ASIS PSP Practice Test Questions and Exam Dumps Part16 Q301-320

View Full ASIS PSP Exam Dumps and Practice Test Dumps

 

Question 301.

A security professional is reviewing a facility where employees can enter a restricted production area using either a proximity card or a mechanical key. What should be evaluated?

  1. Whether the key provides a less accountable bypass of the electronic access-control system
    2. Whether the proximity cards have attractive designs
    3. Whether employees prefer keys
    4. Whether the door opens inward

Correct Answer: 1

Explanation:

An electronic access-control system may provide authorization management and transaction records, but an uncontrolled mechanical-key override can bypass those benefits. The security professional should determine who possesses keys, how they are issued and recovered, whether their use is logged, and whether the mechanical override is genuinely required. Emergency and maintenance needs may justify alternate access, but it should be controlled according to risk. The overall opening should provide consistent protection rather than allowing a secondary access method to become an unmonitored weakness.

Question 302.

What is the primary purpose of conducting a photometric survey for security lighting?

  1. To determine the age of lighting fixtures
    2. To measure illumination levels and distribution so actual lighting performance can be compared with security requirements
    3. To identify employee work schedules
    4. To determine camera storage capacity

Correct Answer: 2

Explanation:

A photometric survey measures actual illumination at relevant locations and can reveal dark areas, excessive contrast, poor uniformity, or other lighting conditions affecting security. Measurements can be compared with design objectives and the needs of guards, cameras, pedestrians, and other users. Visual inspection remains useful because glare, shadows, obstructions, and scene characteristics may affect performance even when measured illumination appears adequate. Surveys are particularly valuable after installation or significant site changes because actual conditions may differ from original design assumptions.

Question 303.

A facility wants to install vibration sensors on a perimeter fence. Which condition should receive particular attention?

  1. Office furniture placement
    2. Employee badge photographs
    3. Wind, loose fence fabric, vegetation, nearby activity, and other vibration sources that could generate nuisance alarms
    4. Visitor parking permits

Correct Answer: 3

Explanation:

Fence-mounted vibration sensors detect physical disturbances, but environmental and structural conditions can influence their performance. Wind, vegetation striking the fence, loose fabric, maintenance activity, animals, or nearby machinery may create unwanted signals. The system should be selected and configured for the actual fence construction and environment. Detection zones, sensitivity, maintenance, alarm assessment, and response should also be considered. Testing under representative weather and operating conditions helps establish whether the system can detect relevant activity while maintaining an acceptable nuisance alarm rate.

Question 304.

A security manager discovers that an emergency override button can unlock several high-security doors but its use is not logged. What should be considered?

  1. Removing all emergency override capability
    2. Allowing everyone to use the button
    3. Hiding the button without documenting it
    4. Controlling authorization and recording override activations while preserving legitimate emergency functionality

Correct Answer: 4

Explanation:

Emergency override capabilities may be necessary for safety or operational reasons, but they can also create significant security consequences. The organization should define who may activate the function, under what circumstances, and what doors are affected. Where appropriate, activation should generate logs or alarms so actions can be reviewed. The control itself should be protected against unauthorized use while remaining available when legitimately required. Emergency functions should be included in periodic testing to verify that security, safety, and accountability requirements remain properly balanced.

Question 305.

What does risk transfer generally involve in a security risk-management context?

  1. Shifting specified financial or contractual consequences of risk to another party while recognizing that some exposure may remain
    2. Physically moving every asset to another facility
    3. Eliminating all threats to the organization
    4. Ignoring the risk completely

Correct Answer: 1

Explanation:

Risk transfer involves shifting defined consequences or responsibilities to another party, commonly through insurance or contractual arrangements. Transfer does not necessarily remove the underlying threat, vulnerability, or operational consequence. For example, insurance may compensate for certain financial losses but cannot fully restore disrupted operations, reputation, or safety impacts. Management should therefore understand what portion of risk is actually transferred and what residual exposure remains. Risk transfer can be used alongside mitigation, avoidance, or acceptance as part of an organization’s broader risk treatment strategy.

