View Full ASIS PSP Exam Dumps and Practice Test Dumps
Question 221.
A security professional is evaluating a perimeter gate that remains open for extended periods while multiple delivery vehicles enter. What is the most appropriate concern?
- The gate’s paint may fade faster
2. Extended opening periods can create opportunities for unauthorized vehicles or pedestrians to enter without proper verification
3. Delivery vehicles should never use gates
4. The gate should remain permanently open
Correct Answer: 2
Explanation:
A controlled gate provides limited protection when it remains open long enough for unauthorized traffic to pass through without verification. The security professional should evaluate delivery volume, gate operating time, vehicle queuing, credential procedures, guard visibility, surveillance, and methods for detecting or preventing unauthorized following. Solutions might include procedural changes, improved gate equipment, separate delivery processing, or additional controls. The objective is to accommodate legitimate traffic while maintaining accountability for vehicles and individuals crossing the perimeter boundary.
Question 222.
What is the primary purpose of conducting a site security survey before recommending major physical security improvements?
- To systematically examine existing conditions, assets, vulnerabilities, controls, operations, and physical characteristics relevant to security
2. To guarantee management will approve every recommendation
3. To replace threat and risk analysis permanently
4. To determine only how many cameras are installed
Correct Answer: 1
Explanation:
A security survey provides direct information about how a facility is configured and how protective measures operate in practice. It may examine boundaries, buildings, access points, lighting, locks, alarms, surveillance, guard operations, critical assets, utilities, and surrounding conditions. Interviews and document reviews can supplement physical observations. Survey findings help security professionals identify weaknesses and develop recommendations that reflect actual site conditions. A survey is an important input to security planning, but recommendations should still be connected to relevant threats, consequences, operational requirements, and risk.
Question 223.
A facility uses motion detectors in a warehouse where moving equipment frequently causes nuisance alarms. What should the security manager do?
- Ignore every future alarm from the warehouse
2. Permanently bypass all intrusion detection
3. Evaluate sensor type, placement, configuration, environmental conditions, and operational activity to reduce nuisance alarms while preserving detection
4. Eliminate warehouse operations
Correct Answer: 3
Explanation:
Frequent nuisance alarms can consume response resources and reduce confidence in the alarm system. The manager should identify what is activating the sensors and determine whether placement, sensitivity, technology, masking, operating schedules, or procedures should be changed. A different sensing technology or combination of technologies may sometimes be more suitable. Simply bypassing detection can create an unacceptable vulnerability. The goal is to achieve reliable detection of relevant activity while minimizing predictable alarms caused by legitimate environmental or operational conditions.
Question 224.
A security system uses default administrator passwords on several network-connected cameras. What should be done?
- Publish the passwords for maintenance convenience
2. Keep them because factory passwords are always secure
3. Disable camera authentication
4. Replace default credentials with appropriately managed unique credentials and restrict administrative access
Correct Answer: 4
Explanation:
Default credentials can be widely known or easily discovered, creating unnecessary risk for network-connected physical security equipment. Administrative accounts should be protected with appropriately strong authentication and limited to authorized personnel. Credential management should address issuance, storage, changes, revocation, and accountability. Network restrictions and logging can provide additional protection. Cameras, controllers, recorders, and similar devices should be treated as security-sensitive systems because unauthorized administrative access could allow an individual to disable, alter, or misuse important protective capabilities.
Question 225.
Why should a security professional distinguish between risk avoidance and risk mitigation?
- Avoidance eliminates the activity or exposure creating the risk, while mitigation applies controls intended to reduce the risk.
2. Both terms always mean exactly the same thing.
3. Mitigation requires eliminating the asset.
4. Avoidance means purchasing insurance.
Correct Answer: 1
Explanation:
Risk treatment can take different forms depending on organizational objectives and available options. Risk avoidance involves discontinuing or changing an activity so the particular exposure no longer exists. Mitigation retains the activity but introduces measures intended to reduce likelihood, vulnerability, consequence, or another component of risk. Other treatment options can include transfer and acceptance. Understanding these distinctions helps management make deliberate decisions rather than assuming that every risk requires additional physical security equipment. Treatment choices should be documented and aligned with organizational risk tolerance.
