Certified Security Consultant (CSC) — Questions and Answers
Question 1: An attacker uses a compromised employee account to exfiltrate data over several weeks. Which detection control would MOST likely have identified this earliest?
- Penetration testing
- Firewall rule updates
- User and Entity Behavior Analytics (UEBA) (Correct answer)
- Antivirus signature scanning
Correct answer: User and Entity Behavior Analytics (UEBA)
UEBA detects anomalous behavior patterns compared to a user's baseline, making it effective at catching insider threats and compromised accounts.
Question 2: Which of the following statements about risk appetite versus risk tolerance is MOST accurate?
- Risk appetite and risk tolerance are interchangeable terms in security frameworks
- Risk appetite is a precise technical threshold; risk tolerance is a strategic concept
- Risk tolerance is set by regulators; risk appetite is set by security teams
- Risk appetite is the broad strategic willingness to accept risk; risk tolerance is the acceptable deviation from that appetite (Correct answer)
Correct answer: Risk appetite is the broad strategic willingness to accept risk; risk tolerance is the acceptable deviation from that appetite
Risk appetite defines the overall level of risk an organization is willing to pursue, while risk tolerance specifies the acceptable variance or deviation around that appetite.
Question 3: Which of the following best describes a Recovery Point Objective (RPO)?
- The maximum acceptable amount of data loss measured in time prior to a disaster (Correct answer)
- The specific location designated as the alternate recovery site
- The number of personnel required to restore critical operations
- The time needed to test the disaster recovery plan
Correct answer: The maximum acceptable amount of data loss measured in time prior to a disaster
RPO defines the maximum age of data that an organization can afford to lose, essentially setting the backup frequency requirement.
Question 4: When a security officer is found to have violated a company policy, the FIRST step a supervisor should typically take in a progressive discipline process is:
- Immediate termination of employment
- Suspension without pay pending a full investigation
- Verbal counseling documented in the officer's personnel record (Correct answer)
- A formal written warning placed in the personnel file
Correct answer: Verbal counseling documented in the officer's personnel record
Progressive discipline begins with the least severe step — verbal counseling — which is documented but gives the officer an opportunity to correct the behavior before escalation.
Question 5: Which type of attack requires the MOST immediate crisis response due to its potential to permanently destroy data or disable systems at scale?
- Credential stuffing against a web application
- Phishing campaign targeting employees
- DNS hijacking of a single subdomain
- Wiper malware deployment across enterprise systems (Correct answer)
Correct answer: Wiper malware deployment across enterprise systems
Wiper malware is designed to permanently destroy data and disable systems, making rapid containment critical to prevent irreversible damage.
Question 6: In quantitative risk analysis, what does an Annualized Rate of Occurrence (ARO) of 0.25 indicate?
- The threat is expected to occur four times per year
- The threat is expected to occur once every four years (Correct answer)
- The threat causes 25% asset loss per incident
- The threat has a 25% severity rating
Correct answer: The threat is expected to occur once every four years
An ARO of 0.25 means the threat event is expected to occur 0.25 times per year, or approximately once every four years.
Question 7: What is the MAIN reason security consultants use standardized templates for report writing?
- To comply with international export control regulations
- To reduce the time required to complete assessments
- To avoid having to customize reports for individual clients
- To ensure consistency, completeness, and professional quality across all deliverables (Correct answer)
Correct answer: To ensure consistency, completeness, and professional quality across all deliverables
Standardized templates enforce consistent structure and reduce the risk of omitting critical sections.
Question 8: What is the security risk of 'door prop' alerts being consistently ignored by security staff?
- It triggers false positives in biometric enrollment databases
- It causes access logs to record duplicate entries for authorized users
- It normalizes alarm fatigue, allowing genuine intrusion events to go unaddressed (Correct answer)
- It drains battery backup systems for access control panels
Correct answer: It normalizes alarm fatigue, allowing genuine intrusion events to go unaddressed
Alarm fatigue causes security personnel to ignore or delay responding to alarms because of too many false or nuisance alerts, creating real security gaps.
Question 9: Why is staying current with industry developments important for Court Security Specialist professionals?
- Only academic researchers need to stay current
- Industry changes rarely affect practice
- To provide the best possible service using current knowledge and practices (Correct answer)
- It is only important for certification renewal
Correct answer: To provide the best possible service using current knowledge and practices
Staying current ensures professionals provide the best possible service by incorporating the latest knowledge, techniques, and regulatory requirements.
Question 10: In a Business Impact Analysis (BIA), what does the Maximum Tolerable Downtime (MTD) metric define?
- The average annual cost of a security incident
- The frequency at which backups must be tested
- The time required to restore a system from backup
- The longest period a business process can be disrupted before causing unacceptable harm (Correct answer)
Correct answer: The longest period a business process can be disrupted before causing unacceptable harm
MTD (also called Maximum Tolerable Period of Disruption) is the upper boundary of disruption a process can sustain before consequences become unacceptable.
Question 11: What is the MAIN purpose of a 'dead zone' analysis in a CCTV system design?
- To locate areas not covered by any camera that could be exploited by an intruder (Correct answer)
- To test network bandwidth under maximum load
- To identify areas where cameras exceed their resolution limit
- To schedule preventive maintenance for camera housings
Correct answer: To locate areas not covered by any camera that could be exploited by an intruder
A dead zone analysis maps uncovered areas in a camera layout so the designer can add cameras, adjust angles, or accept documented risk for those gaps.
Question 12: Which standard provides internationally recognized guidelines for Business Continuity Management Systems?
- ISO 27001
- ISO 22301 (Correct answer)
- ASIS SPC.1
- NFPA 1600
Correct answer: ISO 22301
ISO 22301 is the international standard specifically for Business Continuity Management Systems (BCMS), outlining requirements for planning, implementing, and improving continuity capabilities.
Question 13: When assessing the adequacy of perimeter security for a critical infrastructure facility, a CSC should evaluate which combination of factors?
