ASIS PSP Practice Test Questions and Exam Dumps Part18 Q341-360

View Full ASIS PSP Exam Dumps and Practice Test Dumps

 

Question 341.

A security professional is evaluating an exterior door that provides access to a critical area. The door is strong, but the adjacent wall is lightweight construction. What should be the primary concern?

  1. The surrounding construction may provide an easier bypass than attacking the protected door
    2. The door should be repainted
    3. The electronic reader should be removed
    4. The wall has no relationship to physical security

Correct Answer: 1

Explanation:

Physical protection should be evaluated as a complete system rather than as isolated components. A highly resistant door provides limited value if an adversary can penetrate the adjacent wall more quickly and easily. The security professional should compare the resistance of the door, frame, hardware, wall, ceiling, floor, glazing, and penetrations against credible attack methods. Protection does not require every component to be identical, but obvious weak points should not undermine the required delay. Balanced construction helps ensure security investments contribute meaningfully to the overall protection objective.

Question 342.

What is the main purpose of a factory acceptance test for security equipment or systems?

  1. To replace all site testing after installation
    2. To verify specified functionality or performance before equipment is delivered or installed at the operational site
    3. To determine employee access privileges
    4. To approve future system modifications automatically

Correct Answer: 2

Explanation:

A factory acceptance test can verify important equipment or system functions before shipment, particularly for complex or customized security solutions. Testing may confirm hardware configuration, software functionality, interfaces, performance, and compliance with defined requirements. Discovering problems before delivery can reduce costly field corrections. However, factory testing does not demonstrate that the system will operate correctly after installation within the actual facility. Site acceptance and integrated testing remain important because cabling, networks, environmental conditions, interfaces, and field installation can introduce additional problems.

Question 343.

A security manager discovers that an access-control reader is positioned where unauthorized individuals can easily observe employees entering PINs. What should be considered?

  1. Increasing PIN length only
    2. Removing the door lock
    3. Reader placement, shielding, user behavior, authentication method, and measures to reduce observation of sensitive authentication information
    4. Posting valid PIN examples nearby

Correct Answer: 3

Explanation:

Authentication information can be compromised through observation even when the electronic system itself functions correctly. Reader and keypad placement should reduce unnecessary visibility from public or uncontrolled areas. Physical shielding, user awareness, alternative authentication methods, and appropriate entrance design may further reduce exposure. The required controls should reflect the sensitivity of the protected area and realistic observation opportunities. Security design should consider how people actually interact with equipment, because human and environmental factors can undermine otherwise technically sound authentication mechanisms.

Question 344.

A critical security system automatically installs software updates without prior testing. What risk should management address?

  1. Updates always improve availability
    2. Testing is unnecessary for security systems
    3. Automatic updates eliminate compatibility problems
    4. Uncontrolled updates may introduce incompatibility, configuration changes, outages, or other unintended effects on security operations

Correct Answer: 4

Explanation:

Security updates may correct important vulnerabilities, but uncontrolled installation can also affect drivers, integrations, databases, operating systems, or device compatibility. Critical physical security systems should use a managed update process that considers urgency, testing, backups, recovery, maintenance windows, and operational consequences. Emergency updates may require accelerated procedures when risk is significant. The objective is not to avoid updates, but to balance cybersecurity needs with system availability and reliable physical protection through disciplined change management.

Question 345.

Why should security personnel understand the difference between detection and assessment?

  1. Detection indicates that a condition or event may have occurred, while assessment determines what happened and what response is appropriate.
    2. Detection and assessment always mean exactly the same thing.
    3. Assessment must occur before any event is detected.
    4. Detection eliminates the need for response.

Correct Answer: 1

Explanation:

A sensor may detect motion, a door opening, fence disturbance, or another predefined condition, but the alarm alone may not explain the cause. Assessment provides additional information needed to determine whether the event represents an intrusion, environmental condition, equipment problem, or authorized activity. Assessment may use video, guards, communications, or other methods. Reliable assessment helps organizations avoid unnecessary responses while ensuring genuine incidents receive appropriate attention. Detection, assessment, delay, communications, and response should therefore operate as coordinated parts of the protection system.

