View Full ASIS PSP Exam Dumps and Practice Test Dumps
Question 321.
A security professional is reviewing a facility where exterior doors use door-position switches. What is the primary security purpose of these devices?
- To identify whether a monitored door is physically open or closed and support detection of abnormal door conditions
2. To verify an employee’s biometric identity
3. To measure exterior illumination
4. To control camera resolution
Correct Answer: 1
Explanation:
Door-position switches provide information about the physical state of a monitored opening. When integrated with access control or intrusion detection, they can help identify conditions such as a door being forced open or remaining open longer than authorized. Their usefulness depends on appropriate alarm logic, timing, monitoring, and response procedures. The switch does not determine by itself whether a person is authorized; credential and request-to-exit information may be needed for that purpose. Functional testing should verify that actual door conditions generate the intended system events.
Question 322.
A security manager is evaluating whether a critical facility should have an alternate security operations center. What should primarily drive the decision?
- Whether another room is currently unused
2. The consequences of losing the primary center and the organization’s required continuity capability
3. The number of monitors in the primary center
4. Whether employees prefer another location
Correct Answer: 2
Explanation:
An alternate security operations capability may be justified when loss of the primary center would significantly impair alarm monitoring, communications, access management, incident coordination, or other essential functions. The organization should evaluate credible hazards, recovery objectives, staffing, communications, system access, power, and geographic or infrastructure separation. An alternate location should not share unnecessary common points of failure with the primary center. The required capability can range from limited emergency functionality to a fully redundant center depending on risk and continuity requirements.
Question 323.
A security professional discovers that sensitive security equipment can be reached through an unlocked telecommunications closet used by multiple contractors. What is the best response?
- Add more labels identifying the equipment
2. Allow contractors unrestricted access for convenience
3. Restrict and manage access to the closet according to the sensitivity of the equipment and legitimate work requirements
4. Remove equipment identification records
Correct Answer: 3
Explanation:
Telecommunications and equipment rooms can contain network switches, security controllers, communication circuits, and other components whose manipulation could affect multiple protective systems. Access should therefore be limited according to business need and equipment criticality. Contractors may require temporary or supervised access for legitimate maintenance, but unrestricted access can create unnecessary exposure. Electronic access control, key management, visitor procedures, monitoring, or other measures may be appropriate. Supporting infrastructure deserves protection because compromise of backend components can affect many security devices simultaneously.
Question 324.
An organization plans to introduce facial recognition into an existing surveillance system. What should be addressed before deployment?
- Only the number of cameras
2. Only the software purchase price
3. Only the size of the watch list
4. Operational purpose, accuracy, testing, privacy, legal requirements, data governance, false matches, and response procedures
Correct Answer: 4
Explanation:
Facial recognition introduces operational, technical, privacy, and governance considerations beyond conventional video surveillance. The organization should define why the capability is required and how alerts will be assessed before action is taken. Performance should be tested under representative conditions, including expected camera angles and lighting. Watch-list quality, access to biometric data, retention, legal requirements, and false-positive handling should also be addressed. Automated results should be incorporated into documented assessment procedures rather than automatically treated as proof of identity or wrongdoing.
Question 325.
What is the primary purpose of a perimeter clear zone between vegetation or structures and a security fence?
- To improve visibility and reduce opportunities for concealment, climbing assistance, or unnoticed approach
2. To eliminate the need for intrusion detection
3. To provide employee parking
4. To guarantee that the fence cannot be penetrated
Correct Answer: 1
Explanation:
A clear zone can improve observation by cameras and personnel while reducing concealment and objects that might assist climbing. It may also improve the performance of certain perimeter detection technologies and make evidence of disturbance easier to observe. The appropriate dimensions and treatment depend on terrain, property limits, security objectives, and operational requirements. Clear zones complement fences, lighting, detection, surveillance, and response. They should be maintained because vegetation, stored materials, construction activity, or other changes can gradually compromise the intended open area.