- CCTV camera count and coverage percentage as the primary metrics
- Lighting levels and fence material grade only
- Guard staffing levels, technology systems, physical barriers, and response protocols holistically (Correct answer)
- Fence height only, as it is the primary deterrent metric
Correct answer: Guard staffing levels, technology systems, physical barriers, and response protocols holistically
A comprehensive perimeter security assessment must evaluate all layers — physical barriers, detection technology, human resources, and response capabilities — as an integrated system.
Question 14: Which of the following is a key component of an incident response plan?
- Supply chain expansion plans.
- Employee retirement strategy.
- Project profitability reports.
- Clear communication protocols and escalation procedures (Correct answer)
Correct answer: Clear communication protocols and escalation procedures
Clear communication protocols and escalation procedures are a key component of an incident response plan. These protocols ensure that relevant information is shared accurately and promptly with the right people, both internally and externally. Defined escalation procedures guide who needs to be informed and when, ensuring that incidents are addressed at the appropriate level and resources are deployed effectively.
Question 15: What is a threat in the context of risk management?
- A backup plan.
- A risk mitigation strategy.
- An insurance policy.
- A potential cause of harm or loss (Correct answer)
Correct answer: A potential cause of harm or loss
In risk management, a threat refers to any potential event or agent that could exploit a vulnerability and cause harm or loss to an asset. Examples include natural disasters, malicious actors, or system failures. Identifying threats is a crucial first step in understanding what adverse events an organization needs to protect against.
Question 16: Why is it important to use standardized terminology in documentation?
- It makes notes look more professional
- It reduces the amount of writing needed
- It ensures consistent understanding across all readers and reduces ambiguity (Correct answer)
- It is only required in academic settings
Correct answer: It ensures consistent understanding across all readers and reduces ambiguity
Standardized terminology ensures all readers interpret documentation consistently, reducing miscommunication and supporting quality care coordination.
Question 17: An organization's incident response plan assigns a specific individual to make final decisions during a crisis. What is this role typically called?
- Security Architect
- Chief Compliance Officer
- Crisis Arbitrator
- Incident Commander (Correct answer)
Correct answer: Incident Commander
The Incident Commander is the designated authority responsible for overall decision-making and coordination during an active incident or crisis response.
Question 18: A bomb threat is received by phone. According to best practices, the recipient should FIRST:
- Contact law enforcement before ending the call
- Immediately evacuate the building
- Keep the caller talking and gather as much information as possible (Correct answer)
- Activate the fire alarm to initiate evacuation
Correct answer: Keep the caller talking and gather as much information as possible
Keeping the caller talking allows collection of critical details (location, time, description) that can be passed to law enforcement.
Question 19: A security consultant is developing an emergency response plan for an active-shooter incident at a corporate campus. Which protocol framework is now the MOST widely taught in U.S. commercial facilities?
- Shelter-in-place protocol
- Code Red evacuation procedure
- Lockdown-only protocol
- Run-Hide-Fight (Avoid-Deny-Defend) (Correct answer)
Correct answer: Run-Hide-Fight (Avoid-Deny-Defend)
Run-Hide-Fight (or Avoid-Deny-Defend per CISA/ALERRT) is the dominant framework taught in U.S. workplaces, giving individuals a tiered set of options based on their proximity to and nature of the threat.
Question 20: During a major earthquake response, a security team discovers some individuals are unaccounted for. What tool is used to systematically track personnel accountability?
- Situation Report (SITREP)
- Resource Status Board
- Personnel Accountability Report (PAR) (Correct answer)
- Incident Action Plan (IAP)
Correct answer: Personnel Accountability Report (PAR)
A Personnel Accountability Report (PAR) is a formal headcount mechanism used to account for all individuals after an emergency.
Question 21: A conflict arises between a security consultant's recommendation to segment a network and the operations team's concern about performance degradation. The MOST appropriate resolution is to:
- Document the disagreement and make no recommendation
- Implement segmentation without consulting operations
- Abandon the segmentation recommendation entirely
- Engage both security and operations in a collaborative design session to achieve segmentation with acceptable performance trade-offs (Correct answer)
Correct answer: Engage both security and operations in a collaborative design session to achieve segmentation with acceptable performance trade-offs
Collaborative cross-functional design sessions integrate security requirements with operational constraints, producing solutions both teams can support.
Question 22: Which crisis communication principle states that organizations should be the first to disclose negative news about themselves?
- Principle of Transparency
- Principle of Non-Attribution
- Principle of Compartmentalization
- Principle of Preemption (Correct answer)
Correct answer: Principle of Preemption
The Principle of Preemption in crisis communications advises organizations to proactively disclose negative news before it is revealed by external parties, preserving credibility.
Question 23: In the context of business continuity, 'single points of failure' (SPOFs) are critical because they:
- Must be eliminated through redundancy before a BCP can be approved
- Are only relevant to IT infrastructure and not physical security operations
- Are the most expensive components of any security system
- Represent components whose failure would halt an entire critical process (Correct answer)
Correct answer: Represent components whose failure would halt an entire critical process
A SPOF is any component or process that, if it fails, causes the entire system or critical function to stop, making it a high-priority target for redundancy planning.
Question 24: A client asks a security consultant to help document the step-by-step procedures for recovering a specific IT application after a failure. This document is called a:
- Risk Register
- System Recovery Procedure (SRP) or IT Disaster Recovery Plan (Correct answer)
- Crisis Communication Plan
- Business Continuity Plan (BCP)
Correct answer: System Recovery Procedure (SRP) or IT Disaster Recovery Plan
A System Recovery Procedure or IT Disaster Recovery Plan contains the specific technical steps required to restore a particular system or application after failure.
Question 25: A security consultant is performing a gap analysis on a client's access control system. Which standard provides the MOST comprehensive framework for physical and environmental security controls?
