View Full ASIS PSP Exam Dumps and Practice Test Dumps
Question 281.
A security professional is assessing a facility where dense vegetation has grown immediately beside the perimeter fence. What should be the primary concern?
- The vegetation may increase landscaping costs
2. Vegetation can provide concealment, climbing assistance, obstructed surveillance, and interference with perimeter detection
3. All vegetation automatically constitutes a security breach
4. Vegetation affects only the appearance of the property
Correct Answer: 2
Explanation:
Vegetation near a perimeter can influence several security functions. Dense growth may conceal individuals, obstruct camera or guard sightlines, provide climbing assistance, or interfere with fence-mounted and volumetric detection technologies. Security personnel should evaluate vegetation against the intended perimeter performance and establish appropriate maintenance standards. Complete removal is not necessarily required; landscaping can often support security when properly designed. Periodic inspections are important because vegetation changes over time, meaning a perimeter that originally provided good visibility may gradually develop significant vulnerabilities.
Question 282.
What is the primary purpose of establishing formal security acceptance criteria before a new system is installed?
- To define measurable conditions that must be satisfied before the organization accepts the system as meeting its requirements
2. To allow the installer to determine requirements after construction
3. To eliminate commissioning and testing
4. To guarantee that the system will never fail
Correct Answer: 1
Explanation:
Acceptance criteria establish an objective basis for determining whether delivered security systems meet contractual and operational requirements. Criteria may address detection performance, image quality, access-control functions, alarm transmission, integrations, documentation, training, response times, or other relevant characteristics. Defining them before installation reduces disputes about what constitutes satisfactory completion. Testing should demonstrate compliance, and unresolved deficiencies can be documented for correction. Acceptance confirms that defined requirements have been demonstrated at that point in time; it does not eliminate future maintenance or performance verification.
Question 283.
A company is considering visitor pre-registration for a large corporate campus. What is a major security benefit?
- It guarantees every visitor is trustworthy
2. It eliminates the need for identity verification
3. It allows expected visitors, hosts, authorization, and access requirements to be reviewed before arrival
4. It gives visitors unrestricted campus access
Correct Answer: 3
Explanation:
Pre-registration can improve visitor processing by allowing the organization to confirm the expected visitor, host, purpose, arrival information, and required access before the individual reaches the facility. It may reduce congestion and support advance screening where appropriate. However, pre-registration does not prove the identity or trustworthiness of the person who arrives. Appropriate identity verification, credential issuance, access restrictions, escort requirements, and checkout procedures may still be necessary. Visitor controls should reflect the sensitivity of the destination and organizational risk.
Question 284.
A security manager discovers that an access-control database is backed up regularly, but restoration has never been tested. What should be done?
- Assume successful backup means successful recovery
2. Stop creating backups
3. Delete older configuration information
4. Conduct controlled restoration testing to verify that required data and configurations can actually be recovered
Correct Answer: 4
Explanation:
A backup provides limited assurance unless the organization can successfully restore it. Files can be incomplete, corrupted, incompatible, incorrectly configured, or missing important dependencies. Controlled recovery testing verifies whether access permissions, configurations, databases, and other required information can be restored within acceptable timeframes. Testing should avoid unnecessarily disrupting production systems and should follow documented recovery procedures. Lessons from restoration exercises can identify gaps before an actual failure. Backup and recovery should therefore be treated as complementary capabilities rather than independent administrative tasks.
Question 285.
Why should a security risk assessment document important assumptions?
- Assumptions help users understand the basis of the analysis and identify when changed conditions may require reassessment.
2. Assumptions guarantee that risk calculations are correct.
3. Assumptions eliminate uncertainty.
4. Assumptions should remain secret from decision-makers.
Correct Answer: 1
Explanation:
Risk assessments are often based on assumptions about threats, occupancy, response capabilities, asset values, system performance, operating hours, or other conditions. Documenting these assumptions helps decision-makers understand the basis and limitations of the analysis. If an assumption later becomes invalid, the organization can recognize that the resulting risk conclusions may also need revision. Clear assumptions improve transparency and support future reassessment. They do not remove uncertainty, but they help prevent estimates or temporary conditions from being mistaken for permanent facts.
