ASIS PSP Practice Test Questions and Exam Dumps Part19 Q361-380

View Full ASIS PSP Exam Dumps and Practice Test Dumps

 

Question 361.

A security professional is evaluating a facility with a large number of roof-mounted HVAC units. Which physical security issue should receive particular attention?

  1. Whether rooftop equipment and associated openings provide unauthorized access routes into protected spaces
    2. Whether all HVAC units are the same color
    3. Whether employees can see the equipment from offices
    4. Whether the equipment manufacturer also produces access-control systems

Correct Answer: 1

Explanation:

Rooftop equipment can create less obvious paths into a facility. HVAC openings, service hatches, roof doors, ladders, ducts, and adjacent structures should be assessed for their potential to provide unauthorized access. The professional should also consider how individuals can reach the roof and whether critical equipment is vulnerable to tampering. Appropriate barriers, locks, detection, surveillance, or other controls may be justified according to risk. Physical security assessments should include roofs and penetrations rather than concentrating exclusively on ground-level doors and windows.

Question 362.

What is the primary advantage of a full-height mechanical turnstile at an appropriate controlled entrance?

  1. It automatically verifies every person’s identity without credentials.
    2. It can provide stronger control of individual pedestrian passage than an ordinary unlocked doorway.
    3. It eliminates all emergency-egress requirements.
    4. It allows unlimited simultaneous passage.

Correct Answer: 2

Explanation:

A full-height turnstile can physically regulate pedestrian movement and make casual tailgating more difficult than through a conventional door. It is commonly integrated with an access-control credential system so authorized users are permitted to pass individually. However, throughput, accessibility, emergency egress, safety, visitor handling, and potential bypass routes must be considered. A turnstile does not independently prove identity unless combined with appropriate authentication. Its effectiveness depends on how it is integrated into the surrounding boundary and overall access-control process.

Question 363.

A security manager discovers that video evidence from an important incident was overwritten before investigators requested it. What should be reviewed?

  1. Only the camera mounting height
    2. Employee badge colors
    3. Video retention requirements, incident preservation procedures, storage capacity, and processes for placing relevant recordings on hold
    4. The number of monitors in the control room

Correct Answer: 3

Explanation:

Routine video retention periods may be adequate for normal operations but insufficient if relevant recordings are not preserved after an incident becomes known. Organizations should establish procedures for identifying, exporting, protecting, and retaining potentially relevant footage according to investigative, legal, privacy, and organizational requirements. Storage capacity should support the defined retention period at actual recording settings. Personnel should also know when evidence preservation is required. Proper handling helps prevent useful video from being automatically overwritten during an ongoing investigation.

Question 364.

A security professional is reviewing an entrance where metal detection screening is being considered. What should be determined first?

  1. Which detector has the most lights
    2. Whether every employee likes screening
    3. Whether the equipment can replace access control
    4. The screening objective, prohibited-item policy, threat basis, legal requirements, throughput, staffing, alarm-resolution process, and operating procedures

Correct Answer: 4

Explanation:

Screening technology should be selected only after the organization defines what it is trying to detect and how alarms will be handled. The security professional should consider credible threats, prohibited-item policies, applicable legal requirements, expected traffic, staffing, privacy, secondary screening, and procedures for discovered items. Equipment sensitivity must balance detection needs with operational throughput and nuisance alarms. Screening should operate as part of a broader entrance-security process rather than being treated as a stand-alone technology that automatically resolves every risk.

Question 365.

What is the primary purpose of maintaining a security incident log?

  1. To create a consistent record that supports investigation, trend analysis, follow-up, accountability, and future risk assessment
    2. To guarantee that similar incidents never happen again
    3. To replace emergency response procedures
    4. To record only incidents that cause financial loss

Correct Answer: 1

Explanation:

Consistent incident records help an organization understand what occurred, when and where it happened, what actions were taken, and whether follow-up remains necessary. Over time, incident logs can reveal recurring locations, methods, timing, or control failures that might not be obvious from individual events. Records should use consistent classifications and contain information appropriate to organizational requirements. Access and retention should also be controlled because incident records may contain sensitive information. Reliable incident data strengthens both operational response and future risk assessment.