- NIST SP 800-53 (PE controls)
- ISO/IEC 27001 Annex A.11
- PCI DSS Requirement 9
- Both NIST SP 800-53 PE controls and ISO/IEC 27001 Annex A.11 (Correct answer)
Correct answer: Both NIST SP 800-53 PE controls and ISO/IEC 27001 Annex A.11
Both NIST SP 800-53 (Physical and Environmental Protection family) and ISO 27001 Annex A.11 provide comprehensive physical/environmental security control frameworks.
Question 26: When a security consultant conducts a vulnerability assessment for emergency response, what does a 'single point of failure' represent?
- A lone employee responsible for emergency planning
- A facility with only one emergency exit
- An emergency contact list with one primary and no backup
- A component whose failure would disable the entire emergency response capability (Correct answer)
Correct answer: A component whose failure would disable the entire emergency response capability
A single point of failure is any element whose failure cascades to incapacitate the broader emergency response system.
Question 27: Which legal principle most directly governs whether a private security company can be held liable for the unauthorized actions of its security officers?
- Respondeat superior (Correct answer)
- Sovereign immunity
- Res ipsa loquitur
- Stare decisis
Correct answer: Respondeat superior
Respondeat superior holds employers liable for torts committed by employees acting within the scope of their employment.
Question 28: When a security consultant recommends a 'warm site' recovery strategy, the client should expect:
- A mobile trailer unit that can be deployed to any location
- Immediate failover with zero data loss
- A recovery time of several hours to days as equipment is brought online (Correct answer)
- A fully staffed and operational duplicate facility at all times
Correct answer: A recovery time of several hours to days as equipment is brought online
A warm site has partially configured equipment and connectivity, typically requiring hours to days of setup before full operations resume, balancing cost and recovery speed.
Question 29: A security consultant must communicate the same risk finding to both a technical IT team and a C-suite audience. The MOST effective approach is to:
- Tailor the message—technical details for IT, business impact framing for the C-suite (Correct answer)
- Provide only the C-suite version to everyone for simplicity
- Delegate the technical presentation to the client's IT manager
- Use the same presentation for both groups to ensure consistency
Correct answer: Tailor the message—technical details for IT, business impact framing for the C-suite
Effective communication requires audience adaptation—technical audiences need implementation details while executives need risk and business context.
Question 30: What is the MOST critical consideration when integrating facial recognition into a public-space surveillance system in the US?
- Ensuring the system can process at least 60 frames per second
- Using only cameras from domestic manufacturers
- Compliance with applicable state biometric privacy laws such as Illinois BIPA (Correct answer)
- Selecting cameras with the highest megapixel count
Correct answer: Compliance with applicable state biometric privacy laws such as Illinois BIPA
Several US states have enacted biometric privacy laws (notably Illinois BIPA) that impose strict consent, storage, and data-sharing requirements on facial recognition systems.
Question 31: What is the primary purpose of a tabletop exercise in incident response planning?
- To measure network detection response times
- To test the technical capabilities of security tools
- To simulate a real attack on production systems
- To walk stakeholders through response procedures in a discussion-based format (Correct answer)
Correct answer: To walk stakeholders through response procedures in a discussion-based format
Tabletop exercises are discussion-based simulations where participants walk through response procedures without affecting live systems.
Question 32: What is the RECOMMENDED minimum standoff distance between a high-value facility and the public street, per U.S. security guidelines for blast-resistant design?
- 82 feet (Correct answer)
- 10 feet
- 165 feet
- 33 feet
Correct answer: 82 feet
100 meters (approximately 328 ft) is ideal, but 25 meters (82 feet) is often cited as the minimum practical standoff distance to significantly reduce blast overpressure damage to a facility.
Question 33: A company's badge access logs show that an employee's credential was used to enter the facility at 8:02 AM, yet the employee reported arriving at 9:15 AM. This anomaly MOST likely indicates:
- A system clock synchronization error
- The employee forgot their entry time
- Credential sharing or a cloned badge (Correct answer)
- A malfunctioning card reader
Correct answer: Credential sharing or a cloned badge
A credential used before the legitimate holder arrives is a strong indicator of credential sharing or a cloned/stolen badge being used by an unauthorized person.
Question 34: After an emergency incident is resolved, which document captures lessons learned and recommendations for plan improvement?
- Business Continuity Plan update
- Incident Command Log
- Insurance Loss Report
- After-Action Report (AAR) (Correct answer)
Correct answer: After-Action Report (AAR)
The After-Action Report systematically documents what worked, what failed, and how plans should be improved.
Question 35: A security consultant is assessing a facility that stores high-value assets. Which perimeter security layer provides the FIRST line of defense?
- Interior barriers
- Guard posts at entry points
- Outer perimeter fencing (Correct answer)
- CCTV surveillance systems
Correct answer: Outer perimeter fencing
The outer perimeter fencing forms the first layer of defense in a defense-in-depth perimeter security model.
Question 36: Under the concept of 'transferred intent,' if a security officer fires at an armed suspect and accidentally strikes an innocent bystander, the officer may face liability because:
- Bystander injuries are always considered criminal negligence
- Intent transfers from the intended target to the actual victim (Correct answer)
- Warning shots must precede any firearm discharge
- Firearms use is strictly prohibited for private security
Correct answer: Intent transfers from the intended target to the actual victim
Transferred intent is a legal doctrine where the intent directed at one person legally transfers to the unintended victim for purposes of establishing liability.
Question 37: A security manager is developing a training program. Which training method is MOST effective for teaching officers how to respond to a medical emergency?
- Reading a printed manual about first aid procedures
- Hands-on scenario-based drills simulating actual medical emergencies (Correct answer)
- Attending a one-time classroom lecture on medical terminology
- Watching a video lecture about emergency response protocols
Correct answer: Hands-on scenario-based drills simulating actual medical emergencies
Scenario-based hands-on drills build muscle memory and decision-making skills that are retained far better than passive instructional methods for emergency situations.
Question 38: A company's emergency plan designates an Assembly Point. What is the security consultant's key consideration for this location?
