ASIS PSP Practice Test Questions and Exam Dumps Part20 Q381-400

View Full ASIS PSP Exam Dumps and Practice Test Dumps

 

Question 381.

A security professional is reviewing an entrance where employees frequently allow coworkers to follow them through an access-controlled door without presenting credentials. Which term best describes this behavior when the first employee knowingly permits the second person to enter?

  1. Piggybacking
    2. Risk transfer
    3. Anti-passback
    4. Alarm assessment

Correct Answer: 1

Explanation:

Piggybacking commonly refers to an authorized person knowingly allowing another individual to enter through a controlled opening without independently authenticating. Tailgating may involve following without the authorized person’s knowledge or explicit permission. Both practices can undermine access control because the system records fewer credential transactions than actual entrants. Appropriate countermeasures may include employee awareness, entrance design, turnstiles, security officers, video monitoring, or other controls based on risk. Employees should understand that familiarity with another person does not replace required authentication procedures.

Question 382.

A facility is selecting between passive infrared and dual-technology motion detectors for an interior space. What should primarily guide the decision?

  1. Which detector has the smallest enclosure
    2. Threat characteristics, environmental conditions, coverage, nuisance alarm sources, required detection performance, and testing results
    3. Which technology was purchased most recently
    4. The number of employees in the security department

Correct Answer: 2

Explanation:

Different sensor technologies respond to different physical phenomena and environmental conditions. Passive infrared sensors detect changes in infrared energy, while dual-technology devices may combine multiple sensing principles to influence alarm decisions. Neither approach is universally superior. The security professional should evaluate likely intrusion paths, room geometry, airflow, temperature, machinery, animals, sunlight, and other potential nuisance sources. Installation and testing under representative conditions are essential. Sensor selection should support the required probability of detection while maintaining an operationally acceptable nuisance alarm rate.

Question 383.

A security manager discovers that the badge printer used to produce employee credentials is located in an unlocked office accessible to many people. What should be done?

  1. Leave it accessible because printed badges require activation
    2. Remove all badge photographs
    3. Restrict access to credential-production equipment, supplies, software, and issuance functions according to authorized responsibilities
    4. Allow employees to print replacement credentials themselves

Correct Answer: 3

Explanation:

Credential-production equipment can be used to create convincing badges or other identification materials even if additional electronic activation is required. Access to printers, blank cards, encoding devices, issuance software, and related supplies should therefore be controlled. Organizations should also establish authorization and accountability for badge creation, replacement, activation, and disposal. Separating sensitive credential functions where appropriate can further reduce misuse. Credential security begins before a badge reaches the user and continues throughout issuance, use, replacement, revocation, and final destruction.

Question 384.

A facility’s security radio system depends on one repeater located in an area vulnerable to flooding. What should management evaluate?

  1. Whether guards prefer another radio brand
    2. Only the repeater’s purchase price
    3. Whether the repeater can be painted
    4. The consequences of repeater loss and whether relocation, redundancy, alternate communications, or environmental protection is justified

Correct Answer: 4

Explanation:

A single repeater can become a critical dependency when large portions of a facility rely on it for security communications. If the equipment is exposed to flooding or another credible hazard, one event could significantly impair guard coordination and emergency response. Management should assess the likely consequences, available alternate communication methods, restoration time, and potential mitigation. Relocation, environmental protection, redundant equipment, or other solutions may be appropriate. Resilience planning should identify and manage common points of failure before an emergency exposes them.

Question 385.

What is the primary purpose of a security design basis or design criteria document?

  1. To translate security objectives and assessed risks into documented requirements that guide design and verification
    2. To serve as a list of preferred manufacturers only
    3. To replace all construction drawings
    4. To guarantee that future threats will not change

Correct Answer: 1

Explanation:

A security design basis establishes the assumptions, threats, performance objectives, constraints, and requirements that guide a security project. It helps designers understand what the system is expected to accomplish rather than selecting equipment without a defined purpose. The document can also support later testing and acceptance because performance can be compared with established requirements. As risks or facility conditions change, the design basis may require review. Clear requirements improve consistency among security, architecture, engineering, operations, and other project stakeholders.

