ASIS PSP Practice Test Questions and Exam Dumps Part9 Q161-180

View Full ASIS PSP Exam Dumps and Practice Test Dumps

 

Question 161.

A security professional is evaluating the protection of a facility’s utility connections. Why should water, power, telecommunications, and other critical services be included in the assessment?

  1. Only because utilities increase operating costs
    2. Disruption or manipulation of critical utilities can affect security systems, operations, and facility resilience
    3. Utility systems are always protected by service providers
    4. Utilities have no relationship to physical security

Correct Answer: 2

Explanation:

Critical utilities can directly affect physical security and business continuity. Loss of electrical power may disable cameras or access-control equipment, while telecommunications failures can prevent alarms from reaching monitoring personnel. Water, fuel, and other services may also support critical operations. Security professionals should identify important utility dependencies, accessible connection points, single points of failure, and potential disruption scenarios. Appropriate measures may include physical protection, redundancy, backup power, alternate communications, monitoring, and recovery procedures. Protection should reflect the consequences associated with losing each service.

Question 162.

What is the primary purpose of a physical security penetration test conducted under controlled conditions?

  1. To evaluate whether defined protective measures can be bypassed and identify weaknesses under authorized test conditions
    2. To intentionally damage security equipment
    3. To replace all risk assessments
    4. To guarantee that future intrusions will fail

Correct Answer: 1

Explanation:

An authorized physical security penetration test can provide practical evidence about how barriers, access controls, personnel, procedures, and detection systems perform against realistic attempts to bypass them. Testing should have clearly defined objectives, authorization, scope, safety requirements, rules of engagement, and reporting procedures. Results can reveal weaknesses that may not be apparent during document reviews or inspections. Testing does not prove that every future attack will be prevented, but it can provide valuable information for improving the overall protective system.

Question 163.

A facility experiences repeated door-forced-open alarms at the same entrance during delivery periods. What should the security manager do?

  1. Disable all door alarms
    2. Treat every event as employee misconduct without investigation
    3. Analyze delivery procedures, door operation, alarm configuration, traffic patterns, and actual security requirements
    4. Remove the entrance

Correct Answer: 3

Explanation:

Recurring alarms associated with a specific activity may indicate an operational conflict, equipment problem, poor configuration, or inappropriate procedure. The manager should determine whether deliveries require the door to remain open longer than configured, whether hardware functions correctly, and whether alternative workflows can preserve security. Simply disabling alarms can hide genuine unauthorized activity, while assuming misconduct may overlook design problems. Analyzing the underlying cause allows the organization to reduce nuisance alarms while maintaining the required detection capability.

Question 164.

A security control room monitors multiple facilities, but all alarm communications use one telecommunications provider and one physical route. What should be evaluated?

  1. Monitor size
    2. Control-room furniture
    3. Camera housing color
    4. Common-mode communication failure and the need for appropriately diverse or redundant alarm paths

Correct Answer: 4

Explanation:

Multiple logical connections may still share the same underlying physical infrastructure. If all alarm communications depend on one provider, cable route, network device, or facility, a single failure can disrupt monitoring across multiple sites. The security professional should identify these common dependencies and determine whether path diversity, alternate providers, wireless backup, local monitoring, or other continuity measures are justified. Redundancy provides value only when backup components are sufficiently independent from the same failure conditions affecting the primary system.

Question 165.

Why is asset criticality important when developing physical security priorities?

  1. It helps determine which assets would create the greatest organizational consequences if lost, damaged, disrupted, or compromised.
    2. Every asset always has identical importance.
    3. Criticality is based only on replacement price.
    4. Criticality eliminates the need to evaluate threats.

Correct Answer: 1

Explanation:

Asset criticality reflects the significance of an asset to organizational objectives and the consequences of its loss, disruption, damage, or compromise. Replacement cost may be one factor, but operational dependency, safety, reputation, legal obligations, information sensitivity, and recovery difficulty can also matter. Understanding criticality helps security professionals allocate limited resources toward assets where adverse events would have the greatest impact. Criticality should still be considered together with threats, vulnerabilities, existing controls, and other elements of risk.