Question 326.
A security manager finds that guards cannot communicate by radio from a basement area containing critical equipment. What should be done?
- Require guards to avoid the basement
2. Conduct coverage testing and implement appropriate communications improvements or alternate methods for the dead zone
3. Eliminate all radio communications
4. Depend on guards shouting for assistance
Correct Answer: 2
Explanation:
Radio dead zones can prevent guards from reporting incidents, receiving instructions, requesting assistance, or acknowledging alarms. Coverage should be tested throughout areas where personnel may reasonably need communications, including basements, stairwells, mechanical spaces, parking structures, and remote exterior locations. Solutions might include repeaters, distributed antenna systems, alternative frequencies, fixed emergency communications, or other methods appropriate to the facility. Communication performance should also be periodically verified because building modifications and equipment changes can alter radio coverage.
Question 327.
A facility’s critical server room has water pipes running directly above electronic security equipment. What should the security professional recommend?
- Ignore the pipes because water is not a security issue
2. Remove all server-room access controls
3. Evaluate leak exposure and use appropriate relocation, shielding, leak detection, drainage, or other protective measures
4. Increase visitor badge printing
Correct Answer: 3
Explanation:
Water damage can disable critical electronic systems even when unauthorized access is well controlled. Pipes, roof leaks, sprinkler failures, condensation, and nearby plumbing should therefore be considered when protecting critical equipment. Where practical, equipment or piping may be relocated; otherwise, shielding, leak detection, drainage, monitoring, and response procedures may reduce exposure. Environmental protection is part of physical security resilience because loss of critical infrastructure can impair surveillance, access control, communications, and other essential protective functions.
Question 328.
A security manager wants to use a new video analytics platform that requires continuous cloud connectivity. What should be evaluated?
- Only the user-interface appearance
2. Only the number of available analytics features
3. Only the subscription price
4. Connectivity dependencies, data protection, service availability, latency, cybersecurity, failure behavior, and continuity requirements
Correct Answer: 4
Explanation:
Cloud-dependent security capabilities introduce dependencies beyond the local facility. Internet outages, provider disruptions, latency, authentication failures, or cybersecurity incidents may affect availability. The organization should understand what functions continue locally when connectivity is lost and how critical events are handled during an outage. Video or other security data transmitted externally may also require privacy, retention, contractual, and access controls. The technology should be evaluated against operational requirements and risk rather than selected solely for its feature set.
Question 329.
Why should a security manager compare leading and lagging security indicators?
- Leading indicators can show preventive activity or emerging conditions, while lagging indicators describe outcomes that have already occurred.
2. Both always measure exactly the same information.
3. Lagging indicators predict every future incident.
4. Leading indicators eliminate the need for incident data.
Correct Answer: 1
Explanation:
Lagging indicators commonly measure outcomes such as thefts, unauthorized entries, losses, or incidents that have already occurred. Leading indicators can include overdue maintenance, unresolved vulnerabilities, training completion, testing results, or other conditions that may provide earlier warning about security performance. Neither category is sufficient by itself. Using both can help management understand past outcomes while monitoring activities and conditions intended to prevent future problems. Metrics should remain connected to meaningful security objectives rather than being collected simply because they are easy to count.
Question 330.
A facility uses a guard-tour system requiring officers to scan checkpoints in a fixed sequence. What potential limitation should be considered?
- Checkpoints automatically eliminate all patrol risks
2. A rigid sequence may make patrol movement predictable and encourage focus on scanning rather than meaningful observation
3. Guard-tour systems prevent officers from reporting incidents
4. Checkpoints should replace all patrol supervision
Correct Answer: 2
Explanation:
Guard-tour systems can document that officers reached designated locations, but they do not prove that meaningful observation occurred. A rigid checkpoint sequence may also make patrol timing predictable. The system should support patrol objectives rather than turn the patrol into a mechanical scanning exercise. Routes and timing may incorporate appropriate variation while ensuring important areas receive required coverage. Supervisors should consider incident reporting, observation quality, response capability, and risk conditions alongside checkpoint completion when evaluating patrol effectiveness.
