to edit records
    2. Maintain accurate timestamps, controlled access, appropriate retention, and integrity of relevant security records
    3. Delete records immediately after an incident
    4. Disable system audit trails

Correct Answer: 2

Explanation:

Security records can support investigations only when their timing, integrity, and origin are sufficiently reliable. Systems should use appropriately synchronized time sources, and access to records should be limited to authorized personnel. Audit trails and controlled export procedures can help establish how evidence was handled. Retention should preserve records long enough for legitimate investigative and legal needs. When records are collected for a specific investigation, appropriate chain-of-custody procedures may also be necessary to document possession, transfer, and preservation.

Question 215.

A facility’s perimeter lighting has several failed fixtures, but no formal process exists for identifying outages. What should be implemented?

  1. Replacement only after a security incident
    2. Permanent removal of lighting
    3. Routine inspection, reporting, repair, and verification procedures based on the lighting’s security importance
    4. Increased camera storage

Correct Answer: 3

Explanation:

Lighting performance can gradually degrade as lamps fail, fixtures become dirty, vegetation grows, or equipment is damaged. Without routine inspection, significant dark areas may persist unnoticed. A maintenance process should identify failures, establish repair priorities, document corrective action, and verify restoration. Critical areas may require faster response than locations where lighting has limited security significance. Periodic nighttime inspections can reveal problems that are difficult to recognize during daylight. Security controls require ongoing maintenance to sustain the performance assumed during design.

Question 216.

A security professional is reviewing remote vendor access to an electronic security management system. What is the best approach?

  1. Provide the vendor with a permanent shared administrator account
    2. Allow unrestricted remote access from any device
    3. Disable logging to simplify maintenance
    4. Limit remote access through authorized, authenticated, monitored, and controlled procedures appropriate to the risk

Correct Answer: 4

Explanation:

Remote maintenance can be useful, but unrestricted vendor access can create a pathway to critical physical security systems. Access should be limited to legitimate support needs and protected using suitable authentication, authorization, monitoring, and network controls. Organizations may also restrict when connections are enabled and require approval for sensitive changes. Individual accounts and audit logs improve accountability compared with shared credentials. Vendor access should be removed when no longer required. Physical security system administration deserves protection comparable to the importance of the functions being controlled.

Question 217.

What is the primary purpose of a tabletop security exercise?

  1. To discuss a simulated scenario and evaluate plans, decisions, coordination, responsibilities, and information needs in a controlled setting
    2. To test physical barriers destructively
    3. To replace all operational drills
    4. To measure camera resolution

Correct Answer: 1

Explanation:

A tabletop exercise allows participants to work through a simulated event without deploying all operational resources. It can reveal unclear responsibilities, communication problems, missing information, conflicting procedures, or gaps in escalation and decision-making. Facilitators typically present scenario developments and ask participants to explain how they would respond. Tabletop exercises are particularly useful for validating plans and preparing for more complex drills or full-scale exercises. Findings should be documented, assigned for corrective action, and reviewed to confirm that meaningful improvements are implemented.

Question 218.

A security manager must choose between repairing an obsolete access-control platform and replacing it. Which factor should receive the broadest consideration?

  1. Original purchase price alone
    2. Lifecycle cost, reliability, supportability, security, integration, operational requirements, and future needs
    3. The age of the building alone
    4. The appearance of new readers

Correct Answer: 2

Explanation:

An obsolete platform may continue functioning while becoming increasingly difficult or expensive to support. The organization should compare repair and replacement options using lifecycle considerations such as maintenance, spare parts, vendor support, cybersecurity, reliability, compatibility, scalability, training, migration, and expected service life. Immediate purchase cost is only one part of the decision. A planned transition can also reduce the operational risk associated with sudden failure of unsupported equipment. Decisions should ultimately support current and anticipated security requirements.

Question 219.

An employee requests temporary access to a highly restricted area for a one-week assignment. What is the most appropriate approach?

  1. Give the employee permanent access to avoid future requests
    2. Provide a shared master credential
    3. Authorize only the necessary temporary access for the required period and ensure it expires or is removed afterward
    4. Disable access logging during the assignment

Correct Answer: 3

Explanation:

Temporary access should follow the principles of least privilege and limited duration. The employee should receive only the access necessary for the assignment and only for the period during which that access is justified. Appropriate authorization should be documented, and the privilege should expire automatically or be promptly removed when the assignment ends. This reduces the accumulation of unnecessary permissions. Access activity should remain appropriately logged, particularly for sensitive areas where accountability and investigation capability are important.

Question 220.

A physical security assessment identifies several vulnerabilities but the organization cannot correct all of them immediately. What is the most appropriate management approach?

  1. Address vulnerabilities in alphabetical order
    2. Correct only those that are easiest to fix
    3. Ignore all vulnerabilities until sufficient funding exists for every correction
    4. Prioritize actions based on risk and use appropriate interim or compensating controls where necessary

Correct Answer: 4

Explanation:

Organizations frequently have more potential security improvements than can be implemented immediately. Risk-based prioritization helps direct available resources toward vulnerabilities with the most significant combination of threat, weakness, and consequence. High-priority deficiencies may require temporary compensating controls while permanent solutions are designed or funded. Management should document decisions, responsibilities, target dates, and residual risk. Lower-priority items should remain tracked rather than disappearing from consideration. This approach supports deliberate resource allocation while maintaining visibility of unresolved security exposure.