Question 386.

A facility uses electromagnetic locks on several doors. During a power outage, all doors release simultaneously. What should the security professional evaluate?

  1. Whether employees prefer mechanical locks
    2. Whether the failure behavior satisfies life-safety requirements while appropriately managing the security consequences of unlocked doors
    3. Whether cameras use the same power circuit
    4. Whether the doors have identical finishes

Correct Answer: 2

Explanation:

Lock behavior during power failure must balance safety and security requirements. Some applications require fail-safe unlocking, while others may permit or require different arrangements depending on door function and applicable requirements. The security professional should determine what happens during normal outages, fire alarms, emergency releases, and backup-power operation. If doors must unlock, compensating measures such as monitoring, guards, or other controls may be appropriate during extended outages. Failure modes should be deliberately designed and tested rather than discovered during an actual emergency.

Question 387.

A security assessment finds that delivery drivers can walk directly from a loading dock into sensitive office areas. What is the most appropriate improvement?

  1. Increase the number of delivery vehicles
    2. Remove loading-dock surveillance
    3. Establish controlled separation between receiving operations and sensitive internal areas, with authorized routes and access controls
    4. Allow drivers to select their own destinations

Correct Answer: 3

Explanation:

Loading docks create necessary contact with external drivers, vendors, and goods but should not automatically provide unrestricted access to internal facilities. Appropriate zoning can separate receiving areas from employee or sensitive spaces. Controlled doors, visitor procedures, designated waiting areas, escorts, surveillance, and delivery processes may be used according to risk. The objective is to support efficient receiving while limiting unnecessary movement by individuals whose legitimate purpose is confined to the loading or delivery function.

Question 388.

A security manager wants to evaluate a proposed security investment using cost-benefit analysis. Which approach is most appropriate?

  1. Select the least expensive control automatically
    2. Select the most expensive control automatically
    3. Consider only installation cost
    4. Compare expected security benefits and risk reduction with lifecycle costs, operational effects, limitations, and alternatives

Correct Answer: 4

Explanation:

Cost-benefit analysis supports informed decision-making by comparing the expected value of a security measure with the resources required to implement and sustain it. Costs may include acquisition, installation, maintenance, staffing, training, licensing, and eventual replacement. Benefits can include reduced likelihood or consequences of loss, improved resilience, or operational advantages. Quantification may not always be precise, particularly for low-frequency, high-consequence risks. The analysis should therefore combine available financial information with sound risk judgment rather than treating purchase price as the sole decision factor.

Question 389.

Why should a facility control access to rooms containing fire alarm, security, and building-management control equipment?

  1. Unauthorized access could allow tampering with systems that support safety, security, and facility operations.
    2. Control rooms should always be open to the public.
    3. Access restrictions eliminate equipment failures.
    4. Only information technology equipment requires physical protection.

Correct Answer: 1

Explanation:

Control equipment can influence numerous building functions, including alarms, access, environmental systems, and emergency operations. Unauthorized manipulation could disable monitoring, change settings, suppress alarms, or disrupt facility operations. Access should therefore be limited to personnel with legitimate responsibilities, with stronger controls applied when the consequences of misuse are significant. Monitoring and audit records may provide additional accountability. Protecting central control equipment is often more efficient than focusing exclusively on individual field devices because one compromised controller can affect many downstream systems.

Question 390.

A facility plans to use an X-ray system for package screening. What should be addressed before operation begins?

  1. Only equipment dimensions
    2. Screening objectives, operator training, image interpretation, alarm-resolution procedures, throughput, safety requirements, maintenance, and quality control
    3. Only the number of packages received annually
    4. Only the equipment’s purchase price

Correct Answer: 2

Explanation:

X-ray screening effectiveness depends heavily on trained operators and clearly defined procedures. The organization should establish what personnel are expected to identify, what happens when an image raises concern, and how suspicious packages are handled without unnecessary exposure. Equipment safety requirements, testing, maintenance, and quality assurance should also be addressed. Throughput must be considered because excessive workload can reduce screening effectiveness. Screening equipment should be integrated into a broader mail or package security process rather than relied upon as an independent solution.