- Proximity to the main entrance for convenience
- Availability of cellular network coverage
- Presence of a security camera for monitoring
- Distance and upwind positioning from the hazard area (Correct answer)
Correct answer: Distance and upwind positioning from the hazard area
Assembly points must be safely distanced from the hazard and positioned upwind to avoid smoke or chemical exposure.
Question 39: Which perimeter intrusion detection system (PIDS) technology is MOST susceptible to false alarms caused by animals and wind-blown debris?
- Microwave sensors
- Fence-mounted vibration sensors
- Active infrared beam sensors (Correct answer)
- Buried seismic/ported coaxial cable sensors
Correct answer: Active infrared beam sensors
Active infrared (IR) beam sensors are highly susceptible to false alarms from insects, birds, dust, and small animals crossing the beam path, especially in outdoor environments.
Question 40: Which NIST publication provides guidance on security assessment documentation and reporting standards for federal systems?
- NIST SP 800-61
- NIST SP 800-115 (Correct answer)
- NIST SP 800-53
- NIST SP 800-37
Correct answer: NIST SP 800-115
NIST SP 800-115 is the Technical Guide to Information Security Testing and Assessment, covering assessment documentation.
Question 41: Which kill chain phase does lateral movement most directly correspond to in the Lockheed Martin Cyber Kill Chain?
- Weaponization
- Installation
- Delivery
- Actions on Objectives (Correct answer)
Correct answer: Actions on Objectives
Lateral movement occurs as adversaries expand access toward their target, which corresponds to the Actions on Objectives phase where they pursue their mission.
Question 42: What does an effective security staffing model account for when calculating how many security officers are needed for a site?
- The number of posts, hours of coverage needed, relief factors, vacation, and sick leave to ensure every post is always filled (Correct answer)
- The number of incidents reported at the site in the prior calendar year only
- The preferences of the client regarding officer appearance and uniforms
- Only the number of entrances and exits that must be monitored
Correct answer: The number of posts, hours of coverage needed, relief factors, vacation, and sick leave to ensure every post is always filled
A complete staffing model calculates relief factors — extra personnel needed to cover breaks, days off, vacations, and sick leave — to ensure continuous post coverage.
Question 43: According to standard physical security practice, a security post order should be reviewed and updated at a MINIMUM of:
- Only when the contract with the guard company is renewed
- Every five years or after a major policy change
- Whenever a new security officer is assigned to the post
- Annually or after any significant incident or operational change (Correct answer)
Correct answer: Annually or after any significant incident or operational change
Post orders should be reviewed at least annually and immediately after any significant incident, organizational change, or shift in threat environment to ensure they remain accurate and effective.
Question 44: Under GDPR Article 83, what is the maximum fine for the most serious violations (Tier 2)?
- €50 million or 5% of global annual turnover
- €10 million or 2% of global annual turnover
- €20 million or 4% of global annual turnover (Correct answer)
- €100 million or 10% of global annual turnover
Correct answer: €20 million or 4% of global annual turnover
GDPR Tier 2 violations carry fines up to €20 million or 4% of the undertaking's total worldwide annual turnover, whichever is higher.
Question 45: Which phase of the NIST incident response lifecycle focuses on learning from past incidents to improve future response?
- Post-Incident Activity (Correct answer)
- Containment, Eradication, and Recovery
- Detection and Analysis
- Preparation
Correct answer: Post-Incident Activity
The Post-Incident Activity phase includes lessons-learned reviews to improve processes and prevent recurrence.
Question 46: What distinguishes a 'functional exercise' from a 'full-scale exercise' in emergency preparedness?
- Functional exercises are unannounced; full-scale exercises are scheduled
- Functional exercises test only one department while full-scale tests all departments
- Functional exercises activate functions without field deployment; full-scale deploys real resources (Correct answer)
- Functional exercises use live agents; full-scale uses simulated scenarios
Correct answer: Functional exercises activate functions without field deployment; full-scale deploys real resources
Functional exercises test coordination and decision-making without physically deploying field resources or equipment.
Question 47: A security consultant is evaluating a CCTV system. Which camera feature is MOST important for capturing usable evidence images in a low-light parking lot?
- High frame rate (60fps)
- Wide dynamic range (WDR)
- Pan-tilt-zoom (PTZ) functionality
- Low lux / IR illumination capability (Correct answer)
Correct answer: Low lux / IR illumination capability
Low-lux sensors combined with infrared (IR) illuminators allow cameras to capture clear images in near-darkness, which is critical for parking lot surveillance.
Question 48: Which standard governs the interoperability of IP-based security cameras and video management systems from different manufacturers?
- ISO 27001
- NIST SP 800-53
- H.265/HEVC
- ONVIF (Correct answer)
Correct answer: ONVIF
ONVIF (Open Network Video Interface Forum) is the industry standard that ensures interoperability between IP-based surveillance products from different vendors.
Question 49: What is the first step before implementing any treatment procedure?
- Check insurance authorization only
- Begin the procedure immediately to save time
- Delegate the procedure to support staff
- Verify patient identity and obtain informed consent (Correct answer)
Correct answer: Verify patient identity and obtain informed consent
Verifying patient identity and obtaining informed consent is always the first step before any treatment, ensuring patient safety and legal compliance.
Question 50: When developing a Business Continuity Plan (BCP), which step should be completed FIRST?
- Identifying alternate work-from-home policies
- Conducting a Business Impact Analysis (BIA) (Correct answer)
- Purchasing backup power generators
- Drafting evacuation procedures for all personnel
Correct answer: Conducting a Business Impact Analysis (BIA)
The BIA must be completed first to identify critical functions and set recovery priorities before any continuity strategies can be designed.
Question 51: How do intrusion detection systems contribute to security?
- By preventing phishing attacks
- By cleaning up malware
- By triggering alerts on suspicious activity (Correct answer)
- By managing passwords
Correct answer: By triggering alerts on suspicious activity
Intrusion detection systems (IDS) are designed to monitor network or system activities for malicious or anomalous behavior. When such activity is detected, the IDS generates an alert, notifying security personnel of a potential security incident. This allows for timely investigation and response, helping to prevent or mitigate the impact of an attack.
