View Full ASIS PSP Exam Dumps and Practice Test Dumps
Question 261.
A security professional is reviewing a facility where the perimeter fence terminates at the wall of an adjacent building. What should be evaluated most carefully?
- Whether the neighboring building has the same architectural style
2. Whether the junction creates a climbing, bypass, concealment, or unauthorized access opportunity
3. Whether the fence and building use matching colors
4. Whether employees can see the junction from their desks
Correct Answer: 2
Explanation:
Perimeter barriers should be evaluated at transitions and termination points because these locations can create unexpected weaknesses. An adjacent structure may provide climbing assistance, concealment, rooftop access, or a route around the fence. The security professional should assess the complete geometry of the boundary and determine whether additional barriers, surveillance, detection, lighting, or procedural controls are necessary. A perimeter can be effective along most of its length yet remain vulnerable where it intersects buildings, waterways, terrain, utility structures, or other physical features.
Question 262.
What is the primary purpose of configuration management for physical security systems?
- To maintain controlled and documented system settings, versions, components, and changes throughout the system lifecycle
2. To prevent every future system modification
3. To eliminate maintenance documentation
4. To allow any administrator to make undocumented changes
Correct Answer: 1
Explanation:
Configuration management helps ensure that security systems remain in a known and controlled state. It can include documentation of device settings, software or firmware versions, network information, integrations, and approved changes. Without configuration management, unauthorized or accidental modifications may degrade security performance or make troubleshooting difficult. Changes should be reviewed according to their potential impact, documented, tested, and reflected in relevant system records. Maintaining reliable configuration information also supports recovery when equipment must be replaced or restored after a failure.
Question 263.
A facility has installed emergency call stations throughout a remote parking area. What should be verified periodically?
- Only the color of each station
2. Only whether employees know the manufacturer’s name
3. Communications, location identification, visibility, power, monitoring, response procedures, and physical condition
4. Only the number of parking permits issued
Correct Answer: 3
Explanation:
Emergency call stations are useful only when users can locate and operate them and when calls reliably reach personnel capable of responding. Testing should verify audio or other communications, correct identification of the caller’s location, power, signage or visibility, monitoring, and associated response procedures. Physical damage or environmental exposure should also be inspected. Personnel receiving calls should know how to assess and escalate them. Routine functional testing provides greater assurance than simply confirming that the stations remain physically installed.
Question 264.
An organization has installed a sophisticated intrusion detection system but has no personnel assigned to respond to alarms overnight. What is the most significant weakness?
- The sensors may be too modern
2. The system contains too many devices
3. The building may have insufficient signage
4. Detection without an effective assessment and response capability may not prevent successful intrusion
Correct Answer: 4
Explanation:
Detection is only one component of an effective protection system. An alarm must be communicated, assessed, and followed by an appropriate response within a useful timeframe. If no one can respond overnight, an adversary may have sufficient time to complete the objective despite early detection. The organization should evaluate monitoring, communications, barriers, delay, response resources, and external support where appropriate. Investments in detection should therefore be coordinated with the broader detection-delay-response relationship rather than considered independently.
Question 265.
Why should physical security requirements be included in construction contract documents when appropriate?
- They help communicate required security performance, responsibilities, materials, testing, documentation, and acceptance expectations to project participants.
2. They guarantee that construction will have no deficiencies.
3. They eliminate the need for project oversight.
4. They allow contractors to ignore security drawings.
Correct Answer: 1
Explanation:
Security requirements are easier to enforce when they are clearly incorporated into project documentation. Specifications, drawings, performance criteria, submittal requirements, testing procedures, and documentation expectations help contractors understand what must be delivered. Clear requirements can also reduce disputes about substitutions, interfaces, commissioning, and acceptance. Security professionals should coordinate with appropriate project stakeholders so requirements are consistent with architecture, engineering, life safety, accessibility, and operations. Contract documentation does not eliminate oversight, but it establishes a stronger basis for verification.
Question 266.
A security manager wants to use access-control data to investigate unusual after-hours activity. Which capability is most important?
- Decorative badge templates
2. Accurate event logging with reliable timestamps and identifiable individual credentials
3. Larger access readers
4. More entrance signs
Correct Answer: 2
Explanation:
Investigating after-hours access requires reliable information about who used a credential, at which opening, and at what time. Individual credentials and accurate timestamps support event reconstruction and can be correlated with video, alarms, or other records. Shared credentials and inaccurate clocks weaken accountability. Logs should also be protected from unauthorized alteration and retained according to legitimate investigative requirements. Access records are most useful when credential administration, system time, audit controls, and retention practices collectively support reliable evidence.
Question 267.
A security professional is reviewing a door equipped with electromagnetic locking hardware. Which issue requires particular attention?
- The magnet’s exterior color
2. Whether employees can hear the lock operate
3. Power-loss behavior, release methods, emergency egress, life-safety requirements, and access-control integration
4. Whether the door has a company logo
Correct Answer: 3
Explanation:
Electromagnetic locks depend on electrical power and therefore require careful consideration of how the opening behaves during outages and emergencies. Release mechanisms, fire alarm interfaces, request-to-exit functions, emergency egress, and applicable codes or life-safety requirements must be coordinated with the security objective. Backup power may also affect expected operation. The complete door system should be tested under normal, emergency, and failure conditions. Security must not be improved in a way that creates unacceptable risk to occupants.