Question 366.

A facility is considering microwave intrusion sensors for an exterior application. Which factor should receive particular attention?

  1. Office occupancy only
    2. Detection-zone characteristics, environmental movement, terrain, nearby objects, interference, nuisance alarm sources, and boundary control
    3. Employee uniform design
    4. Visitor badge expiration only

Correct Answer: 2

Explanation:

Microwave sensors create detection fields whose behavior depends on installation geometry and the surrounding environment. Moving vegetation, water, vehicles, animals, terrain, nearby structures, or other conditions may influence performance. Designers should understand the actual detection pattern and ensure that coverage remains within the intended protected area where practical. Calibration, testing, maintenance, alarm assessment, and response are also important. Sensor technology should be matched to site conditions and the intrusion methods it is expected to detect rather than selected solely from nominal range specifications.

Question 367.

An organization wants to reduce the risk associated with employees sharing access-control PINs. Which measure is most appropriate?

  1. Display all PINs at the security desk
    2. Assign one PIN to each department
    3. Use individually attributable authentication, reinforce credential-protection requirements, and monitor for suspicious use patterns
    4. Disable access logging

Correct Answer: 3

Explanation:

Shared authentication information weakens accountability because the system cannot reliably determine which person used it. Individual PINs or other individually attributable credentials improve traceability, although users must still protect them from disclosure. Security awareness, appropriate authentication design, transaction monitoring, and investigation of unusual access patterns can further reduce risk. For higher-security areas, PINs may be combined with another factor. Authentication controls should support both authorization and accountability rather than becoming shared secrets known by broad groups of users.

Question 368.

A security manager is reviewing the use of proprietary security-system technology. What lifecycle concern should be considered?

  1. Proprietary systems always cost less
    2. Proprietary systems never require upgrades
    3. Open systems cannot provide security
    4. Dependence on one vendor may affect future integration, support, replacement options, pricing, and migration flexibility

Correct Answer: 4

Explanation:

Proprietary technology may provide valuable functionality, but organizations should understand the lifecycle implications of dependence on a particular vendor or ecosystem. Future expansion, integration, software licensing, replacement parts, technical support, and migration may be constrained. Open interfaces can provide flexibility, but they also require careful cybersecurity and compatibility management. Neither approach is automatically superior. The security professional should evaluate performance, supportability, total lifecycle cost, interoperability, and organizational requirements before making a long-term platform decision.

Question 369.

Why should security personnel verify that emergency responder key boxes contain current keys?

  1. Outdated or incorrect keys can delay authorized emergency access when rapid entry is required.
    2. Key boxes should contain every organizational key.
    3. Emergency responders never use facility keys.
    4. Key verification eliminates the need for access control.

Correct Answer: 1

Explanation:

Emergency responder key boxes or similar controlled-access arrangements can support rapid entry during fires or other emergencies. Building renovations, lock changes, rekeying, and access-control upgrades can leave stored keys obsolete if the contents are not updated. Periodic verification helps ensure the intended doors can still be opened. The box itself should also receive appropriate physical protection and access control. Emergency access arrangements should be coordinated with relevant authorities and maintained as carefully as normal security credentials.

Question 370.

A security manager is deciding between accepting a vulnerability and implementing an expensive corrective measure. What information is most useful?

  1. The age of the security department
    2. The assessed risk, expected risk reduction, implementation and lifecycle costs, operational effects, alternatives, and residual risk
    3. The number of pages in the assessment
    4. The popularity of the proposed technology

Correct Answer: 2

Explanation:

Risk treatment decisions should be based on the significance of the exposure and the expected effect of available alternatives. Management should understand the credible threat, vulnerability, consequences, existing controls, proposed risk reduction, costs, operational impacts, and residual risk. Expensive measures are not automatically justified, nor should a vulnerability be accepted simply because remediation is costly. The analysis should provide decision-makers with enough information to determine whether mitigation, acceptance, transfer, avoidance, or another treatment is appropriate.

Question 371.