Question 286.
A facility wants to use an infrared beam system along a perimeter. What should be considered during design?
- Only the length of the fence
2. Alignment, terrain, vegetation, weather, mounting stability, coverage, obstruction, nuisance alarms, and maintenance
3. Only employee work schedules
4. Only the beam equipment’s color
Correct Answer: 2
Explanation:
Beam-based perimeter detection depends on maintaining appropriate transmission between components. Terrain changes, vegetation, snow, fog, animals, structural movement, misalignment, and objects placed in the beam path can affect performance. The design should consider mounting stability, detection zones, bypass opportunities, environmental conditions, testing, and maintenance access. Alarm assessment and response must also be integrated into the protective system. The suitability of beam detection should therefore be determined from site-specific conditions rather than simply the distance that equipment specifications claim it can cover.
Question 287.
A facility’s security team finds that contractors continue to use valid credentials several weeks after completing their work. Which process requires improvement?
- Camera maintenance
2. Perimeter lighting
3. Contractor offboarding and timely credential expiration or revocation
4. Parking-space allocation
Correct Answer: 3
Explanation:
Contractor access should be limited to legitimate work requirements and appropriate time periods. When assignments end, credentials that remain active create unnecessary exposure because former contractors may retain the ability to enter controlled areas. Offboarding should therefore include prompt credential revocation, return of badges or keys, removal of system privileges, and documentation where appropriate. Automatically defined expiration dates can reduce dependence on manual action. Periodic reconciliation of active contractor credentials against current contracts or assignments can identify permissions that were not removed correctly.
Question 288.
An organization is evaluating two security technologies with similar initial prices but substantially different maintenance and replacement requirements. What should guide the comparison?
- Purchase price alone
2. Which product has more advertising
3. Which system has the newest appearance
4. Total lifecycle cost together with performance, reliability, supportability, operational impact, and expected service life
Correct Answer: 4
Explanation:
Initial acquisition price represents only part of a security system’s economic impact. Installation, licensing, maintenance, staffing, training, consumables, network requirements, replacement parts, upgrades, and eventual disposal or replacement can substantially affect total cost. A lower-priced system may become more expensive if it requires frequent maintenance or has a short support lifecycle. Financial considerations should also be evaluated alongside required security performance and operational reliability. Lifecycle analysis gives management a more complete basis for comparing alternatives than initial purchase price alone.
Question 289.
What is an important purpose of line supervision in an intrusion alarm circuit?
- To detect certain faults or tampering affecting the alarm communication circuit rather than assuming an intact circuit is always present
2. To increase fence height
3. To identify employee job titles
4. To replace alarm response procedures
Correct Answer: 1
Explanation:
An unsupervised alarm circuit may be vulnerable to wiring faults or manipulation that prevents a sensor from communicating correctly. Line supervision can help identify conditions such as open circuits, shorts, or other changes depending on the system design. These conditions can then generate trouble or tamper indications requiring investigation. Supervision does not prevent all attacks or equipment failures, so physical protection, testing, maintenance, and response procedures remain necessary. Its purpose is to improve awareness of the integrity of critical alarm pathways.
Question 290.
A security professional is reviewing camera placement at a building entrance. The camera captures the tops of people’s heads but provides poor facial detail. What should be changed?
- Increase recording retention only
2. Adjust camera location, height, angle, lens, and field of view to meet the defined identification or recognition objective
3. Add more access cards
4. Increase perimeter fence height
Correct Answer: 2
Explanation:
Camera placement should be based on the surveillance task rather than merely providing general scene coverage. A camera mounted too high or at an excessive angle may capture movement while providing insufficient facial information for identification or recognition. The professional should define the required task and adjust position, lens, field of view, lighting, and other parameters accordingly. Actual images should then be tested under representative conditions. Recording more unusable video does not compensate for poor camera geometry at the point where useful information is needed.