Question 268.
A security system vendor requires permanent remote administrator access for routine support. What should the organization do?
- Give the vendor unrestricted access to every security system
2. Disable all administrative logs
3. Share the internal administrator password
4. Determine whether continuous access is necessary and apply controlled, limited, authenticated, monitored vendor access appropriate to support needs
Correct Answer: 4
Explanation:
Vendor support requirements should not automatically result in unrestricted permanent access. The organization should determine what remote functions are genuinely necessary, when they are required, and what systems the vendor must reach. Access can then be limited through authorization, strong authentication, network controls, logging, time restrictions, or approval processes. Vendor accounts should be reviewed and removed when no longer required. These controls reduce exposure while preserving legitimate maintenance capability for critical physical security systems.
Question 269.
What is an important benefit of using a risk-based approach to physical security budgeting?
- Resources can be directed toward exposures where security improvements are expected to provide the greatest relevant risk reduction.
2. Every department automatically receives identical funding.
3. The most expensive security technology is always purchased first.
4. Budgeting no longer requires management decisions.
Correct Answer: 1
Explanation:
Security resources are finite, so investments should reflect the significance of identified risks and organizational priorities. A risk-based approach considers assets, threats, vulnerabilities, consequences, existing controls, and the expected effect of proposed improvements. This helps management distinguish critical needs from desirable but lower-priority enhancements. Cost, feasibility, lifecycle implications, and operational impact also remain relevant. The objective is not necessarily to spend more, but to allocate available resources deliberately toward protection measures that address meaningful organizational exposure.
Question 270.
A security manager finds that a camera’s recorded images are adequate during daytime but nearly unusable at night. What should be evaluated?
- Only daytime resolution
2. Nighttime illumination, camera sensitivity, scene contrast, infrared capability where appropriate, positioning, and actual recording settings
3. Employee access schedules only
4. The camera’s purchase date alone
Correct Answer: 2
Explanation:
Video performance should be verified under the conditions in which surveillance is required. A camera that performs well during daylight may produce noise, blur, glare, or insufficient detail at night. The manager should evaluate available illumination, camera sensitivity, lens characteristics, infrared options where appropriate, scene contrast, exposure, compression, and positioning. Lighting changes can also affect other cameras or human observation. Testing actual nighttime images against the defined surveillance task provides a better basis for improvement than relying only on equipment specifications.
Question 271.
A company is concerned about unauthorized removal of valuable equipment through employee exits. Which approach is most appropriate?
- Increase perimeter lighting only
2. Allow unrestricted removal because employees are credentialed
3. Establish risk-based property removal, authorization, inspection, inventory, and accountability procedures
4. Eliminate employee exits
Correct Answer: 3
Explanation:
Controlling entry does not necessarily prevent unauthorized removal of organizational property. Where theft risk justifies additional controls, the organization may use property passes, inventory records, exit inspections, asset tags, supervisory authorization, or other measures. Procedures should be lawful, consistently applied, and appropriate to the assets and workplace environment. Security professionals should also examine incident patterns and internal movement of high-value items. Effective asset protection addresses both unauthorized entry and unauthorized removal through legitimate access points.
Question 272.
A facility wants to use video analytics to automatically detect objects left unattended in a public lobby. What should be established before relying on the capability?
- Only the camera manufacturer
2. Only the lobby dimensions
3. Only the number of visitors
4. Detection criteria, expected performance, environmental limitations, assessment procedures, response actions, and testing
Correct Answer: 4
Explanation:
Automated analytics should be tied to a clearly defined operational objective. The organization should determine what qualifies as an unattended object, how long it must remain before generating an alert, and how personnel will assess and respond. Crowds, furniture, lighting, camera angle, and scene changes can affect performance. Testing under representative conditions helps establish realistic expectations for both missed detections and nuisance alarms. Analytics can support operator awareness, but alerts generally require human assessment within established security procedures.
Question 273.
Why should visitor records be protected against unnecessary disclosure?
- They may contain personal, organizational, scheduling, or relationship information that should be accessible only for legitimate purposes.
2. Visitor records should always be displayed publicly.
3. Protecting visitor records prevents visitors from entering.
4. Visitor information has no operational value.
Correct Answer: 1
Explanation:
Visitor records can reveal names, organizations, hosts, dates, times, destinations, and other information that may have privacy or security implications. Access should therefore be limited to personnel with legitimate operational, investigative, legal, or compliance needs. Retention should also reflect applicable requirements rather than keeping information indefinitely without purpose. Protecting visitor data does not prevent its legitimate use for access management or investigations. Physical security programs should protect the information generated by security processes as well as the facilities themselves.
Question 274.
A security professional is assessing a facility with multiple elevators serving both public and restricted floors. Which control should be considered?