Question 346.

A facility is considering a revolving security door for a controlled employee entrance. What should be evaluated before installation?

  1. Only the door’s appearance
    2. Throughput, individual passage control, emergency operation, accessibility, safety, authentication, entrapment concerns, and response procedures
    3. Only the number of nearby windows
    4. Only the manufacturer’s headquarters location

Correct Answer: 2

Explanation:

Security revolving doors can provide stronger control of individual passage than conventional doors, but they introduce operational and safety considerations. The organization should evaluate peak traffic, authentication, detection of multiple occupants, accessibility alternatives, emergency release, fire and life-safety requirements, and procedures for rejected users. The system should also be tested under normal and exception conditions. Entrance technology should support both the required security level and legitimate movement rather than creating unacceptable congestion or unsafe emergency behavior.

Question 347.

A security professional identifies an exterior electrical disconnect that can easily be operated from a public area and would disable important security equipment. What should be done?

  1. Add instructions showing how to operate it
    2. Ignore it because electrical equipment is not part of security
    3. Protect the disconnect against unauthorized operation while preserving legitimate emergency and maintenance access
    4. Permanently remove the electrical disconnect

Correct Answer: 3

Explanation:

Power infrastructure supporting security systems can become a vulnerability when unauthorized individuals can easily interrupt it. The professional should identify which security functions depend on the disconnect and determine appropriate physical protection, access restrictions, monitoring, or backup power. Any modification must preserve legitimate electrical safety, emergency, and maintenance requirements. Protecting cameras and access readers while leaving their power sources openly accessible creates an incomplete security design. Supporting utilities should therefore be included in physical security assessments.

Question 348.

A facility uses a third-party monitoring center for intrusion alarms. What should management evaluate?

  1. Only the monitoring company’s logo
    2. Only monthly service cost
    3. Only the number of employees at the facility
    4. Alarm transmission, service availability, escalation procedures, response coordination, testing, contractual requirements, and continuity capabilities

Correct Answer: 4

Explanation:

Outsourced monitoring becomes part of the organization’s security response chain. Management should understand how alarms reach the provider, how events are prioritized, who receives notifications, how escalation occurs, and what happens during communication or monitoring-center outages. Testing should verify the complete process rather than only the local alarm panel. Contracts or service agreements should define important performance and responsibility expectations. Third-party monitoring can provide valuable capability, but responsibility for understanding and managing the resulting security dependencies remains with the organization.

Question 349.

What is an important purpose of assigning an owner to each significant security risk?

  1. It establishes accountability for monitoring the risk and coordinating appropriate treatment or acceptance decisions.
    2. It transfers all consequences personally to the risk owner.
    3. It guarantees the risk will disappear.
    4. It eliminates management oversight.

Correct Answer: 1

Explanation:

Risk ownership helps ensure that identified exposures do not remain unaddressed because responsibility is unclear. A risk owner can monitor changing conditions, coordinate treatment activities, escalate concerns, and support decisions about residual risk. The owner does not necessarily perform every corrective action personally; implementation may involve security, facilities, information technology, operations, finance, or other functions. Clear accountability is particularly important when treatment requires multiple projects or extends over time. Risk ownership supports continuing management rather than one-time documentation.

Question 350.

A security manager is selecting a credential technology for a new campus. Which approach is most appropriate?

  1. Select the least expensive card regardless of requirements
    2. Evaluate security strength, interoperability, lifecycle, credential management, usability, scalability, and future system requirements
    3. Select technology solely because another company uses it
    4. Ignore reader and system compatibility

Correct Answer: 2

Explanation:

Credential technology can remain in service for many years, so selection should consider more than initial price. Security strength, resistance to unauthorized duplication, interoperability, reader compatibility, issuance processes, mobile or multi-application requirements, scalability, and future migration all matter. The organization should also consider how credentials are enrolled, activated, replaced, revoked, and audited. A campus-wide credential strategy can reduce fragmented technologies and improve lifecycle management. Selection should ultimately support the organization’s defined authentication and access-control requirements.

Question 351.