Question 306.

A facility uses multiple security technologies from different manufacturers. What should be evaluated before integrating them into one management platform?

  1. Only whether their enclosures match
    2. Interoperability, interface functionality, data exchange, cybersecurity, supportability, failure behavior, and operational requirements
    3. Only the age of each manufacturer
    4. Only the number of operators

Correct Answer: 2

Explanation:

Integration can improve operator awareness and workflow, but different systems may support interfaces differently. The organization should verify which events, commands, identities, video streams, and status information can actually be exchanged. Cybersecurity, licensing, vendor support, time synchronization, upgrades, and failure modes also require attention. Integration should be tested against operational scenarios rather than judged solely by technical compatibility claims. A connected platform provides value when the combined system reliably supports defined security processes without introducing unacceptable dependencies or vulnerabilities.

Question 307.

A security professional finds that a high-security room has a suspended ceiling that extends over the wall into an uncontrolled corridor. What vulnerability should be considered?

  1. Carpet wear
    2. Lighting color temperature
    3. Possible bypass of the controlled door by crossing above a wall that does not extend to a secure structural boundary
    4. Employee parking availability

Correct Answer: 3

Explanation:

A strong door provides limited protection if the surrounding construction can be bypassed easily. Walls protecting sensitive spaces should be evaluated from floor to the appropriate structural boundary, including ceilings, raised floors, ducts, and other penetrations. A suspended ceiling may conceal a route over a partition that stops below the structural deck. Corrective measures should reflect the threat and required delay. Security professionals should therefore evaluate the entire enclosure around a protected space rather than focusing only on visible doors and locks.

Question 308.

A security manager wants to install automatic license plate recognition at a vehicle entrance. Which limitation should be considered?

  1. License plates always establish the identity of the driver
    2. The technology eliminates the need for vehicle-access policies
    3. Every plate can be read accurately under all conditions
    4. Plate recognition identifies vehicle registration information or plate characters, not necessarily the actual driver or authorization context

Correct Answer: 4

Explanation:

Automatic license plate recognition can support vehicle identification, logging, and comparison against authorized or watch lists, but a plate does not prove who is driving. Plates may also be obscured, altered, dirty, missing, or difficult to capture because of angle, lighting, weather, or speed. The system should therefore be used according to a clearly defined security objective. Where driver identity is important, additional credentialing or verification may be required. Privacy, retention, and access to plate data should also be appropriately managed.

Question 309.

Why should a security professional evaluate local crime and incident information during a site assessment?

  1. It can provide relevant context about recurring threats and patterns in the facility’s surrounding environment.
    2. Local crime information predicts exactly what will happen at the facility.
    3. It eliminates the need to assess site vulnerabilities.
    4. Only national statistics are relevant to physical security.

Correct Answer: 1

Explanation:

Local incident and crime information can help identify patterns such as theft, trespassing, vehicle crime, vandalism, or other activity occurring near a facility. This information provides context for threat assessment but should not be treated as a precise prediction of future events. The organization should also consider site-specific assets, operations, adversaries, vulnerabilities, internal incidents, and other intelligence. Relevant information should be current and interpreted carefully. Security decisions are strongest when local context is combined with facility-specific analysis rather than used in isolation.

Question 310.

A security manager wants to reduce the possibility that cloned proximity cards can be used to enter a highly sensitive area. Which approach is most appropriate?

  1. Print larger employee names on the cards
    2. Evaluate stronger credential technologies or additional authentication appropriate to the risk
    3. Disable access logging
    4. Allow employees to share cards

Correct Answer: 2

Explanation:

Some credential technologies provide stronger resistance to copying or unauthorized duplication than others. For sensitive areas, the organization should evaluate whether existing credentials provide adequate assurance and whether cryptographically stronger smart credentials, PINs, biometrics, or other authentication measures are justified. Technology selection should also consider usability, lifecycle management, reader compatibility, enrollment, and exception handling. No credential should be considered invulnerable, so authentication should remain part of a broader system including authorization, monitoring, physical barriers, and response.