Question 226.
A high-security facility is considering optical turnstiles for an employee lobby. What should be evaluated before selection?
- Only their architectural appearance
2. Throughput, detection capability, tailgating performance, accessibility, emergency behavior, staffing, and integration with access control
3. Only the number of available finishes
4. Only employee height
Correct Answer: 2
Explanation:
Optical turnstiles can support controlled pedestrian movement, but performance depends on the security objective and operating environment. The organization should evaluate how effectively the equipment detects unauthorized passage, expected traffic volume, accessibility requirements, emergency egress, visitor handling, alarm response, and integration with credential systems. Some installations may also require nearby security personnel to respond to violations. Testing realistic peak traffic and exception conditions helps determine whether the selected configuration provides both acceptable throughput and the required level of access control.
Question 227.
A security professional discovers that an electronic lock is installed on a weak hollow door and damaged frame. What principle should guide corrective action?
- Electronic locks automatically compensate for structural weakness
2. The credential reader is the only component that matters
3. The entire door, frame, lock, hardware, hinges, and surrounding construction should provide balanced protection
4. Replace the access cards only
Correct Answer: 3
Explanation:
A secure opening performs as an assembly. A strong electronic lock provides little delay if the door, frame, hinges, glazing, or surrounding construction can be defeated easily. Security professionals should therefore evaluate the complete opening against credible attack methods and required performance. Corrective action might involve reinforcing or replacing several components rather than upgrading the lock alone. Balanced protection reduces the likelihood that investment in one strong component simply redirects an adversary toward an obvious weaker element.
Question 228.
A facility plans to change its emergency evacuation routes because of construction. What should the security team do?
- Ignore the change because evacuation is solely a safety matter
2. Lock temporary evacuation routes after normal business hours regardless of requirements
3. Disable all access controls during construction
4. Coordinate temporary security, access, egress, accountability, and emergency-response arrangements with appropriate stakeholders
Correct Answer: 4
Explanation:
Construction can change normal entrances, exits, evacuation routes, barriers, surveillance coverage, and responder access. Security personnel should coordinate with safety, facilities, construction teams, emergency planners, and other relevant stakeholders so temporary arrangements preserve both protection and required egress. Temporary doors or routes may require alarms, guards, barriers, lighting, signage, or revised procedures. Conditions should be reviewed throughout the project because construction environments change rapidly. Temporary security should receive deliberate planning rather than being treated as an informal exception.
Question 229.
What is an important purpose of security system audit trails?
- They provide records of significant user and system activities that can support accountability, troubleshooting, and investigations.
2. They prevent all unauthorized actions automatically.
3. They eliminate the need for authentication.
4. They should be editable by every system user.
Correct Answer: 1
Explanation:
Audit trails can record administrative logins, configuration changes, credential modifications, alarm acknowledgments, remote door commands, and other important actions. These records help determine who performed an action and when, which supports accountability and investigation. Audit logs should be protected against unauthorized alteration and retained according to legitimate operational and organizational requirements. Logging alone does not prevent misuse, so appropriate authentication, authorization, monitoring, and management oversight remain necessary. Audit trails are most valuable when they are accurate, protected, and actually reviewed when appropriate.
Question 230.
A security manager wants to determine whether a proposed camera can identify individuals at a specific entrance. What is the best method?
- Choose the camera with the highest advertised resolution
2. Define the identification requirement and verify actual image performance at the required distance, angle, lighting, and scene conditions
3. Select the camera with the largest housing
4. Evaluate only storage capacity
Correct Answer: 2
Explanation:
Resolution alone does not determine whether a surveillance image can support identification. Distance, field of view, target size, lens selection, angle, lighting, motion, compression, focus, and other factors influence usable image detail. The security professional should first define the surveillance task and then verify performance under representative conditions. Design calculations can support selection, but practical testing can reveal environmental issues that specifications do not fully capture. Cameras should be evaluated according to the operational information they must provide rather than isolated technical numbers.