Question 52: A high-security facility requires that all visitors be authenticated BEFORE they reach the inner secured area. Which control BEST enforces this?
- CCTV monitoring at all entrances
- Security awareness signage at all doors
- Motion sensors in the lobby
- A visitor management system integrated with an airlock entry (Correct answer)
Correct answer: A visitor management system integrated with an airlock entry
An airlock (mantrap) integrated with visitor management ensures visitors are identified and authorized before gaining access to the secured inner area.
Question 53: What is business continuity planning?
- A strategy to maintain critical operations during disruptions (Correct answer)
- Planning for permanent closure during crises.
- A method to avoid regulatory audits.
- A marketing strategy to boost revenue.
Correct answer: A strategy to maintain critical operations during disruptions
Business continuity planning is a proactive strategy designed to ensure that an organization can continue to deliver its critical products or services during and after a disruption. It involves identifying potential threats, assessing their impact, and developing plans to maintain essential operations. The goal is to minimize downtime and quickly restore full functionality, safeguarding the business's viability.
Question 54: Which physical security standard provides design guidance specifically for protection of critical infrastructure facilities in the US?
- ASIS SPC.1 (Correct answer)
- NFPA 72
- ISO 27001
- UL 2050
Correct answer: ASIS SPC.1
ASIS SPC.1 (Security Management Standard) and related ASIS guidelines provide frameworks for physical security program design including critical infrastructure.
Question 55: The legal concept of 'assault' in the context of security force differs from 'battery' in that assault:
- Must involve a deadly weapon to be actionable
- Requires physical contact causing injury
- Involves intentionally placing someone in reasonable apprehension of imminent harmful contact (Correct answer)
- Applies only to attacks on law enforcement personnel
Correct answer: Involves intentionally placing someone in reasonable apprehension of imminent harmful contact
Assault is the intentional act that creates reasonable apprehension of immediate harmful contact, while battery is the actual unlawful physical contact itself.
Question 56: Which organization enforces compliance with workplace safety laws in the U.S.?
- FCC
- FBI
- OSHA (Correct answer)
- FTC
Correct answer: OSHA
OSHA, the Occupational Safety and Health Administration, is a federal agency of the United States Department of Labor. Its mission is to ensure safe and healthful working conditions for workers by setting and enforcing standards and by providing training, outreach, education, and assistance. Therefore, OSHA is responsible for enforcing compliance with workplace safety laws in the U.S.
Question 57: Which law primarily governs data privacy and protection in the U.S. healthcare sector?
- FISMA
- SOX
- FERPA
- HIPAA (Correct answer)
Correct answer: HIPAA
HIPAA (Health Insurance Portability and Accountability Act) is a U.S. federal law that establishes national standards to protect sensitive patient health information from being disclosed without the patient's consent or knowledge. It mandates strict security and privacy rules for healthcare providers, health plans, and healthcare clearinghouses. This makes it the primary governing law for data privacy in the U.S. healthcare sector.
Question 58: A security consultant is advising on crisis communications. What is the MOST important principle when releasing information to the public during an emergency?
- Provide timely, accurate, and consistent information from a single spokesperson (Correct answer)
- Allow department heads to communicate directly with media independently
- Delay statements until all facts are confirmed to avoid misinformation
- Release comprehensive technical details to demonstrate transparency
Correct answer: Provide timely, accurate, and consistent information from a single spokesperson
Timely, accurate, and consistent messaging through a unified spokesperson prevents rumor proliferation and maintains public trust.
Question 59: What is the PRIMARY purpose of a 'hot site' in business continuity planning?
- A data archive center with no active computing resources
- A temporary office space with basic furniture only
- A fully operational alternate facility that can be activated immediately after a disaster (Correct answer)
- A location for storing paper-based backup records
Correct answer: A fully operational alternate facility that can be activated immediately after a disaster
A hot site is a fully equipped alternate facility with hardware, software, and data that mirrors production systems and can be activated immediately following a disaster.
Question 60: What should a practitioner do if a patient experiences an adverse reaction during treatment?
- Stop the procedure immediately and assess the patient (Correct answer)
- Complete the procedure and document afterward
- Continue at a reduced intensity
- Have the patient sign a waiver and continue
Correct answer: Stop the procedure immediately and assess the patient
Immediately stopping the procedure and assessing the patient is the correct response to an adverse reaction, prioritizing patient safety above all else.
Question 61: What is the key difference between a disaster recovery plan (DRP) and a business continuity plan (BCP)?
- BCP is only for natural disasters; DRP covers cyberattacks
- DRP covers IT systems recovery; BCP covers broader operational continuity during disruption (Correct answer)
- DRP is a subset of the incident response plan
- BCP only applies to financial institutions
Correct answer: DRP covers IT systems recovery; BCP covers broader operational continuity during disruption
A DRP focuses on restoring IT systems and data after a disaster, while a BCP encompasses maintaining all critical business functions during and after disruption.
Question 62: What is the primary purpose of a 'go bag' (emergency kit) pre-positioned at a facility?
- Enable rapid deployment of critical supplies and information during emergency evacuation (Correct answer)
- Serve as a backup for the facility's digital security systems
- Store sensitive documents for evacuation
- Hold personal protective equipment for security officers only
Correct answer: Enable rapid deployment of critical supplies and information during emergency evacuation
A go bag provides immediately accessible critical supplies, documents, and communications tools needed in the first hours of an emergency response.
Question 63: A security consultant recommends establishing an Emergency Operations Center (EOC). What is the EOC's primary function?
- Conduct post-incident forensic analysis
- Coordinate information and resources across responding agencies or departments (Correct answer)
- House physical security personnel during normal operations
- Store emergency supplies and equipment
Correct answer: Coordinate information and resources across responding agencies or departments
The EOC serves as the centralized coordination hub for multi-agency or multi-departmental emergency responses.