Question 311.

A facility has an unused underground service tunnel connecting it to another building. What should the security professional do?

  1. Ignore the tunnel because it is no longer operational
    2. Store unrestricted spare keys inside it
    3. Evaluate the tunnel as a potential access route and secure, monitor, or otherwise control it according to risk
    4. Remove all controls from the connected building

Correct Answer: 3

Explanation:

Unused tunnels, utility passages, basements, ducts, and similar routes can provide less visible means of approaching or entering protected areas. The security professional should determine where the tunnel originates and terminates, who can access it, what barriers exist, and whether detection or surveillance is appropriate. Permanently closing an unused route may sometimes be practical, while other facilities may require continued maintenance access. All potential paths into a protected environment should be assessed, including those not used during normal operations.

Question 312.

An organization is planning temporary fencing around a construction area inside an operating facility. What should guide its design?

  1. Appearance alone
    2. Lowest cost regardless of function
    3. Contractor convenience only
    4. Required separation, construction risks, access points, asset exposure, duration, monitoring, emergency needs, and changing site conditions

Correct Answer: 4

Explanation:

Construction can introduce temporary workers, tools, open walls, altered circulation, and new access routes. Temporary fencing should therefore support defined security objectives rather than merely mark the construction boundary. The organization should determine who needs access, what assets require separation, how emergency movement will occur, and whether gates, lighting, surveillance, or guards are needed. Conditions should be reassessed as construction progresses because the security environment may change from one phase to another. Temporary controls should be adjusted accordingly.

Question 313.

What is the primary security value of visitor escort requirements in sensitive areas?

  1. Escorts provide oversight of visitors whose independent access is not authorized and help ensure movement remains consistent with the approved purpose.
    2. Escorts guarantee visitors cannot commit misconduct.
    3. Escorts eliminate the need for visitor identification.
    4. Escorts should provide visitors with unrestricted access.

Correct Answer: 1

Explanation:

Escort requirements allow legitimate visitors to enter areas where independent access would not be appropriate. The escort can guide movement, help prevent accidental entry into unauthorized spaces, and provide organizational accountability for the visit. Policies should define who may serve as an escort, how many visitors can reasonably be supervised, and what happens if the escort must leave. Escorting complements visitor identification, authorization, badges, and access restrictions. Its effectiveness depends on personnel understanding that escort responsibility is an active security function rather than a formality.

Question 314.

A security professional is comparing passive and active vehicle barriers. What is the key distinction?

  1. Passive barriers always use electricity
    2. Active barriers can change position to permit authorized passage, while passive barriers generally remain fixed
    3. Passive barriers provide no vehicle resistance
    4. Active barriers never require maintenance

Correct Answer: 2

Explanation:

Passive vehicle barriers, such as certain fixed bollards or reinforced structures, remain in position and are commonly used where vehicle passage is not required. Active barriers can move to permit authorized vehicles and then return to a protective position. Active systems introduce additional considerations such as controls, power, safety devices, operating speed, maintenance, emergency procedures, and failure behavior. Either type should be selected according to credible vehicle threats, required performance, site geometry, traffic operations, and applicable tested barrier ratings where appropriate.

Question 315.

A security manager notices that employees routinely prop open a secure door while carrying materials between rooms. What is the most appropriate response?

  1. Permanently disable the door alarm
    2. Discipline every employee without examining the workflow
    3. Determine the operational need and redesign procedures or material movement so required security can be maintained without routine propping
    4. Remove the secure door

Correct Answer: 3

Explanation:

Repeated door propping often indicates a conflict between security controls and legitimate operations. Management should determine why personnel need repeated passage, how materials are transported, and whether door hardware, access permissions, staffing, carts, schedules, or another process can address the issue. Security expectations should also be reinforced. Simply disabling alarms creates a vulnerability, while enforcement alone may not correct an impractical workflow. Effective physical security supports legitimate operations while preventing convenience-driven practices from routinely defeating protective boundaries.

Question 316.