Question 331.
A security professional is evaluating a building with large air-intake openings near ground level. What should be considered?
- Only ventilation efficiency
2. Only exterior appearance
3. Whether the openings provide unauthorized access, tampering opportunities, or exposure requiring appropriate physical protection
4. Employee parking capacity
Correct Answer: 3
Explanation:
Ventilation openings, ducts, louvers, and similar penetrations can create physical access or tampering opportunities if their size and location permit. Security measures may include appropriately designed grilles, barriers, monitoring, or other controls that preserve required airflow, maintenance, and safety functions. The professional should consider both the opening and its connection to sensitive internal spaces. Building penetrations should be included in perimeter and envelope assessments because unauthorized entry does not necessarily occur through conventional doors and windows.
Question 332.
A security project has reached substantial completion, but several important deficiencies remain unresolved. What should occur before final acceptance?
- Ignore deficiencies because construction is almost complete
2. Pay no attention to testing results
3. Remove the deficiencies from project records
4. Document the deficiencies, assign corrective actions, verify completion, and confirm required performance before final acceptance
Correct Answer: 4
Explanation:
A punch list provides a structured method for documenting incomplete or deficient project work. Security-related deficiencies should be assessed according to their effect on required performance and corrected before final acceptance unless management formally approves another arrangement. Corrective work should be retested where necessary. Documentation, training, as-built information, and other contractual deliverables should also be reviewed. Final acceptance should reflect demonstrated completion of defined requirements rather than simply the passage of a construction milestone.
Question 333.
What is the principal benefit of separating public, controlled, restricted, and highly restricted areas within a facility?
- Security requirements can increase progressively as people move toward more sensitive assets and operations.
2. Every employee must receive access to every zone.
3. Zoning eliminates the need for authorization.
4. Public areas automatically become high-security areas.
Correct Answer: 1
Explanation:
Security zoning creates progressively controlled boundaries based on asset sensitivity and legitimate access needs. Public visitors may enter certain areas freely, while employee, restricted, and highly sensitive areas require increasingly limited authorization. This reduces unnecessary exposure and allows stronger controls to be concentrated where consequences are greatest. Zoning should consider circulation routes, elevators, stairwells, doors, visitor movement, emergency egress, and operational requirements. Effective zoning creates logical layers of protection rather than applying the same controls uniformly throughout an entire facility.
Question 334.
A security manager is evaluating a panic alarm used by employees working alone. What is most important to verify?
- The button’s color
2. Activation, alarm transmission, location identification, monitoring, response, testing, and employee training
3. The number of nearby cameras only
4. Whether the alarm makes a loud local sound
Correct Answer: 2
Explanation:
A panic or duress alarm must function as a complete process. Activation should reliably reach the correct monitoring point and provide enough information for personnel to understand where assistance is required. Response procedures should define who acts and how the situation is handled. Depending on the application, discreet operation may be more appropriate than an audible local alarm. Regular testing verifies the technical path, while training ensures employees understand when and how to activate the system without creating unnecessary confusion.
Question 335.
An organization wants to allow employees after-hours access only when there is a legitimate business need. Which approach is most appropriate?
- Give every employee permanent 24-hour access
2. Disable transaction logging after normal hours
3. Apply scheduled access permissions with controlled approval and exception processes for legitimate after-hours needs
4. Leave exterior doors unlocked overnight
Correct Answer: 3
Explanation:
Access privileges should reflect actual operational requirements. If most employees need access only during normal working periods, time schedules can reduce unnecessary exposure while allowing approved exceptions for overtime, maintenance, emergencies, or special projects. Exception procedures should identify appropriate authorization and duration. After-hours transactions should remain logged because unusual access may warrant review. Periodic analysis can also identify privileges that are broader than necessary. Time-based controls support least privilege without preventing legitimate work when appropriately administered.