Question 64: Which risk management concept refers to the idea that some level of risk always remains and can never be fully eliminated?
- Residual risk (Correct answer)
- Inherent risk
- Total risk
- Absolute risk
Correct answer: Residual risk
Residual risk acknowledges that even after all practical controls are implemented, some exposure remains because no control is 100% effective.
Question 65: During a crisis, an organization activates its Emergency Operations Center (EOC). What is the PRIMARY function of the EOC?
- Conducting digital forensic investigations
- Developing new security policies
- Coordinating cross-functional response activities and decision-making during a crisis (Correct answer)
- Managing customer refunds
Correct answer: Coordinating cross-functional response activities and decision-making during a crisis
The EOC serves as a centralized coordination hub for decision-making and resource management across all functions during a crisis or major incident.
Question 66: A security consultant conducting a full-scale continuity exercise that involves actual system failovers and personnel mobilization is performing a:
- Tabletop exercise
- Full-scale simulation (Correct answer)
- Functional exercise
- Structured walkthrough
Correct answer: Full-scale simulation
A full-scale simulation activates the actual recovery plan, mobilizes resources, and tests real system failovers to validate plan effectiveness under realistic conditions.
Question 67: Under the US OSHA standard 29 CFR 1910.38, emergency action plans are required to include which element?
- A list of all employees and their emergency roles
- Procedures for reporting a fire or other emergency (Correct answer)
- Vendor contacts for emergency cleanup services
- Insurance coverage details for property damage
Correct answer: Procedures for reporting a fire or other emergency
OSHA 29 CFR 1910.38 requires procedures for reporting emergencies as a core EAP element.
Question 68: What does 'paralanguage' refer to in the context of professional security communication?
- A secondary programming language used in security scripts
- Encrypted communication protocols
- Jargon used exclusively by security professionals
- Non-verbal vocal elements such as tone, pitch, pace, and volume that influence message interpretation (Correct answer)
Correct answer: Non-verbal vocal elements such as tone, pitch, pace, and volume that influence message interpretation
Paralanguage encompasses vocal qualities beyond words—tone, pacing, and emphasis—that significantly affect how a message is received.
Question 69: Which NIMS component standardizes terminology and processes across multiple agencies responding to an emergency?
- Unified Command
- Incident Command System (ICS) (Correct answer)
- Joint Information Center (JIC)
- Emergency Operations Center (EOC)
Correct answer: Incident Command System (ICS)
ICS provides a standardized, on-scene incident management structure used across all disciplines.
Question 70: A security consultant recommends implementing a 'relief factor' of 1.4 for a 24/7 post. What does this mean in practical staffing terms?
- For every one officer needed on post, 1.4 officers must be employed to cover all shifts, days off, and absences (Correct answer)
- Officers receive a 40% pay increase for working overnight shifts
- Officers work 40% longer shifts than standard to reduce total headcount
- The post requires 40% more physical security equipment than a standard post
Correct answer: For every one officer needed on post, 1.4 officers must be employed to cover all shifts, days off, and absences
A relief factor of 1.4 means you multiply the number of positions by 1.4 to determine total staff needed, accounting for days off, vacation, sick leave, and training time.
Question 71: A security officer at a nightclub uses a chokehold to subdue a combative patron who is hitting another guest. Many jurisdictions have banned chokeholds primarily because:
- Federal OSHA standards prohibit all neck contact
- They require specialized police certification not available to civilians
- They carry a high risk of death or serious injury and disproportionate lethal outcomes (Correct answer)
- They are ineffective against multiple attackers
Correct answer: They carry a high risk of death or serious injury and disproportionate lethal outcomes
Chokeholds compress the airway or carotid arteries and have caused numerous in-custody deaths, leading many jurisdictions to classify them as potentially lethal force.
Question 72: What is the purpose of a treatment plan review?
- To satisfy regulatory audit requirements only
- To evaluate progress and adjust interventions as needed (Correct answer)
- To reduce the number of sessions
- To justify billing codes
Correct answer: To evaluate progress and adjust interventions as needed
Treatment plan reviews evaluate patient progress and allow practitioners to adjust interventions for optimal outcomes, ensuring care remains appropriate and effective.
Question 73: An organization discovers that an attacker has established persistence on their network via a backdoor. After removing the backdoor, what additional step is CRITICAL before declaring recovery complete?
- Updating all user passwords organization-wide
- Replacing all hardware on the network
- Filing a civil lawsuit against the attacker
- Conducting a thorough threat hunt to identify any additional persistence mechanisms (Correct answer)
Correct answer: Conducting a thorough threat hunt to identify any additional persistence mechanisms
Threat hunting after removing a known backdoor is critical because attackers often establish multiple persistence mechanisms to maintain access.
Question 74: When a security officer makes a report of unsafe working conditions or illegal activity, they are protected from retaliation under which federal law?
- The Uniform Services Employment and Reemployment Rights Act (USERRA)
- The Occupational Safety and Health Act (OSHA) whistleblower provisions (Correct answer)
- The Privacy Act of 1974
- The National Labor Relations Act (NLRA) only if they are union members
Correct answer: The Occupational Safety and Health Act (OSHA) whistleblower provisions
OSHA's whistleblower protection program prohibits employers from retaliating against workers who report safety concerns or violations of laws OSHA enforces.
Question 75: How should monitoring alerts be configured?
- Only for critical system failures
- With no thresholds to capture everything
- To alert on every minor deviation
- With meaningful thresholds that indicate actionable conditions (Correct answer)
Correct answer: With meaningful thresholds that indicate actionable conditions
Meaningful thresholds prevent alert fatigue while ensuring actionable conditions are caught, enabling timely response to genuine issues.
Question 76: What is the concept of 'Indicators of Compromise' (IoCs) used for in incident response?
- Measuring employee security awareness
- Documenting regulatory compliance gaps
- Calculating financial losses from an incident
- Identifying artifacts that suggest a system has been breached (Correct answer)
Correct answer: Identifying artifacts that suggest a system has been breached
IoCs are forensic artifacts—such as unusual IP addresses, file hashes, or registry keys—that indicate a system may have been compromised.