A security operations center receives so many low-value notifications that operators sometimes miss critical alarms. What should be done?

  1. Add every possible system notification to the same priority
    2. Remove all alarm displays
    3. Require operators to acknowledge alerts without assessment
    4. Review alarm rationalization, priorities, thresholds, workflows, interface design, and operator workload

Correct Answer: 4

Explanation:

Excessive notifications can create alarm overload and make important events harder to identify. The organization should determine which conditions genuinely require immediate operator attention and which can be logged, grouped, filtered, or handled differently. Priorities should reflect risk and required response. Interface design, staffing, procedures, and training should also support effective decision-making. Alarm rationalization does not mean suppressing meaningful events; it aims to ensure that actionable information reaches operators in a form that supports timely assessment and response.

Question 317.

Why should security personnel maintain records of unresolved security deficiencies?

  1. Tracking deficiencies supports accountability, prioritization, interim controls, escalation, and confirmation that corrective actions are completed.
    2. Documenting deficiencies automatically corrects them.
    3. Only deficiencies resulting in losses should be recorded.
    4. Records eliminate the need for responsible owners.

Correct Answer: 1

Explanation:

Security assessments, inspections, incidents, maintenance, and audits can identify deficiencies that cannot always be corrected immediately. A tracking process helps ensure those issues remain visible until they are resolved or formally accepted. Records can include severity, responsible owner, interim measures, target date, status, and verification of completion. Significant delays can be escalated to appropriate management. Without structured tracking, known vulnerabilities may be forgotten after the original assessment or meeting, leaving the organization exposed despite having previously identified the problem.

Question 318.

A security manager is considering installing glass-break sensors. What should be evaluated before selection?

  1. Only window dimensions
    2. Glazing type, expected attack, sensor technology, acoustic or vibration environment, coverage, placement, and testing requirements
    3. Only the number of occupants
    4. Only the manufacturer’s warranty length

Correct Answer: 2

Explanation:

Glass-break detection technologies are designed for particular glazing and attack characteristics. Acoustic sensors may respond differently from shock or vibration sensors, and environmental noise can influence some applications. The professional should understand the glass construction, protected opening, likely intrusion method, room acoustics, mounting requirements, coverage, and nuisance alarm sources. Testing should confirm performance after installation. Detection should also be coordinated with physical resistance, surveillance, alarm assessment, and response so that breaking the glazing does not immediately provide unrestricted access before intervention is possible.

Question 319.

An organization plans to dispose of obsolete access-control servers containing historical credential and event information. What should be done?

  1. Sell the servers without examining stored information
    2. Leave the data intact because the systems are obsolete
    3. Apply approved data sanitization or destruction procedures and document disposition according to information sensitivity and requirements
    4. Give the drives to employees for personal use

Correct Answer: 3

Explanation:

Obsolete security equipment can retain sensitive information such as credential records, personnel identifiers, event histories, system configurations, or network details. Disposal should therefore include appropriate sanitization or physical destruction based on the storage technology, information sensitivity, and organizational requirements. Asset disposition should also be documented when necessary for accountability. Simply deleting visible files may not adequately remove recoverable data. Security lifecycle planning should include secure retirement and disposal, not just acquisition, installation, operation, and maintenance.

Question 320.

A facility has implemented multiple new physical security controls after a serious incident. What is the most appropriate long-term management action?

  1. Assume the controls remain effective permanently because they were incident-driven
    2. Stop collecting incident information
    3. Avoid future changes to the security program
    4. Periodically reassess the controls, operating environment, threats, vulnerabilities, performance, and residual risk

Correct Answer: 4

Explanation:

Controls implemented after an incident address conditions understood at a particular point in time. Threats, operations, facilities, technology, staffing, and adversary methods can subsequently change. Equipment may also deteriorate or procedures may gradually be bypassed. Periodic reassessment helps determine whether controls continue to address relevant risks and whether their actual performance matches expectations. Incident trends, exercises, maintenance records, testing, audits, and operational feedback can support the review. Security should therefore be managed as a continuing risk process rather than a one-time reaction to past events.