Question 336.
A security manager learns that a manufacturer will discontinue support for a critical intrusion detection platform next year. What should be done?
- Wait until the platform fails completely
2. Ignore the announcement because the system currently works
3. Remove intrusion detection immediately
4. Develop a lifecycle transition plan addressing risk, replacement options, migration, budget, testing, training, and continuity
Correct Answer: 4
Explanation:
End-of-support status can increase operational and security risks because replacement parts, software fixes, technical assistance, or compatible components may become unavailable. Organizations should plan migration before failure forces an emergency replacement. The transition should consider system requirements, interfaces, data migration, procurement, installation, testing, training, and temporary protection during cutover. Budget planning is also important because large systems may require phased replacement. Lifecycle management allows security modernization to occur deliberately rather than reactively.
Question 337.
What is an important reason for periodically testing emergency generators supporting physical security systems?
- Testing helps verify that backup power can start, carry required loads, and operate as expected when normal power is unavailable.
2. A generator that started once will always start in the future.
3. Generator testing replaces preventive maintenance.
4. Security systems never depend on backup power.
Correct Answer: 1
Explanation:
Backup power is valuable only if it functions when normal electrical service fails. Periodic generator testing can reveal starting problems, battery issues, fuel concerns, transfer-switch failures, inadequate load capacity, or other deficiencies. Testing should reflect organizational requirements and may include relevant security-system loads rather than checking the generator in isolation. Fuel supply, maintenance, physical protection, and expected runtime also matter. Backup power should be evaluated as part of the complete resilience strategy for critical security functions.
Question 338.
A security professional is evaluating a high-value storage room where several employees know the same mechanical lock combination. What should be considered?
- Posting the combination inside the room
2. Individual accountability, need-to-know access, combination control, and changing the combination when authorization changes
3. Giving the combination to all employees
4. Eliminating the storage inventory
Correct Answer: 2
Explanation:
Shared lock combinations can be operationally necessary in some applications, but they reduce individual accountability and require disciplined management. The organization should limit knowledge to authorized personnel, protect the combination from unnecessary disclosure, and change it when individuals with knowledge no longer require access or when compromise is suspected. Where stronger accountability is required, individually attributable electronic access or dual-control arrangements may be preferable. Lock management should correspond to asset value, threat, access frequency, and operational requirements.
Question 339.
A security assessment finds that a remote building receives very few incidents but contains a uniquely critical asset. How should protection decisions be made?
- Use incident frequency alone and remove most controls
2. Assume remote facilities have no threats
3. Consider asset criticality, credible threats, vulnerabilities, consequences, response capability, and available controls rather than incident history alone
4. Apply exactly the same controls as every other building
Correct Answer: 3
Explanation:
Historical incidents are useful but do not fully define future risk, particularly when an asset has unusually significant consequences if compromised. Low incident frequency may reflect limited exposure, effective controls, incomplete reporting, or simply the absence of previous attempts. Security professionals should consider credible threats, vulnerabilities, asset criticality, response capability, and consequences alongside historical data. Risk-based decisions should reflect the specific facility rather than assuming that past experience alone determines the level of protection required.
Question 340.
After a physical security exercise reveals several weaknesses, what should management do next?
- Repeat the exercise immediately without reviewing findings
2. Keep findings undocumented to avoid criticism
3. Treat the exercise as complete once participants leave
4. Document lessons, assign corrective actions and owners, establish priorities and deadlines, and verify that improvements are implemented
Correct Answer: 4
Explanation:
Exercises provide value when identified weaknesses lead to measurable improvement. Findings should be documented clearly and translated into corrective actions with responsible owners and realistic completion dates. Higher-risk deficiencies may require immediate or interim measures. Management should track progress and verify that corrective actions actually resolve the identified problem rather than simply closing administrative tasks. Follow-up exercises or testing may then confirm improved performance. This process turns exercises into an ongoing capability-development tool rather than isolated training events.