CSC Physical Security Operations 2 — Questions and Answers
Question 1: A security consultant is designing an access control system for a data center. Which authentication factor combination provides the highest assurance for physical entry?
- PIN plus smart card
- Smart card plus biometric (Correct answer)
- Biometric plus security question
- PIN plus security guard verification
Correct answer: Smart card plus biometric
Smart card plus biometric combines something-you-have with something-you-are, providing two distinct factor types and the highest assurance for critical facilities.
Question 2: During a physical security assessment, you observe that a facility uses a mantrap at its main entrance. What is the PRIMARY security function of a mantrap?
- To delay forced entry attempts
- To prevent piggybacking and tailgating (Correct answer)
- To detect concealed weapons
- To log entry and exit timestamps
Correct answer: To prevent piggybacking and tailgating
A mantrap (also called an airlock or sally port) prevents unauthorized individuals from following authorized personnel through a secured entrance by ensuring only one person passes through at a time.
Question 3: A company's badge access logs show that an employee's credential was used to enter the facility at 8:02 AM, yet the employee reported arriving at 9:15 AM. This anomaly MOST likely indicates:
- A system clock synchronization error
- Credential sharing or a cloned badge (Correct answer)
- A malfunctioning card reader
- The employee forgot their entry time
Correct answer: Credential sharing or a cloned badge
A credential used before the legitimate holder arrives is a strong indicator of credential sharing or a cloned/stolen badge being used by an unauthorized person.
Question 4: Which ASIS International standard provides guidelines for the development and implementation of an organizational resilience management system, including physical security components?
- ASIS SPC.1
- ASIS PSP Standard
- ASIS GDL-VPPG
- ASIS ORM.1 (Correct answer)
Correct answer: ASIS ORM.1
ASIS ORM.1 (Organizational Resilience Management System) provides requirements and guidance for resilience, while ASIS SPC.1 focuses specifically on supply chain security.
Question 5: A security consultant recommends installing anti-passback controls on an access system. What vulnerability does this control PRIMARILY address?
- Employees sharing their access credentials with visitors
- One badge being used to let multiple people through a single door
- A valid credential being used to exit before it has been used to enter (Correct answer)
- Unauthorized duplication of proximity cards
Correct answer: A valid credential being used to exit before it has been used to enter
Anti-passback prevents a credential from being used to exit an area before it has registered an entry, stopping one card from being passed back through a door to let another person in.
Question 6: When assessing a facility's key control program, which finding represents the GREATEST security risk?
- Keys are not color-coded by department
- Master keys are issued without a key receipt form
- Duplicate keys are stored in an unlocked drawer in the security office (Correct answer)
- Key issuance logs are maintained in paper format
Correct answer: Duplicate keys are stored in an unlocked drawer in the security office
Storing duplicate (or master) keys in an unlocked location completely undermines key control, as anyone with access to the security office can obtain unrestricted keys without detection.
Question 7: A CSC candidate is evaluating a facility that uses proximity card readers for access control. Which attack technique specifically targets these systems by reading a card's RF signal from a distance without the cardholder's knowledge?
- Shoulder surfing
- Relay attack
- Skimming/eavesdropping (Correct answer)
- Brute-force credential attack
Correct answer: Skimming/eavesdropping
Skimming (or RFID eavesdropping) captures the RF signal from a proximity card at a distance, allowing duplication of the credential without the cardholder being aware.
A security consultant is designing an access control system for a data center.
Which authentication factor combination provides the highest assurance for physical entry?