A high-security facility has an exterior fence with horizontal structural members on the public side that make climbing easier. What should be evaluated?

  1. Whether the fence is visually attractive
    2. Whether the fence is newly installed
    3. Anti-climb characteristics and whether the design unintentionally provides footholds or handholds
    4. Whether employees can touch the fence

Correct Answer: 3

Explanation:

Fence height alone does not determine resistance to climbing. Mesh size, horizontal rails, nearby objects, structural members, terrain, gates, and top treatments can influence how easily the barrier can be crossed. Where climbing is a credible concern, design should minimize features that provide convenient footholds or handholds while complying with applicable requirements. The fence should also be evaluated with detection, surveillance, clear zones, and response. Perimeter protection works best when the barrier’s actual construction supports the intended delay objective.

Question 352.

A security operations center relies heavily on one highly experienced operator who understands undocumented system workarounds. What should management do?

  1. Ensure only that operator can use the systems
    2. Prevent other employees from receiving training
    3. Accept the dependency because experience cannot be documented
    4. Document critical procedures, cross-train personnel, correct underlying system issues, and reduce dependence on one individual

Correct Answer: 4

Explanation:

Heavy dependence on one person’s undocumented knowledge creates a continuity risk. Illness, turnover, reassignment, or emergencies may leave other operators unable to perform essential tasks. Management should capture legitimate procedures, provide cross-training, and ensure documentation is current and accessible to authorized personnel. Informal workarounds should also be evaluated because they may indicate technical or procedural problems requiring correction. Resilience includes both technology and personnel capability, so critical security functions should not depend unnecessarily on a single individual’s knowledge.

Question 353.

Why should physical security personnel participate in planning for organizational mergers or acquisitions when facilities are affected?

  1. Changes may introduce new personnel, facilities, assets, systems, credentials, and risks requiring coordinated security integration.
    2. Mergers affect finance only.
    3. Existing access permissions should automatically be combined without review.
    4. Security systems never require integration after organizational changes.

Correct Answer: 1

Explanation:

Mergers and acquisitions can create significant physical security changes. New facilities may use different credential technologies, guard procedures, risk standards, visitor systems, and security architectures. Personnel roles and access requirements may also change rapidly. Early security involvement helps identify integration priorities, incompatible systems, excessive permissions, sensitive assets, and transitional vulnerabilities. A structured approach can establish common standards while allowing site-specific differences where justified. Organizational change should therefore trigger security reassessment rather than automatic combination of existing arrangements.

Question 354.

A facility is evaluating an active vehicle barrier at a busy entrance. Which safety-related consideration is especially important?

  1. Barrier color
    2. Vehicle detection, operating logic, warning devices, emergency procedures, and prevention of unintended barrier activation
    3. Employee badge photographs
    4. Nearby office furniture

Correct Answer: 2

Explanation:

Active vehicle barriers can stop or obstruct vehicles and therefore require carefully designed safety controls. Detection loops, traffic signals, warning devices, operating procedures, control logic, emergency overrides, and operator training can reduce the risk of accidental activation. Security performance against the defined vehicle threat remains important, but safety must be integrated into the design. Functional testing should include normal traffic, rejected vehicles, power failures, emergency operation, and other relevant scenarios. Barrier systems should be treated as complete operational systems rather than isolated mechanical devices.

Question 355.

A security manager discovers that access permissions are assigned directly to individual employees without standardized role definitions. What improvement could simplify administration?

  1. Eliminate authorization reviews
    2. Give every employee identical permissions
    3. Use appropriately defined role-based access profiles while retaining processes for justified exceptions
    4. Allow employees to choose their own restricted areas

Correct Answer: 3

Explanation:

Role-based access profiles can simplify administration by linking common job responsibilities to predefined physical access privileges. When employees enter or leave roles, administrators can assign or remove appropriate profiles rather than managing numerous individual doors manually. Roles should be carefully designed to avoid granting unnecessary access, and exceptions should be documented and periodically reviewed. Role-based administration does not eliminate the need for authorization or access reviews, but it can improve consistency, scalability, and accuracy across larger organizations.

Question 356.

An organization wants to evaluate the resilience of its access-control system during a network outage. What is the best method?