- Removing all floor indicators
2. Restricting elevator access to protected floors using appropriate authorization while maintaining emergency and accessibility requirements
3. Allowing every visitor access to every floor
4. Replacing elevators with stairways
Correct Answer: 2
Explanation:
Elevators can bypass ground-floor access boundaries by providing direct access to upper restricted areas. Depending on risk, credential-controlled floor selection, destination controls, staffed reception, or secured elevator lobbies may be appropriate. The design should account for visitors, employees, accessibility, emergency responders, fire-service operation, and system failures. Elevator controls should complement rather than replace protection at sensitive floor entrances. Security professionals should evaluate vertical circulation as part of the facility’s overall zoning and access-control strategy.
Question 275.
A security officer discovers a damaged perimeter fence during patrol. What should occur first according to a well-designed security process?
- Wait until the next scheduled maintenance cycle regardless of severity
2. Repair it personally without reporting it
3. Report and assess the vulnerability promptly, initiate appropriate temporary protection, and arrange prioritized repair
4. Stop all facility operations automatically
Correct Answer: 3
Explanation:
Damage to a perimeter can create an immediate vulnerability, so the condition should be reported and evaluated promptly. The severity, location, nearby assets, existing detection, and likely repair time should determine the response. Temporary measures could include increased patrols, guards, temporary barriers, lighting, or surveillance until permanent repair is completed. The repair should then be verified. A structured process ensures that security deficiencies discovered during routine operations are tracked and controlled rather than simply noted for future maintenance.
Question 276.
A facility uses one server for access control, video management, and intrusion monitoring with no failover capability. What should the security manager evaluate?
- Whether the server has a company logo
2. Only its storage capacity
3. Whether employees know where the server is located
4. The operational consequences of server failure and whether redundancy, failover, or other continuity measures are justified
Correct Answer: 4
Explanation:
Consolidating several security functions on one server can simplify administration but may also create a significant single point of failure. The manager should determine what functions would be lost, how long restoration would take, whether field devices retain local capability, and what risks arise during an outage. Redundant servers, virtualization, backups, alternate procedures, or rapid replacement may be appropriate depending on criticality. Resilience decisions should be based on operational consequences rather than assuming every system requires identical redundancy.
Question 277.
What is the main purpose of periodically reviewing security standard operating procedures?
- To ensure procedures remain accurate, practical, authorized, and aligned with current risks, systems, staffing, and operations
2. To increase document length
3. To eliminate employee training
4. To ensure procedures never change
Correct Answer: 1
Explanation:
Security procedures can become outdated as facilities, technology, staffing, threats, responsibilities, and organizational requirements change. Periodic review helps confirm that personnel instructions remain accurate and practical. Incident lessons, audit findings, exercises, and employee feedback may reveal areas requiring revision. Updated procedures should be communicated and supported by appropriate training. Document control is also important so personnel do not unknowingly rely on obsolete versions. Procedures should reflect how security is actually expected to operate, not simply remain unchanged for administrative convenience.
Question 278.
A security manager is reviewing a high number of forced-door alarms generated during shift changes. Which action is most appropriate?
- Disable forced-door monitoring during every shift change
2. Analyze door hardware, traffic flow, access behavior, alarm timing, and operational processes before adjusting controls
3. Ignore the alarms permanently
4. Replace every employee credential
Correct Answer: 2
Explanation:
A concentration of forced-door alarms during predictable periods suggests that operational conditions may be interacting poorly with security controls. Employees may be holding doors, closers may be inadequate, alarm timing may be unsuitable, or entrance capacity may be insufficient. The manager should determine the actual cause and distinguish legitimate operational activity from unauthorized behavior. Adjustments can then improve both security and workflow. Automatically suppressing alarms can conceal genuine events, while ignoring the underlying process may allow insecure practices to continue.
Question 279.
A high-security area requires two authorized employees to be present whenever a vault is opened. Which control principle does this represent?
- Natural access control
2. Risk transfer
3. Dual control or two-person authorization
4. Perimeter zoning
Correct Answer: 3
Explanation:
Dual control requires participation by two authorized individuals for specified sensitive activities. It reduces the ability of one person to perform a high-risk action independently and can strengthen accountability. Depending on the application, separate credentials, keys, combinations, approvals, or procedural verification may be used. The organization should define how exceptions and emergencies are handled without undermining the control. Dual control is generally reserved for activities where the consequences of unauthorized or improper action justify the additional operational burden.
Question 280.
A security professional is preparing recommendations after completing a comprehensive site assessment. How should recommendations be presented to management?
- In random order without cost or risk information
2. Based solely on the newest available technology
3. As mandatory equipment purchases without alternatives
4. Prioritized according to risk, with clear rationale, expected benefits, operational considerations, costs, dependencies, and implementation priorities
Correct Answer: 4
Explanation:
Management needs enough information to make informed decisions about security investments. Recommendations should clearly connect identified vulnerabilities and risks with proposed improvements and explain how each measure contributes to protection. Prioritization helps distinguish urgent needs from longer-term enhancements. Cost, feasibility, operational impact, dependencies, and potential compensating measures can support implementation planning. Recommendations should focus on performance and risk reduction rather than promoting specific technologies without justification. Clear presentation also makes it easier to track management decisions and subsequent corrective actions.