Question 291.
A facility needs to protect a room containing critical network and security infrastructure. Which approach best supports layered protection?
- Rely exclusively on the room’s lock
2. Place a warning sign on the door only
3. Combine appropriate building access, restricted-area controls, door protection, detection, surveillance, environmental monitoring, and response
4. Allow unrestricted access during business hours
Correct Answer: 3
Explanation:
Critical infrastructure benefits from multiple complementary protective measures rather than dependence on one control. Building-level access can reduce general exposure, while additional restrictions around the critical room limit authorized populations further. Door hardware, intrusion detection, surveillance, environmental monitoring, logging, and response procedures can provide additional layers. The specific combination should reflect assessed risk and operational requirements. Layered protection increases the likelihood that failure or defeat of one measure does not immediately provide unrestricted access to the critical asset.
Question 292.
A security manager is planning a full-scale emergency exercise. What should be established before the exercise begins?
- A requirement that participants receive no safety information
2. A goal of deliberately disrupting normal operations as much as possible
3. No defined evaluation criteria
4. Objectives, scope, safety controls, participant roles, exercise boundaries, communications, and evaluation methods
Correct Answer: 4
Explanation:
A full-scale exercise can involve significant personnel and operational activity, so careful planning is essential. Objectives should identify what capabilities are being evaluated, while scope and exercise boundaries prevent unintended actions. Safety controls and clear communications distinguish simulated events from real emergencies. Evaluators should know what performance indicators to observe. Afterward, findings should be documented and corrective actions assigned. A successful exercise is not one that simply creates realistic activity; it should generate useful evidence about preparedness and identify opportunities for improvement.
Question 293.
Why should a facility periodically review who has access to security-system administration functions?
- Administrative privileges may remain after job changes or no longer be necessary, creating avoidable opportunities for misuse.
2. Every employee should eventually become an administrator.
3. Administrative privileges never change after installation.
4. Access reviews are required only after a security incident.
Correct Answer: 1
Explanation:
Security-system administrators may be able to create credentials, unlock doors, disable alarms, modify camera configurations, or change other critical settings. These privileges should be limited to personnel with a current business need. Job transfers, contractor changes, organizational restructuring, or temporary assignments can leave obsolete privileges active. Periodic reviews help identify unnecessary accounts and excessive permissions. Individual accountability, strong authentication, audit logging, and timely revocation further reduce the risk associated with privileged security-system access.
Question 294.
A security professional is evaluating a building entrance that must accommodate wheelchair users. What should guide the access-control design?
- Security requirements only, regardless of accessibility
2. Both required security performance and applicable accessibility, operational, and life-safety needs
3. The narrowest possible entrance
4. Separate access without equivalent security controls
Correct Answer: 2
Explanation:
Access-control systems should provide required security without creating inappropriate barriers for authorized users. Door widths, opening forces, credential-reader placement, turnstiles, gates, timing, and other design features may have accessibility implications. Alternative accessible routes should provide appropriate protection and should not become uncontrolled bypasses around stronger security measures. Security professionals should coordinate with architects, code specialists, facilities personnel, and users as appropriate. Integrating accessibility during design is more effective than attempting to retrofit an unsuitable entrance after installation.
Question 295.
A facility plans to issue temporary badges to visitors. Which design feature can improve security?
- Making temporary badges identical to permanent executive credentials
2. Giving all visitors the same unrestricted access profile
3. Clear visual differentiation combined with limited privileges and defined expiration
4. Removing visitor identification information from all records
Correct Answer: 3
Explanation:
Temporary badges should help personnel distinguish visitors from permanent employees while limiting electronic privileges to authorized destinations and time periods. Expiration reduces the risk that an unreturned badge remains usable after the visit. Depending on organizational needs, the badge may also identify escort requirements or other relevant status without unnecessarily exposing sensitive information. Visual differentiation supplements rather than replaces electronic access controls and employee awareness. The overall visitor-management process should address issuance, authorization, use, return, expiration, and investigation of lost credentials.