  1. Review the product brochure only
    2. Assume local controllers will behave correctly
    3. Wait for an accidental outage
    4. Conduct controlled testing of network-loss scenarios and verify door behavior, local authorization, event storage, alarms, and recovery

Correct Answer: 4

Explanation:

Controlled outage testing can reveal how access-control components actually behave when communications to central servers are unavailable. The organization should verify whether local controllers continue making expected access decisions, what happens to alarms and remote commands, whether events are stored, and how information synchronizes after restoration. Emergency and failure behaviors should match documented requirements. Testing should be carefully planned to avoid unsafe or uncontrolled conditions. Demonstrated performance provides stronger assurance than assumptions based solely on system architecture or vendor documentation.

Question 357.

What is an important objective of physical security awareness training for ordinary employees?

  1. Help employees understand relevant security responsibilities, recognize concerning conditions, follow access procedures, and report issues appropriately.
    2. Train every employee to administer security servers.
    3. Eliminate the need for professional security personnel.
    4. Encourage employees to investigate dangerous incidents personally.

Correct Answer: 1

Explanation:

Employees interact with physical security controls every day and can either strengthen or unintentionally weaken them. Awareness training can address credential protection, tailgating, visitor procedures, suspicious activity reporting, emergency actions, prohibited practices, and other responsibilities relevant to the workplace. Training should make clear that employees should report concerns through appropriate channels rather than placing themselves in danger. Effective awareness programs reinforce expected behavior and help create a culture in which security controls are understood as part of normal organizational operations.

Question 358.

A security professional is assessing a facility where emergency exit doors frequently generate held-open alarms during breaks. What should be done?

  1. Permanently suppress the alarms
    2. Investigate why the doors are being held open and address operational behavior, hardware, procedures, and security requirements
    3. Remove all emergency exits
    4. Increase video retention without examining the doors

Correct Answer: 2

Explanation:

Repeated held-open alarms may indicate employee behavior, inadequate break-area access, door hardware problems, poor alarm timing, or another operational issue. The organization should identify the actual cause before changing controls. Emergency exits must continue to satisfy applicable egress requirements while preventing inappropriate entry or prolonged opening where security requires it. Corrective measures could involve education, hardware adjustment, alternate routes, monitoring, or procedural changes. Simply suppressing alarms can hide genuine unauthorized access and undermine the purpose of door monitoring.

Question 359.

A facility needs to protect valuable portable equipment that frequently moves between departments. Which control is most appropriate?

  1. Rely exclusively on perimeter fencing
    2. Allow unrestricted movement because the equipment remains inside the building
    3. Establish asset identification, authorized transfer, inventory reconciliation, custody, and exception-reporting procedures appropriate to value and risk
    4. Stop recording equipment locations

Correct Answer: 3

Explanation:

Portable high-value assets can be vulnerable even inside controlled facilities because they move between locations and authorized users. Asset tags, inventories, transfer records, custody procedures, secure storage, and periodic reconciliation can improve accountability. The organization should determine who may move equipment, how transfers are recorded, and what happens when discrepancies occur. Electronic tracking or surveillance may be useful in some environments, but controls should reflect asset value and operational practicality. Perimeter protection alone does not address internal movement and potential insider loss.

Question 360.

Management wants to know whether the physical security program remains aligned with business operations after several years of organizational growth. What should the security manager do?

  1. Review only the original security plan
    2. Assume growth does not affect security requirements
    3. Add more cameras without analysis
    4. Conduct a current risk and program review covering assets, facilities, operations, threats, vulnerabilities, controls, performance, and organizational changes

Correct Answer: 4

Explanation:

Organizational growth can introduce new assets, facilities, employees, contractors, technologies, business processes, and dependencies. Controls that were appropriate several years earlier may no longer provide adequate coverage or may unnecessarily restrict changed operations. A current review should examine risk, system performance, incidents, maintenance, access requirements, emergency arrangements, and other relevant changes. Findings can then guide updated priorities and investments. Physical security programs should evolve with the organization rather than remain anchored to assumptions made when operations were smaller or substantially different.