โ† All CSM Flashcard Decks

CSM Physical Security & Access Control Flashcards

6 cards from real CSM practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 CSM Physical Security & Access Control flashcards as text
  1. Which access control model grants permissions based on an individual's job role within an organization?

    Answer: Role-Based Access Control (RBAC)

    RBAC assigns permissions based on predefined job roles, simplifying administration by grouping users with similar access needs.

  2. A security manager is designing a facility entry system requiring two independent authentication factors. This is an example of:

    Answer: Multi-factor authentication (MFA)

    MFA requires two or more independent authentication factors (something you know, have, or are) to verify identity before granting access.

  3. What physical security control is specifically designed to prevent one individual from following another through a secured entry point without authenticating?

    Answer: Mantrap (airlock)

    A mantrap (airlock) is a controlled entry vestibule that allows only one person through at a time, preventing tailgating by requiring individual authentication.

  4. Under the ASIS International standards, the 'defense in depth' principle in physical security refers to:

    Answer: Layering multiple security controls so that failure of one does not compromise the entire system

    Defense in depth uses multiple overlapping security layers so that an attacker must defeat several controls, reducing the likelihood of a successful breach.

  5. Which document typically defines the authority levels, zones, and time-based access rules for a facility's access control system?

    Answer: Access control matrix

    An access control matrix maps users or roles to specific resources, defining what access is permitted, at what times, and in which security zones.

  6. A security manager notices that employees are propping open secured doors for convenience. The BEST long-term corrective action is to:

    Answer: Redesign workflows and entry points to eliminate the inconvenience driving the behavior

    Addressing root-cause inconvenience through redesign is more sustainable than punitive measures, as security controls that hinder workflow are routinely defeated by staff.