CRCT - Certified Revenue Control Technician Access Control Systems Questions and Answers — Questions and Answers
Question 1: A technician is installing an access control system in a parking garage that uses long-range RFID tags for monthly passholders and pulls tickets for transient visitors. Which of the following components is essential for ensuring that a vehicle has completely passed through the barrier before it closes?
- A pressure-sensitive exit pad
- A vehicle detection loop (Correct answer)
- An infrared beam sensor at gate height
- A manual override switch for the gate arm
Correct answer: A vehicle detection loop
A vehicle detection loop, typically embedded in the pavement, creates an electromagnetic field. When a large metal object like a vehicle passes over it, the inductance of the loop changes, signaling the controller that a vehicle is present. This is a standard and reliable method to prevent a gate arm from lowering onto a vehicle.
Question 2: A client reports that after an employee was terminated, their access card was deactivated in the system. However, the former employee was still able to enter the facility. Which access control vulnerability does this scenario most likely expose?
- A malfunctioning card reader
- A power failure to the door lock
- Lack of an anti-passback feature
- The system's failure to sync with the door controller in real-time (Correct answer)
Correct answer: The system's failure to sync with the door controller in real-time
In some access control systems, the main server holds the permissions database. When a change is made (like deactivating a card), it must be pushed out to the individual door controllers. If there's a delay or failure in this synchronization, the local controller might still hold the old permissions, allowing the deactivated card to work until the update is received.
Question 3: As a Certified Revenue Control Technician, you are tasked with implementing a security policy for a new access control system. Which of the following principles is most fundamental to mitigating risks from both internal and external threats?
- The principle of open access
- The principle of universal authentication
- The principle of least privilege (Correct answer)
- The principle of maximum convenience
Correct answer: The principle of least privilege
The principle of least privilege dictates that users should only be granted the minimum levels of access—or permissions—needed to perform their job duties. This significantly reduces the risk of accidental data exposure or malicious activity because a user's potential for damage is limited to their specific role.
Question 4: A parking facility manager wants to upgrade their access control system to reduce revenue leakage from employees sharing access fobs. Which technology would provide the highest level of assurance that the person entering is the authorized individual?
- Implementing a PIN pad alongside the fob reader
- Upgrading to encrypted smart cards
- Installing a biometric reader (e.g., fingerprint or facial recognition) (Correct answer)
- Using License Plate Recognition (LPR) tied to employee accounts
Correct answer: Installing a biometric reader (e.g., fingerprint or facial recognition)
Biometric readers verify a unique physical characteristic of the individual, such as a fingerprint, iris pattern, or facial features. This method provides the highest level of identity assurance because it verifies the person themselves, rather than a credential (like a card or PIN) that can be lost, stolen, or shared.
Question 5: During a routine system check, a technician notices that the access control panel for the main entrance is not responding, and the door is failing-safe (unlocked). A power check confirms the panel is receiving electricity. What is the most likely cause of the failure?
- A software bug requiring a system-wide reboot
- A damaged credential reader at the door
- A communication failure between the control panel and the central server (Correct answer)
- A faulty locking mechanism in the door itself
Correct answer: A communication failure between the control panel and the central server
Modern access control systems rely on constant communication between the central server and peripheral components like control panels. If the control panel loses its connection to the server, it may enter a fail-safe or fail-secure mode depending on its programming. Since the panel has power but isn't responding, a network or communication issue is a primary suspect before hardware failure at the door.
Question 6: Which of the following access control system components is the primary 'decision-maker' that verifies a credential against stored permissions and sends the signal to unlock a door?
- The credential reader
- The electric strike
- The access control panel/controller (Correct answer)
- The access control software
Correct answer: The access control panel/controller
The access control panel or controller is the core component that receives data from the reader, compares it to the access rules stored in its memory, and makes the final decision to grant or deny access by energizing the locking hardware. The software is used to program the rules, but the panel often makes the decision locally.
A technician is installing an access control system in a parking garage that uses long-range RFID tags for monthly passholders and pulls tickets for transient visitors.
Which of the following components is essential for ensuring that a vehicle has completely passed through the barrier before it closes?