A security professional finds that a camera covering a parking lot cannot capture useful images because vehicle headlights repeatedly overwhelm the scene. What should be evaluated?

  1. Employee parking assignments only
    2. Camera housing color
    3. Camera positioning, exposure capability, dynamic range, lighting, scene geometry, and the defined surveillance objective
    4. Access-card expiration dates

Correct Answer: 3

Explanation:

Strong headlights can create extreme contrast that reduces useful image detail. The professional should examine camera angle, mounting position, lighting, exposure settings, wide dynamic range capability, and the exact surveillance task. Repositioning a camera may sometimes be more effective than changing specifications. Testing should be performed under representative nighttime traffic conditions because daytime performance may not reveal the problem. Video design should focus on obtaining usable information for the intended task rather than merely ensuring that the scene appears somewhere on a monitor.

Question 372.

A facility is developing procedures for suspicious mail. What is the most appropriate principle?

  1. Employees should open suspicious packages immediately to identify contents.
    2. Suspicious mail should always be moved to the security office.
    3. Every unusual package should automatically cause a facility-wide evacuation.
    4. Personnel should follow established recognition, isolation, notification, and emergency procedures while minimizing unnecessary handling

Correct Answer: 4

Explanation:

Suspicious mail procedures should help employees recognize concerning characteristics and respond without unnecessarily disturbing or transporting the item. Personnel should know whom to notify and how to isolate the immediate area according to established organizational and emergency guidance. Appropriate responders can then assess the situation and determine additional actions. Training should emphasize that untrained employees should not attempt to inspect potentially hazardous contents themselves. Procedures should be coordinated with relevant emergency plans and reflect the organization’s specific threat environment and operations.

Question 373.

What is an important security advantage of using individually numbered mechanical keys?

  1. Numbering can support issuance records, inventories, recovery, and accountability for controlled keys.
    2. Numbered keys cannot be duplicated.
    3. Numbering automatically identifies who used a key at a specific time.
    4. Numbered keys eliminate the need for locks.

Correct Answer: 1

Explanation:

Unique key identifiers allow organizations to record which key was issued to a particular authorized person and support periodic inventories. This improves administrative accountability and helps identify missing keys. However, numbering does not provide an electronic transaction history showing exactly when a key was used, nor does it necessarily prevent unauthorized duplication. Key-control programs should also address secure storage, authorization, issuance, return, duplication, lost keys, rekeying decisions, and periodic audits based on the sensitivity of the protected areas.

Question 374.

A security manager is planning protection for an emergency operations center. Which approach is most appropriate?

  1. Locate it where public visitors routinely gather
    2. Protect access, communications, power, information, environmental systems, and continuity capabilities according to its critical function
    3. Depend only on a conventional office lock
    4. Allow unrestricted access during emergencies

Correct Answer: 2

Explanation:

An emergency operations center may become especially important when normal organizational conditions are disrupted. Its physical protection should therefore consider authorized access, communications, backup power, information security, environmental conditions, and resilience of supporting systems. The organization should also consider whether the center is vulnerable to the same event affecting primary operations. Emergency conditions do not necessarily justify uncontrolled access; authorization and accountability remain important. Protection should be proportional to the center’s role in coordinating organizational response and continuity.

Question 375.

A security assessment identifies a camera mounted where employees can easily reach and redirect it. What is the best corrective approach?

  1. Disable recording
    2. Depend entirely on policy prohibiting camera contact
    3. Improve mounting or physical protection and consider tamper detection while preserving the required field of view
    4. Remove the camera from the surveillance system

Correct Answer: 3

Explanation:

A surveillance camera that can easily be redirected, covered, disconnected, or damaged may not reliably perform its intended function. Mounting height, protective housings, secure cabling, tamper-resistant hardware, or automated tamper alerts may reduce exposure depending on the environment. Changes should preserve maintainability and the required field of view. The professional should also consider whether unauthorized access to the camera reflects a broader zoning or access-control issue. Physical protection of security devices is part of maintaining overall system integrity.

Question 376.

An organization is planning to renovate its main lobby. When should the physical security team become involved?