Question 391.

A security professional discovers that a restricted-area door can be opened from outside by reaching through a nearby opening and activating the interior request-to-exit sensor. What type of problem is this?

  1. A lighting deficiency
    2. A visitor-management problem
    3. A design vulnerability that allows manipulation of the egress mechanism from the unsecured side
    4. A camera retention issue

Correct Answer: 3

Explanation:

Request-to-exit devices must support legitimate egress without creating an easy method for unauthorized entry. If an exterior opening, gap, or accessible sensor allows someone to trigger the release from the unsecured side, the door’s access control can be bypassed. The professional should evaluate the sensor type, placement, surrounding construction, locking arrangement, and applicable life-safety requirements. Corrective measures must preserve required emergency egress while preventing inappropriate external activation. Functional testing should include realistic attempts to manipulate the opening from outside.

Question 392.

A security system generates alarms using clocks that differ by several minutes from the video surveillance system. What is the most important corrective action?

  1. Increase video resolution
    2. Replace employee badges
    3. Disable alarm timestamps
    4. Establish reliable time synchronization across relevant security systems

Correct Answer: 4

Explanation:

Accurate time synchronization is essential when access transactions, alarms, video, communications, and other records must be correlated. Even a small difference can complicate investigations by making events appear to occur in the wrong sequence. Systems should use an appropriate authoritative time source and be monitored for synchronization problems. Time settings should also account for relevant configuration changes such as daylight-saving adjustments where applicable. Reliable timestamps strengthen operational assessment, incident reconstruction, auditability, and evidentiary value across integrated security systems.

Question 393.

What is the primary reason for controlling the duplication of mechanical keys?

  1. Unauthorized copies can undermine key inventories, recovery procedures, and confidence about who can enter protected areas.
    2. Duplicated keys always damage locks.
    3. Key duplication eliminates electronic access control.
    4. All keys must be unique in physical shape.

Correct Answer: 1

Explanation:

A key-control program depends on knowing how many keys exist and who is authorized to possess them. Uncontrolled duplication can create copies that are absent from official records and remain in circulation even after issued keys are recovered. Restricted keyways, authorized duplication procedures, inventories, secure storage, and documented issuance can reduce this risk. No mechanical key system provides the same transaction accountability as individually logged electronic access, so highly sensitive applications may require additional controls depending on organizational risk.

Question 394.

A facility experiences frequent brief power interruptions that cause security devices to reboot. Which solution should be evaluated?

  1. Additional visitor badges
    2. Appropriate uninterruptible power supplies, power conditioning, backup power, and system recovery behavior
    3. Removing alarm monitoring
    4. Increasing fence height

Correct Answer: 2

Explanation:

Short power disturbances can disrupt security systems even when a long-duration generator is available, particularly if devices reboot before backup power takes over. Uninterruptible power supplies can bridge interruptions and provide stable power to critical controllers, servers, network equipment, cameras, and communications devices. The organization should determine required runtime, load, battery maintenance, environmental conditions, and interaction with generators. Testing should verify that systems remain operational or recover correctly. Power resilience should be designed across the complete security infrastructure rather than one device at a time.

Question 395.

A company wants to protect sensitive paper records that are no longer required. Which practice is most appropriate?

  1. Place them in ordinary recycling bins regardless of sensitivity
    2. Store them indefinitely in public areas
    3. Use an approved secure destruction process appropriate to the sensitivity of the information
    4. Give them to visitors for disposal

Correct Answer: 3

Explanation:

Sensitive information remains vulnerable even after its operational usefulness has ended. Organizations should establish retention and disposal requirements and use appropriate destruction methods when records are no longer needed. Depending on information sensitivity, secure shredding or an approved destruction service may be appropriate. Collection containers awaiting destruction should also be protected. Documented chain-of-custody procedures may be justified for particularly sensitive material. Secure disposal prevents information-protection controls from ending prematurely when documents leave active office storage.

Question 396.

A security manager is evaluating a new guard-force contractor. Which approach provides the strongest basis for selection?

  1. Select solely on the lowest hourly rate
    2. Select solely on company size
    3. Select solely on uniform appearance
    4. Evaluate qualifications, training, supervision, staffing reliability, procedures, performance management, legal requirements, references, and cost

Correct Answer: 4

Explanation:

Guard services depend heavily on personnel quality, supervision, training, staffing continuity, procedures, and management support. Price is important but should not be considered independently from the contractor’s ability to meet defined security requirements. Evaluation can address recruiting standards, licensing where applicable, training programs, supervisor coverage, reporting, emergency response, quality assurance, turnover, and past performance. Contract requirements should also establish measurable expectations. The objective is to select a provider capable of delivering reliable security performance throughout the contract lifecycle.

Question 397.

Why should a security professional evaluate drainage structures that cross a protected perimeter?

  1. Culverts, channels, or similar openings may create unintended routes through or beneath the perimeter.
    2. Drainage structures are never relevant to physical security.
    3. Every drainage opening must be permanently sealed.
    4. Drainage systems replace perimeter barriers.

Correct Answer: 1

Explanation:

Drainage infrastructure can create openings beneath fences or walls that may be large enough for unauthorized passage. The security professional should assess opening dimensions, accessibility, seasonal water conditions, maintenance requirements, and potential bypass methods. Grilles, barriers, detection, or other controls may be appropriate, but drainage capacity and flood protection must not be compromised. Regular inspection is important because erosion, debris, damage, or maintenance activity can alter conditions. Perimeter assessments should follow the complete boundary, including natural and engineered crossings.

Question 398.

A facility is designing an emergency mass-notification system. What should be considered beyond simply installing speakers?

  1. Only speaker appearance
    2. Coverage, intelligibility, message authority, activation procedures, redundancy, accessibility, testing, and integration with emergency plans
    3. Only the number of security officers
    4. Only normal office noise levels

Correct Answer: 2

Explanation:

Emergency notification must deliver understandable and actionable information to the intended population. Coverage should account for noisy areas, exterior spaces, hearing or accessibility needs, and locations where speakers alone may be insufficient. Organizations should define who may initiate messages, what communication channels are used, and how information is coordinated during an incident. Redundant channels such as text, desktop, visual, or other methods may improve reach where justified. Periodic testing verifies both technical performance and organizational procedures for creating and distributing emergency messages.

Question 399.

A security manager identifies repeated unauthorized attempts to enter a restricted room using expired credentials. What should be done?

  1. Reactivate every expired credential
    2. Ignore attempts because access was denied
    3. Investigate the pattern, verify credential lifecycle controls, identify the users or causes where possible, and determine whether additional action is required
    4. Disable event logging

Correct Answer: 3

Explanation:

Denied access events can provide valuable security information even when the control successfully prevents entry. Repeated attempts with expired credentials may result from employee confusion, poor credential recovery, outdated access instructions, or deliberate attempts to enter without authorization. Reviewing the pattern can identify whether lifecycle processes or user behavior require correction. Relevant logs, video, and personnel information may support assessment. Security monitoring should consider unsuccessful activity as well as successful access because repeated denied events can reveal emerging vulnerabilities or inappropriate behavior.

Question 400.

What is the most appropriate way to manage a mature physical security program over time?

  1. Freeze all controls once the initial design is complete
    2. Replace all security technology annually
    3. Focus exclusively on incidents that already caused losses
    4. Continuously reassess risks, measure performance, maintain systems, manage changes, address deficiencies, and adapt controls to organizational needs

Correct Answer: 4

Explanation:

Physical security is an ongoing management process rather than a one-time installation project. Threats, assets, facilities, technologies, personnel, and operations change over time, while existing controls can deteriorate or become obsolete. Effective programs combine risk assessment, maintenance, testing, performance measurement, incident analysis, exercises, audits, change management, and corrective-action tracking. Management should periodically review residual risk and adjust priorities as circumstances evolve. This continuing cycle helps ensure that security resources remain aligned with actual organizational requirements and provide sustained protection.