Question 166.

A security manager is reviewing an access-control system that permits unlimited unsuccessful PIN attempts. What improvement should be considered?

  1. Shorter employee names
    2. Appropriate controls for repeated failed authentication attempts, including alerting, lockout, delay, or investigation based on risk
    3. Removal of access logging
    4. Publishing valid PIN formats

Correct Answer: 2

Explanation:

Unlimited authentication attempts can allow repeated guessing or other misuse without triggering attention. Depending on the system and operational requirements, controls can include temporary lockout, increasing delays, alarm generation, monitoring, or investigation after a defined number of failed attempts. The configuration should avoid creating unacceptable denial-of-service or emergency-access problems. Failed attempts should also be logged appropriately. Authentication controls should be selected based on the sensitivity of the protected area and the consequences of unauthorized entry.

Question 167.

A security professional is assessing a facility adjacent to a public parking area. Which issue deserves particular attention?

  1. The color of public vehicles
    2. The number of nearby restaurants
    3. Proximity of uncontrolled vehicles to critical assets, observation opportunities, access routes, and achievable standoff
    4. Employee vacation schedules

Correct Answer: 3

Explanation:

Adjacent public parking may allow uncontrolled vehicles and individuals to approach close to a facility. Depending on the threat environment, this can affect standoff, surveillance, unauthorized pedestrian access, concealment, and other security considerations. The professional should understand property boundaries, vehicle routes, critical asset locations, and what controls can realistically be implemented. Possible measures might include barriers, altered parking arrangements, surveillance, lighting, or relocation of critical functions. Recommendations should be proportional to assessed risk and site constraints.

Question 168.

An organization plans to use security drones to supplement perimeter patrols. What should be evaluated before implementation?

  1. Only the drone’s maximum speed
    2. Only whether the technology is popular
    3. Only battery color
    4. Operational purpose, legal requirements, privacy, environmental limits, operator competency, communications, safety, and integration with response procedures

Correct Answer: 4

Explanation:

Drones can provide useful observation in some environments, but their effectiveness depends on clearly defined operational requirements. Weather, battery endurance, communications, airspace restrictions, privacy, operator qualifications, image quality, and safety can affect deployment. Procedures should establish how drone observations are assessed and how security personnel respond to detected activity. The organization should also plan for equipment failure or conditions in which drones cannot operate. Technology should supplement a risk-based security program rather than being adopted solely because it offers new capabilities.

Question 169.

What is the main purpose of establishing clear security performance metrics?

  1. To provide objective information about whether security processes and controls are achieving defined objectives
    2. To prove that all incidents are preventable
    3. To measure security only by expenditure
    4. To eliminate professional judgment

Correct Answer: 1

Explanation:

Meaningful metrics help management evaluate security performance and identify trends requiring attention. Measures might include response times, alarm reliability, system availability, access-control exceptions, maintenance completion, audit findings, or exercise results. Metrics should relate to defined security objectives and should not encourage undesirable behavior merely to improve reported numbers. Quantitative information can support professional judgment but does not replace it. Effective measurement provides evidence for improvement, resource allocation, and management decisions about the security program.

Question 170.

A security professional is evaluating a high-security entrance that requires both rapid employee throughput and strong identity assurance. What is the best approach?

  1. Remove authentication during shift changes
    2. Evaluate authentication technologies and entrance configurations against security requirements, peak throughput, usability, and exception handling
    3. Require manual searches of every employee regardless of risk
    4. Keep the entrance open during peak periods

Correct Answer: 2

Explanation:

High-security entrances must balance protection with operational requirements. The professional should define the required level of identity assurance and measure expected traffic during peak periods. Credential technologies, biometrics, turnstiles, staffing, lane quantity, and other options can then be evaluated. Exception processes for failed authentication, accessibility, visitors, and emergencies should also be addressed. A system that creates excessive queues may encourage bypass behavior, while one optimized only for speed may provide inadequate protection. Testing realistic throughput is therefore important before final implementation.

Question 171.

A security manager discovers that emergency responders cannot easily access a fenced facility because nobody has established a procedure for opening secured gates during emergencies. What should be done?

  1. Permanently leave all gates open
    2. Remove perimeter fencing
    3. Establish controlled emergency-access procedures coordinated with relevant responders while maintaining appropriate security
    4. Require responders to bypass the fence themselves

Correct Answer: 3

Explanation:

Emergency access must be considered when designing perimeter security. Strong gates and barriers should not unnecessarily delay authorized emergency responders. Procedures may include controlled override methods, designated access points, staffed response, emergency credentials, or other arrangements appropriate to the site and applicable requirements. Coordination with fire, medical, law-enforcement, or other emergency services can clarify expectations before an incident. The objective is to support timely emergency response without routinely weakening perimeter protection during normal operations.

Question 172.

A facility’s access control server fails, and local door controllers continue operating using their most recent authorization data. What security design characteristic does this demonstrate?

  1. Complete elimination of risk
    2. Natural surveillance
    3. Risk transfer
    4. Distributed resilience that can preserve defined access functions during central-server failure

Correct Answer: 4

Explanation:

Local controllers capable of maintaining defined access decisions during loss of the central server can improve resilience. The precise behavior should be intentionally designed, including how recent authorization information is stored, how events are retained, and what happens when communications return. Some functions may be unavailable during the outage, so operational procedures should address those limitations. The appropriate architecture depends on risk and business requirements. Resilience does not mean failures have no consequences, but it can prevent a single central failure from disabling every controlled opening.

Question 173.

Why should security professionals consider maintenance access when designing protected equipment installations?

  1. Equipment must remain serviceable without creating unnecessary security vulnerabilities or requiring routine bypass of protective measures.
    2. Maintenance personnel should always receive unrestricted facility access.
    3. Equipment should never be maintained after installation.
    4. Maintenance requirements are unrelated to physical security.

Correct Answer: 1

Explanation:

Security equipment requires inspection, repair, cleaning, testing, and eventual replacement. If maintenance access is poorly planned, technicians may need to disable controls, prop doors open, or enter areas beyond their legitimate need. Design should provide safe and practical service access while maintaining appropriate authorization and accountability. Procedures may include temporary access, escorts, maintenance windows, impairment controls, and restoration testing. Considering maintainability during design helps sustain long-term security performance and reduces the likelihood of insecure maintenance workarounds.

Question 174.

A security manager wants to compare actual guard response times with the facility’s protection requirements. What information is needed?

  1. Guard uniform costs
    2. Detection and assessment timing, adversary delay, travel and communication times, and the required point of intervention
    3. Number of employee parking spaces
    4. Camera manufacturer names

Correct Answer: 2

Explanation:

Response time should be evaluated as part of the complete protection timeline. The organization needs to understand when potentially hostile activity is detected, how long assessment and communication require, how quickly responders can arrive, and how much delay existing barriers provide. The key question is whether responders can intervene before the adversary completes the objective. Measuring only the time from dispatch to arrival can overlook significant delays elsewhere in the process. Exercises and operational data can provide useful evidence for this analysis.

Question 175.

A facility is located in an area subject to periodic flooding. How should this influence physical security planning?

  1. Flooding should be ignored because it is not a deliberate threat
    2. Only employee evacuation should be considered
    3. Flood exposure should be assessed for its effects on critical assets, security systems, utilities, access routes, and continuity measures
    4. All electronic security systems should automatically be removed

Correct Answer: 3

Explanation:

Physical security risk management can include natural hazards when they affect protection and organizational resilience. Flooding may damage access-control panels, cameras, sensors, communications, power equipment, or security operations centers. It may also block responder routes or force changes in normal access procedures. Critical equipment can sometimes be relocated, elevated, protected, or supported by alternative systems. The appropriate measures should reflect flood likelihood, potential consequences, recovery requirements, and broader organizational emergency and continuity planning.

Question 176.

A security professional learns that a new building automation system will automatically unlock selected doors under certain conditions. What should occur before implementation?

  1. Allow the automation vendor to determine all security requirements
    2. Disable access-control logging
    3. Assume automated actions are always correct
    4. Review the integration, trigger conditions, life-safety requirements, security consequences, failure modes, authorization, and testing

Correct Answer: 4

Explanation:

Integrated building systems can create unexpected security effects if automated actions are not carefully reviewed. A fire or emergency system may legitimately need to influence certain doors, while incorrect logic or unauthorized integration could unintentionally expose protected areas. Security, safety, facilities, engineering, and other appropriate stakeholders should define required behavior under normal, emergency, and failure conditions. Testing should verify the actual integrated operation. System interfaces should also be documented so future modifications do not inadvertently undermine security.

Question 177.

What is an important purpose of maintaining an inventory of physical security equipment?

  1. It supports maintenance, lifecycle planning, configuration control, replacement, and understanding of deployed security assets.
    2. It guarantees every device is operational.
    3. It eliminates the need for testing.
    4. It should contain only equipment purchase prices.

Correct Answer: 1

Explanation:

An accurate equipment inventory helps organizations understand what security devices are deployed, where they are located, their models, support status, maintenance history, and expected lifecycle. This information supports preventive maintenance, spare-parts planning, upgrades, vulnerability management, budgeting, and eventual replacement. An inventory does not demonstrate that equipment is functioning, so testing and inspection remain necessary. For sensitive systems, detailed inventory information should be appropriately protected because it may reveal important characteristics of the organization’s protective infrastructure.

Question 178.

A security manager finds that patrol officers follow exactly the same route at exactly the same time every night. What concern should be evaluated?

  1. Patrol documentation is unnecessary
    2. Excessive predictability may allow an adversary to anticipate gaps in officer presence
    3. Officers should never use patrol routes
    4. Patrols should occur only after alarms

Correct Answer: 2

Explanation:

Regular patrol coverage can be valuable, but excessive predictability may allow someone observing the facility to anticipate when particular areas are unattended. Depending on risk, patrol schedules can incorporate appropriate variation while still ensuring critical inspection requirements are completed. The manager should balance unpredictability with accountability and operational needs. Electronic tour systems can verify coverage without requiring every patrol to follow an identical sequence. Patrol design should support deterrence, observation, inspection, and response objectives rather than becoming a purely repetitive routine.

Question 179.

A facility’s security team discovers that employees have placed opaque decorations on windows used by guards to observe an entrance. What should be done?

  1. Ignore the change because decorations are temporary
    2. Replace the guards
    3. Restore required sightlines or provide equivalent observation while considering legitimate operational needs
    4. Eliminate entrance monitoring

Correct Answer: 3

Explanation:

Changes to the physical environment can unintentionally degrade security functions. If a window was intentionally used to provide observation of an entrance, blocking it may reduce natural or staffed surveillance. The security team should confirm the observation requirement and work with relevant stakeholders to restore visibility or provide an equivalent control. Periodic inspections help identify these gradual changes. Security designs should not be assumed to remain effective indefinitely because furniture, decorations, vegetation, equipment, and operational practices can alter conditions after installation.

Question 180.

Management asks whether a security system that passed acceptance testing five years ago can still be assumed effective today. What is the best response?

  1. Yes, because acceptance testing is permanent
    2. Yes, if no equipment has been visibly damaged
    3. No additional review is needed unless a major theft occurs
    4. Current effectiveness should be verified through maintenance records, testing, inspections, performance data, and updated risk assessment

Correct Answer: 4

Explanation:

Acceptance testing demonstrates performance when a system is commissioned, not permanent effectiveness. Equipment can deteriorate, configurations can change, users can develop workarounds, surrounding environments can change, and new threats may emerge. Periodic testing and inspection help verify technical performance, while updated risk assessment determines whether the original security objectives remain appropriate. Maintenance records, incidents, alarms, response data, and other evidence can reveal changes in effectiveness. Security systems should therefore be managed throughout their lifecycle rather than assumed effective indefinitely.