  1. Only after construction is complete
    2. After all architectural decisions are irreversible
    3. Only if a security incident occurs during construction
    4. Early in planning and design so security requirements can be integrated with architecture, operations, accessibility, and life safety

Correct Answer: 4

Explanation:

Early security involvement allows entrance control, reception, visitor processing, surveillance, barriers, circulation, emergency egress, accessibility, and other requirements to be incorporated into the design. Late changes are often more expensive and may result in awkward or less effective solutions. Security personnel should collaborate with architects, facilities, information technology, operations, and other stakeholders rather than design controls independently. Integrating physical security during planning helps create a functional environment in which protection supports rather than conflicts with normal business operations.

Question 377.

Why should security organizations periodically reconcile issued parking permits against current authorized users?

  1. Permits may remain active after employees, contractors, or vehicles are no longer authorized, creating unnecessary access opportunities.
    2. Parking permits never require administrative control.
    3. Reconciliation guarantees that no unauthorized vehicle can enter.
    4. Every employee should have multiple active permits.

Correct Answer: 1

Explanation:

Parking permits are credentials and should be managed throughout their lifecycle. Employees may leave, contractors may finish assignments, vehicles may change, and temporary permits may remain in circulation beyond their intended period. Periodic reconciliation helps identify obsolete or duplicate permits and supports accurate authorization records. Electronic permits should be deactivated when appropriate, while physical permits may need to be recovered or invalidated. Parking controls should complement vehicle access procedures and should not be treated as a one-time administrative issuance activity.

Question 378.

A security manager wants to improve protection against social engineering at a staffed entrance. Which measure is most appropriate?

  1. Tell guards to admit anyone who appears confident
    2. Provide clear verification and exception procedures, training, supervisory support, and a method for resolving uncertain access requests
    3. Remove identity verification to reduce delays
    4. Allow visitors to approve their own access

Correct Answer: 2

Explanation:

Social engineering can exploit politeness, urgency, authority claims, confusion, or unusual circumstances to persuade personnel to bypass established controls. Entrance staff should receive clear procedures for verifying credentials, contacting hosts, handling exceptions, and escalating uncertain situations. Supervisory support is important so employees do not feel pressured to violate policy merely to avoid inconvenience. Training can use realistic scenarios while emphasizing professional treatment of legitimate visitors. Consistent verification processes reduce reliance on intuition about whether a person appears trustworthy.

Question 379.

A security professional is evaluating the use of privacy masking in a video surveillance system. What is its primary purpose?

  1. To increase recording frame rate
    2. To eliminate camera maintenance
    3. To obscure designated areas of an image when surveillance of those areas is unnecessary or inappropriate while preserving required monitoring elsewhere
    4. To provide biometric authentication

Correct Answer: 3

Explanation:

Privacy masking can prevent operators or recordings from displaying areas that are outside the legitimate surveillance purpose, such as neighboring private spaces or other sensitive locations. The organization should configure masking so it does not interfere with required security coverage. Changes to camera position, zoom, or scene layout may require the masks to be reviewed. Privacy masking is one element of responsible surveillance governance and should be combined with appropriate access controls, retention practices, authorization, and compliance with applicable requirements.

Question 380.

A physical security program has accumulated many procedures, technologies, and controls over several years. What is the best way to determine whether they still provide appropriate protection?

  1. Keep every control because removing controls always increases risk
    2. Evaluate only how much each control originally cost
    3. Replace every control on a fixed annual schedule
    4. Periodically reassess current risks, control effectiveness, operational value, dependencies, costs, and residual exposure

Correct Answer: 4

Explanation:

Security programs evolve as new controls are added in response to projects, incidents, audits, or changing requirements. Over time, some measures may become obsolete, redundant, ineffective, unsupported, or poorly aligned with current operations. Periodic program review helps determine whether controls continue to address relevant risks and whether resources are being used effectively. Testing, incidents, maintenance information, audits, user feedback, and updated risk assessments can inform the review. Security should remain adaptive rather than accumulating controls indefinitely without evaluating their continuing purpose.