Question 77: A security consultant is reviewing a hospital's emergency response plan. Which HICS principle distinguishes hospital incident command from standard ICS?
- Hospitals are exempt from NIMS compliance requirements
- HICS integrates clinical and operational roles into the incident command structure (Correct answer)
- Hospitals use a single command structure rather than unified command
- HICS eliminates the need for a public information officer
Correct answer: HICS integrates clinical and operational roles into the incident command structure
The Hospital Incident Command System (HICS) adapts ICS by incorporating medical and clinical roles alongside standard command functions.
Question 78: In emergency response, what does the term 'span of control' refer to?
- The number of subordinates one supervisor can effectively manage (Correct answer)
- The geographic area under an incident commander's jurisdiction
- The communication range of emergency radio equipment
- The legal authority granted to private security during emergencies
Correct answer: The number of subordinates one supervisor can effectively manage
Span of control in ICS typically ranges from 3 to 7 subordinates, with 5 being optimal.
Question 79: Under the force continuum model, 'officer presence' and 'verbal commands' are categorized as:
- Intermediate force options
- Non-force or minimal force options at the base of the continuum (Correct answer)
- Tactical withdrawal indicators
- Deadly force equivalents when combined
Correct answer: Non-force or minimal force options at the base of the continuum
Presence and verbal commands are the lowest levels on the force continuum and are intended to achieve compliance without physical contact.
Question 80: Under the California Consumer Privacy Act (CCPA) as amended by CPRA, what is the minimum penalty for intentional violations?
- $2,500 per violation
- $1,000 per data record exposed
- $7,500 per intentional violation (Correct answer)
- $100 per consumer
Correct answer: $7,500 per intentional violation
CCPA/CPRA imposes civil penalties of up to $2,500 for unintentional violations and $7,500 per intentional violation, enforced by the California Privacy Protection Agency.
Question 81: What is the significance of professional networking in the Court Security Specialist field?
- It is only important early in one's career
- It facilitates knowledge exchange, referrals, and collaborative problem-solving (Correct answer)
- It distracts from actual work
- It is only useful for finding new employment
Correct answer: It facilitates knowledge exchange, referrals, and collaborative problem-solving
Professional networking facilitates knowledge exchange, generates referrals, and enables collaborative problem-solving that improves practice quality.
Question 82: A CISO receives a threat intelligence report indicating a zero-day vulnerability is being actively exploited against their industry. What is the BEST immediate crisis response action?
- Issue a public statement about the vulnerability
- Activate the incident response team and apply compensating controls while awaiting a patch (Correct answer)
- Shut down all internet-facing systems indefinitely
- Wait for the vendor patch before taking action
Correct answer: Activate the incident response team and apply compensating controls while awaiting a patch
Activating the IR team and deploying compensating controls (such as WAF rules or network segmentation) provides immediate protection while waiting for an official vendor patch.
Question 83: What should be done if an error is discovered in existing records?
- Ignore the error if it seems minor
- Remove the page and rewrite it
- Draw a single line through the error, note the correction, date, and initial (Correct answer)
- Use correction fluid to cover the error
Correct answer: Draw a single line through the error, note the correction, date, and initial
The correct method is a single line through the error with a dated and initialed correction, preserving the original entry for legal and audit purposes.
Question 84: Which legal doctrine holds that an organization must demonstrate it exercised reasonable care in protecting sensitive data to avoid negligence liability?
- Proximate cause
- Duty of care (Correct answer)
- Strict liability
- Respondeat superior
Correct answer: Duty of care
Duty of care requires organizations to take reasonable precautions to protect data; failure to meet this standard can establish negligence.
Question 85: A CSC is designing security for a perimeter with a clear zone. What is the purpose of a 'clear zone' (also called a sterile zone) on both sides of a security fence?
- To provide a buffer area free of obstructions that allows guards and sensors to detect intrusions (Correct answer)
- To mark the legal boundary of property ownership
- To stage emergency vehicles during a security incident
- To designate areas where visitors may wait without escort
Correct answer: To provide a buffer area free of obstructions that allows guards and sensors to detect intrusions
A clear zone eliminates vegetation and obstructions near a fence line so that intrusion detection systems and security personnel have unobstructed visibility.
Question 86: A client asks about the legal requirements for posting signage when deploying video surveillance in a US workplace. What is the BEST general guidance?
- Federal law mandates specific sign dimensions and placement
- Signage is never legally required in the US
- Many US states require visible notice of video surveillance in non-private areas (Correct answer)
- Signage is only required if audio is also being recorded
Correct answer: Many US states require visible notice of video surveillance in non-private areas
While no single federal law mandates workplace surveillance signage, numerous states have enacted notification requirements, and posting signs is considered a best practice to reduce legal liability.
Question 87: Which factor most commonly causes emergency response plans to fail during an actual incident?
- Lack of training and familiarity with the plan among staff (Correct answer)
- Failure to update contact lists annually
- Insufficient number of written plan copies
- Inadequate budget for emergency equipment
Correct answer: Lack of training and familiarity with the plan among staff
Plans fail most often because personnel have not been adequately trained and are unfamiliar with their roles under stress.
Question 88: During incident response, a 'chain of custody' document is maintained primarily to:
- Track responder working hours
- Ensure evidence admissibility in legal or regulatory proceedings (Correct answer)
- Document system uptime metrics
- Speed up the remediation process
Correct answer: Ensure evidence admissibility in legal or regulatory proceedings
Chain of custody documents the handling of evidence to ensure its integrity and admissibility in court or regulatory hearings.
Question 89: Which tabletop exercise element is most valuable for identifying gaps in an emergency response plan?
- Grading participants on individual performance
- Realistic scenario injects that reveal untested decision points (Correct answer)
- Full participation of all 2,000 employees
- Use of live fire or real chemical agents
Correct answer: Realistic scenario injects that reveal untested decision points
Scenario injects introduce unexpected developments that expose gaps in planning and decision-making processes.