Question 296.
A security manager learns that a critical alarm communication path depends on commercial power at several intermediate network devices. What should be evaluated?
- Only the alarm sensor battery
2. The color of network equipment
3. Employee computer usage
4. End-to-end power dependencies and whether backup power supports all components needed for alarm transmission
Correct Answer: 4
Explanation:
Providing backup power only to the alarm panel does not ensure alarm communications will continue if intermediate switches, routers, radios, converters, or service equipment lose power. The manager should map the complete communication path and identify every component required to transmit alarms to the monitoring location. Backup duration and common dependencies should then be compared with continuity requirements. End-to-end analysis helps prevent false confidence created by protecting one component while overlooking another critical device in the same communication chain.
Question 297.
What is the main security purpose of a prohibited-items policy at a controlled facility?
- To define items that may not be introduced into specified areas and establish consistent authorization, screening, and response expectations
2. To guarantee that prohibited items can never enter
3. To replace access control
4. To eliminate the need for employee communication
Correct Answer: 1
Explanation:
A prohibited-items policy establishes organizational expectations regarding items that are restricted from specific facilities or areas. Effective implementation may require communication, signage, screening where appropriate and lawful, exception procedures, storage arrangements, and defined responses when prohibited items are discovered. Requirements should reflect organizational risk, legal obligations, and operational needs. A policy alone does not prevent introduction of restricted items, but it provides the framework needed for consistent enforcement and supports the design of appropriate physical security measures.
Question 298.
A security manager notices that guards routinely leave their radios charging at the control desk during patrols because of poor battery life. What should be done?
- Require guards to patrol without communications
2. Address battery, charging, equipment, and operational requirements so reliable communications are available during patrol duties
3. Eliminate patrols permanently
4. Depend entirely on personal mobile phones without evaluation
Correct Answer: 2
Explanation:
Reliable communications are important for guards who may need to report suspicious activity, request assistance, receive alarms, or coordinate emergency response. If battery limitations routinely cause officers to patrol without radios, the equipment and support process are not meeting operational requirements. The organization should evaluate battery condition, spare batteries, charging arrangements, radio coverage, equipment lifecycle, and patrol duration. Communication systems should be tested under actual operating conditions, including areas where structural features may create dead zones or weak reception.
Question 299.
A security professional discovers that confidential security plans are stored on an unrestricted shared drive accessible to most employees. What should be done?
- Print additional unrestricted copies
2. Publish the plans on the organization’s public website
3. Restrict access according to legitimate need and protect the plans through appropriate information-handling controls
4. Remove all security documentation permanently
Correct Answer: 3
Explanation:
Detailed security plans can reveal camera locations, alarm zones, response procedures, access points, system architecture, and other information that could assist someone attempting to defeat protective measures. Access should therefore be limited to personnel with legitimate responsibilities. Storage, transmission, printing, retention, and disposal should follow appropriate information-protection requirements. Restricting sensitive documentation does not mean eliminating it; accurate security information remains essential for operations, maintenance, emergency response, and future projects. The objective is controlled availability rather than unrestricted distribution.
Question 300.
After implementing several major security improvements, what should the organization do to determine whether the intended risk reduction has actually been achieved?
- Assume installation automatically produced the expected result
2. Evaluate only the amount of money spent
3. Wait for a serious incident before reviewing effectiveness
4. Verify control performance through testing, exercises, metrics, observations, incident data, and reassessment of residual risk
Correct Answer: 4
Explanation:
Security improvements should be evaluated after implementation to determine whether they deliver the intended protection. Equipment may not perform as expected, procedures may be bypassed, personnel may require additional training, or environmental and operational conditions may reduce effectiveness. Testing, exercises, performance metrics, inspections, alarm and incident data, and user observations can provide evidence of actual performance. The organization should then reassess residual risk and determine whether further treatment is justified. This closes the risk-management cycle by connecting investment decisions with measurable security outcomes.