Question 231.
A company wants to reduce the risk associated with one employee having complete control over issuing high-security credentials. What control is most appropriate?
- Give the employee additional unrestricted privileges
2. Eliminate credential records
3. Apply separation of duties or dual authorization to sensitive credential-administration activities where justified
4. Allow employees to issue their own credentials
Correct Answer: 3
Explanation:
Sensitive administrative functions can create insider risk when one individual can authorize, issue, modify, and conceal inappropriate access without independent oversight. Separation of duties divides important responsibilities among different individuals, while dual authorization can require additional approval for particularly sensitive actions. The level of control should reflect risk and operational practicality. Administrative actions should also be appropriately logged and reviewed. These measures improve accountability and reduce dependence on the integrity or availability of a single administrator.
Question 232.
A critical intrusion detection system has no documented procedure for operation during maintenance outages. What should the security manager establish?
- A rule that maintenance can never occur
2. Automatic acceptance of the outage risk
3. Permanent disabling of the affected sensors
4. An impairment process covering authorization, compensating measures, notification, outage duration, restoration, and testing
Correct Answer: 4
Explanation:
Security systems inevitably require maintenance, repair, and modification. An impairment procedure provides a controlled method for managing periods when protection is reduced. It should identify who can authorize the impairment, what areas are affected, whether compensating controls are required, who must be informed, and how restoration will be verified. Outages should not remain active longer than necessary. Testing after maintenance is especially important because equipment that appears restored may still have configuration, communication, or coverage problems.
Question 233.
Why should a security manager review the number of false or nuisance alarms generated by a system?
- Excessive unwanted alarms can consume resources, reduce operator confidence, and obscure genuine security events.
2. Every false alarm proves the system should be removed.
3. Alarm rates have no effect on security performance.
4. A higher nuisance alarm rate always indicates stronger protection.
Correct Answer: 1
Explanation:
A system that produces excessive nuisance alarms can create alarm fatigue and waste assessment and response resources. Personnel may become slower to react or begin assuming that recurring alarms are unimportant. Alarm data should therefore be analyzed to identify problematic devices, environmental causes, configuration issues, or operational practices. Corrective actions should reduce unwanted alarms without sacrificing required detection capability. Alarm quality is an important performance consideration because effective detection depends on both sensitivity to relevant events and manageable rates of non-actionable activations.
Question 234.
A security professional is evaluating the use of laminated security glazing at a vulnerable entrance. What should be considered?
- Only glass thickness
2. The complete glazing system, including glass, framing, anchorage, threat, required performance, and surrounding construction
3. Only the window tint
4. The number of employees who can see the window
Correct Answer: 2
Explanation:
Security glazing performance depends on more than the glass itself. A strong pane installed in a weak frame may fail as a complete assembly. The professional should consider the relevant threat, required resistance or delay, glazing composition, frame, anchorage, opening size, surrounding wall construction, and installation quality. Safety, emergency, architectural, and environmental requirements may also apply. Protection should be evaluated as a system so that strengthening the glazing does not simply shift failure to an adjacent component.
Question 235.
A facility uses electronic access records to estimate which employees are inside during an emergency. What limitation should be recognized?
- Access records always provide exact real-time occupancy
2. Every person entering a building always badges out
3. Tailgating, missed exit transactions, shared credentials, system outages, and emergency movement can make occupancy data incomplete
4. Access-control records can never provide useful information
Correct Answer: 3
Explanation:
Access-control data can assist emergency accountability, but it should not automatically be treated as a perfect occupancy list. People may enter through uncontrolled routes, follow another person, fail to present credentials on exit, use incorrect credentials, or move during an emergency without generating normal transactions. System outages can create additional gaps. If access data is used for accountability, the organization should understand these limitations and consider complementary procedures such as muster processes, supervisor accountability, visitor records, or other appropriate methods.
Question 236.
An organization is replacing several security devices that are no longer supported by the manufacturer. What should be considered during replacement planning?
- Only the purchase price of new devices
2. Only whether the new devices look similar
3. Only the installation schedule
4. Compatibility, migration, security, supportability, training, testing, lifecycle cost, and continuity during transition
Correct Answer: 4
Explanation:
Replacing obsolete security equipment can affect interfaces, databases, procedures, training, and ongoing operations. The organization should understand how old and new components will coexist during migration and whether temporary vulnerabilities will arise. Supportability, cybersecurity, integration, spare parts, lifecycle cost, and expected service life should also influence selection. Testing is necessary before relying on the replacement equipment. A structured transition plan reduces the likelihood that modernization creates unexpected gaps in protection or interrupts essential security operations.
Question 237.
What is the purpose of using tamper-evident seals in appropriate physical security applications?
- To provide visible evidence that a protected container, enclosure, or item may have been opened or disturbed
2. To make the protected item impossible to access
3. To replace all locks and access controls
4. To eliminate inventory procedures
Correct Answer: 1
Explanation:
Tamper-evident seals are designed to indicate that an item or enclosure may have been accessed or altered. They can support accountability for containers, equipment, shipments, or other assets when used within appropriate procedures. Seal identifiers, issuance, inspection, replacement, and discrepancy reporting may need to be controlled depending on the application. A seal generally provides evidence rather than significant physical resistance, so it should not be confused with a strong barrier. Its value depends on personnel actually inspecting and responding to signs of tampering.
Question 238.
A security manager wants to improve patrol coverage without simply increasing staffing. Which approach is most appropriate?
- Require officers to remain at fixed desks
2. Analyze risk, patrol objectives, routes, timing, workload, technology support, and deployment patterns
3. Eliminate patrol documentation
4. Require every patrol to follow an identical route
Correct Answer: 2
Explanation:
Patrol resources should be deployed according to security objectives and risk. Analysis can identify which areas require frequent observation, which activities occur at particular times, and where fixed posts or technology already provide coverage. Guard-tour systems, communications, alarms, and surveillance may help direct officers efficiently, but technology should support rather than replace judgment. Appropriate variation in routes can reduce predictability. The goal is to improve meaningful security coverage and response capability rather than merely maximizing the number of checkpoints visited.
Question 239.
A high-value asset must be transferred between two secure areas within a large facility. What should guide the security arrangements?
- Employee convenience alone
2. The shortest route regardless of exposure
3. Asset value and criticality, route vulnerabilities, timing, custody, authorization, monitoring, and credible threats
4. The appearance of the transport container
Correct Answer: 3
Explanation:
Assets can become more vulnerable while moving between otherwise secure locations. Security planning should consider who is authorized to handle the asset, how custody is documented, the route used, periods of exposure, predictable schedules, and relevant threats. Depending on risk, measures could include secure containers, escorts, surveillance, controlled timing, alternate routes, or documented transfers. The appropriate level of protection should reflect the potential consequences of loss or compromise rather than relying solely on the security of the origin and destination.
Question 240.
A physical security program has accumulated numerous temporary exceptions to normal access-control procedures. What should management do?
- Convert every exception into permanent unrestricted access
2. Ignore exceptions if no incident has occurred
3. Stop documenting exceptions
4. Periodically review exceptions for continued need, authorization, risk, expiration, and opportunities to restore standard controls
Correct Answer: 4
Explanation:
Temporary exceptions can gradually become permanent vulnerabilities if they are not actively managed. Management should know why each exception exists, who approved it, what risk it creates, and when it should expire. Compensating controls may be necessary while an exception remains active. Periodic review can identify obsolete exceptions and operational problems that should be corrected rather than continually bypassed. Formal exception management helps preserve the integrity of access-control standards while allowing legitimate short-term business needs to be accommodated.