Question 90: A security consultant discovers that two department heads are providing contradictory security requirements. What is the BEST first step to resolve this conflict?
- Facilitate a joint meeting to identify common ground and reconcile differences (Correct answer)
- Choose the requirement that is easier to implement
- Document both requirements and implement them separately
- Escalate immediately to the CEO
Correct answer: Facilitate a joint meeting to identify common ground and reconcile differences
Facilitating a joint meeting allows both parties to communicate directly and find a mutually acceptable resolution based on actual security needs.
Question 91: A security consultant is asked to recommend a camera for monitoring a loading dock where license plates must be clearly readable at night. Which camera technology is MOST appropriate?
- Infrared-illuminated fixed camera with narrow field of view (Correct answer)
- Pan-tilt-zoom (PTZ) camera with optical zoom
- Fixed camera with wide dynamic range (WDR)
- Thermal imaging camera
Correct answer: Infrared-illuminated fixed camera with narrow field of view
An IR-illuminated fixed camera with a narrow field of view provides the focused, high-detail nighttime image resolution required to capture legible license plate numbers at the dock entrance.
Question 92: A security consultant recommending a 'hot site' as an alternate recovery facility is describing:
- A mobile command center that can be deployed within 24 hours
- A shared facility leased with other organizations to reduce costs
- A facility with basic infrastructure but no pre-installed equipment
- A fully equipped, immediately operational duplicate of the primary site (Correct answer)
Correct answer: A fully equipped, immediately operational duplicate of the primary site
A hot site is a fully equipped, immediately operational facility that mirrors the primary site and can take over operations with minimal delay.
Question 93: A CSC is asked to evaluate which assets require the most protection. Which criterion should carry the GREATEST weight in this determination?
- The age of the hardware hosting the asset
- The criticality and value of the asset to organizational operations (Correct answer)
- The number of users who access the asset daily
- The physical size of the asset
Correct answer: The criticality and value of the asset to organizational operations
Asset criticality and business value are the primary drivers for prioritizing protection efforts in a risk-based security program.
Question 94: Which recovery time objective (RTO) classification indicates that a function must be restored within 4-24 hours of a disruption?
- Tier 3 – Important
- Tier 2 – Urgent (Correct answer)
- Tier 1 – Immediate
- Tier 4 – Deferrable
Correct answer: Tier 2 – Urgent
Tier 2 (Urgent) functions have RTOs of 4-24 hours, making them high-priority but slightly less critical than immediate functions.
Question 95: A CCTV system's field of view for a parking lot camera is being optimized. Which lens characteristic should a security consultant INCREASE to cover a wider area with a single camera?
- Infrared cut-off frequency
- Angle of view (Correct answer)
- Aperture f-stop
- Focal length
Correct answer: Angle of view
A wider angle of view (achieved with a shorter focal length lens) covers more area, though it reduces image detail; balancing coverage and resolution is key in camera placement.
Question 96: A CSC recommends a threat hunting program to a client. What distinguishes threat hunting from traditional security monitoring?
- Threat hunting is a proactive, hypothesis-driven search for threats that have evaded automated detection (Correct answer)
- Threat hunting replaces incident response procedures
- Threat hunting relies entirely on automated SIEM alert triage
- Threat hunting only addresses external network perimeter threats
Correct answer: Threat hunting is a proactive, hypothesis-driven search for threats that have evaded automated detection
Threat hunting proactively searches for threats using analyst hypotheses and behavioral analytics, targeting adversaries that bypassed automated controls.
Question 97: Which scheduling approach is BEST suited to minimizing security officer fatigue during long-duration contracts requiring continuous coverage?
- Scheduling officers for 24-hour shifts with a 24-hour off period to minimize shift transitions
- Requiring all officers to work 12-hour shifts seven days a week until the contract ends
- Rotating 8- or 10-hour shifts with adequate rest periods between assignments and limits on consecutive days worked (Correct answer)
- Assigning the same officers to the same shifts indefinitely without rotation to build familiarity
Correct answer: Rotating 8- or 10-hour shifts with adequate rest periods between assignments and limits on consecutive days worked
Structured shift rotations with mandatory rest periods prevent cumulative fatigue, which impairs alertness and judgment — critical factors in effective security performance.
Question 98: A client asks a security consultant to remove a critical finding from the final report before it is shared with the board. What is the APPROPRIATE response?
- Explain that omitting validated findings undermines the report's integrity and the client's security posture (Correct answer)
- Issue two separate reports: one complete and one redacted
- Remove the finding to maintain the client relationship
- Downgrade the finding's severity instead of removing it
Correct answer: Explain that omitting validated findings undermines the report's integrity and the client's security posture
Omitting confirmed findings violates professional ethics and may expose both the consultant and client to greater risk.
Question 99: Which factor is most important when determining treatment frequency?
- Practitioner schedule availability
- Evidence-based clinical guidelines and patient response (Correct answer)
- Patient preference alone
- Insurance coverage limits
Correct answer: Evidence-based clinical guidelines and patient response
Treatment frequency should be based on evidence-based clinical guidelines and individual patient response to ensure optimal outcomes.
Question 100: A security consultant finds that a client systematically fails to patch critical vulnerabilities within 30 days. Which CIS Control most directly addresses this gap?
- CIS Control 11 – Data Recovery
- CIS Control 1 – Inventory of Enterprise Assets
- CIS Control 16 – Application Software Security
- CIS Control 7 – Continuous Vulnerability Management (Correct answer)
Correct answer: CIS Control 7 – Continuous Vulnerability Management
CIS Control 7 (Continuous Vulnerability Management) requires organizations to continuously assess and remediate vulnerabilities, including patching critical flaws on a defined schedule.
Certified Security Consultant (CSC)
The CSC credential, awarded by the International Association of Professional Security Consultants (IAPSC), validates expertise in security consulting practices, security management, and professional business ethics for experienced security professionals.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds