Industrial Security Professional (ISP) Certification Exam — Questions and Answers
Question 1: A security policy states that all classified materials must be stored in GSA-approved containers. What type of policy requirement is this?
- Voluntary best practice
- Discretionary control
- Mandatory control (Correct answer)
- Administrative guideline
Correct answer: Mandatory control
GSA-approved container requirements are mandatory controls derived from federal regulation, not discretionary guidelines.
Question 2: Digital forensic investigators use 'write blockers' to:
- Prevent any data from being written to an original evidence drive during imaging, preserving its integrity (Correct answer)
- Block malware from writing to the investigator's workstation
- Speed up the forensic imaging process
- Encrypt evidence drives before analysis
Correct answer: Prevent any data from being written to an original evidence drive during imaging, preserving its integrity
Write blockers create a one-way barrier so the forensic tool can read the drive without modifying any data on it.
Question 3: Which type of investigation focuses specifically on determining the root cause of a security system failure rather than identifying a perpetrator?
- Root cause analysis (RCA) / technical investigation (Correct answer)
- Grand jury investigation
- Administrative investigation
- Criminal investigation
Correct answer: Root cause analysis (RCA) / technical investigation
RCA investigations analyze system failures, process gaps, or equipment malfunctions to prevent recurrence rather than to assign criminal liability.
Question 4: An industrial facility's Emergency Operations Center (EOC) differs from the on-scene command post in that the EOC:
- Provides strategic coordination and resource support removed from the hazard area (Correct answer)
- Is located at the point of the incident for direct oversight
- Is responsible solely for public affairs and media management
- Replaces the Incident Commander's authority during the crisis
Correct answer: Provides strategic coordination and resource support removed from the hazard area
The EOC operates at the strategic level, coordinating logistics, policy decisions, and multi-agency support while the command post handles on-scene tactical operations.
Question 5: What is the role of continuous monitoring in security risk management?
- It reduces the need for employee training.
- It eliminates the need for preventive measures.
- It increases the risk of security breaches.
- It helps identify emerging threats in real-time (Correct answer)
Correct answer: It helps identify emerging threats in real-time
Continuous monitoring involves constantly observing and analyzing security systems, networks, and environments for any unusual activity or new vulnerabilities. This ongoing vigilance allows organizations to detect and respond to emerging threats, changes in risk profiles, or failures in existing controls promptly. It's crucial for maintaining an adaptive and resilient security posture against evolving dangers.
Question 6: A 'continuous evaluation' program in personnel security is designed to:
- Replace the initial security clearance investigation
- Evaluate employee performance on a monthly basis
- Monitor cleared individuals for concerning behaviors between periodic reinvestigations (Correct answer)
- Conduct a new full background investigation every five years
Correct answer: Monitor cleared individuals for concerning behaviors between periodic reinvestigations
Continuous evaluation uses automated record checks to flag relevant derogatory information between reinvestigations without waiting for a scheduled review.
Question 7: Which background investigation element is MOST critical when determining suitability for a sensitive industrial position?
- Credit history review
- All of the above combined (Correct answer)
- Employment verification
- Criminal record check
Correct answer: All of the above combined
A comprehensive personnel security determination requires combining criminal, credit, and employment checks rather than relying on any single element.
Question 8: Under NISPOM, what is the required timeframe for a cleared contractor to report an adverse personnel security action to DCSA?
- Within 90 calendar days
- Within 24 hours
- Within 30 calendar days
- Within 5 business days (Correct answer)
Correct answer: Within 5 business days
NISPOM requires contractors to report adverse information about cleared employees to DCSA within 5 business days of the FSO becoming aware of it.
Question 9: A company's written security policy conflicts with a new DCSA regulation. Which takes precedence?
- The policy in effect at the time the facility clearance was originally granted
- The DCSA regulation, because federal regulations supersede internal company policies (Correct answer)
- Whichever policy is more restrictive, regardless of source
- The company policy, because it is more specific to the facility's operations
Correct answer: The DCSA regulation, because federal regulations supersede internal company policies
Federal regulations like NISPOM have the force of law and always supersede internal company policies; company policies must be updated to reflect new regulatory requirements.
Question 10: A security manager discovers that a former employee's access credentials were used to log in two weeks after termination. This indicates a failure in:
- Annual penetration testing processes
- Fire suppression system maintenance
- Physical perimeter control
- Access termination and offboarding procedures (Correct answer)
Correct answer: Access termination and offboarding procedures
Access that survives beyond an employee's departure indicates the offboarding process failed to revoke credentials in a timely manner.
Question 11: Under the ISP framework, what is 'piggybacking' in the context of access control?
- An authorized person allowing an unauthorized person to follow them through a controlled entry (Correct answer)
- Mounting cameras on fence posts
- Installing a secondary badge reader on an existing door
- Using two-factor authentication simultaneously
Correct answer: An authorized person allowing an unauthorized person to follow them through a controlled entry
Piggybacking (also called tailgating) occurs when an unauthorized person exploits an authorized person's access to pass through a secured door without presenting valid credentials.
Question 12: Which phase of the security risk management cycle involves monitoring implemented controls to verify their continued effectiveness over time?
- Risk identification
- Risk evaluation
- Risk treatment
- Risk review and monitoring (Correct answer)
Correct answer: Risk review and monitoring
Risk review and monitoring is the ongoing phase that ensures controls remain effective as threats, vulnerabilities, and organizational conditions evolve.
Question 13: In the context of industrial security, what is a 'security baseline'?
- The height specification for perimeter fencing
- The minimum acceptable level of security measures required across all facility areas (Correct answer)
- The initial cost estimate for installing security systems
- A record of all past security incidents at the facility
Correct answer: The minimum acceptable level of security measures required across all facility areas
A security baseline defines the minimum set of security controls and measures that must be in place at all times to meet regulatory, organizational, or risk-based requirements.
Question 14: Which assessment methodology involves attempting to defeat security measures through simulated unauthorized access attempts, often unannounced to site staff?
- Red team / adversarial penetration test (Correct answer)
- Gap analysis audit
- Tabletop exercise
- Business impact analysis
Correct answer: Red team / adversarial penetration test
A red team or penetration test simulates real-world attacks against physical and procedural controls, often without staff foreknowledge, to reveal actual vulnerabilities under realistic conditions.
Question 15: An adversarial simulation in which a team attempts to bypass physical and electronic security controls to reach a target within a facility is called a:
- Security survey
- Gap analysis
- Red team assessment (Correct answer)
- Tabletop exercise
Correct answer: Red team assessment
A red team assessment employs adversarial tactics to test physical, electronic, and human security controls under realistic attack conditions.
Question 16: What does 'two-person integrity' (TPI) primarily protect against in a personnel security context?
- Cyber intrusions from external threat actors
- A single insider acting alone to commit theft or sabotage of critical assets (Correct answer)
- Unauthorized photography on the production floor
- Physical injuries during heavy-lifting tasks
Correct answer: A single insider acting alone to commit theft or sabotage of critical assets
TPI requires two authorized individuals to be present during access to sensitive areas or materials, preventing unilateral insider action.
Question 17: In industrial emergency planning, 'consequence analysis' of a potential crisis event is performed to:
- Calculate insurance premiums for hazardous operations
- Determine who is legally responsible for the incident
- Satisfy post-incident reporting requirements only
- Estimate the scope of human, environmental, and economic impacts to guide planning priorities (Correct answer)
Correct answer: Estimate the scope of human, environmental, and economic impacts to guide planning priorities
Consequence analysis quantifies potential impacts of emergency scenarios, enabling planners to allocate resources and develop response strategies proportionate to the risk.
Question 18: Which of the following best describes 'two-person integrity' (TPI) as applied in industrial security?
- Requiring two FSOs to sign off on all security policies
- Requiring dual-factor authentication for all classified computer systems
- Mandating that all classified documents be reviewed by two government officials before release
- Ensuring no single person has unsupervised access to certain sensitive materials or areas (Correct answer)
Correct answer: Ensuring no single person has unsupervised access to certain sensitive materials or areas
Two-person integrity requires at least two authorized, cleared individuals to be present when handling certain sensitive materials to prevent insider threats.
Question 19: A security policy requires visitors to a cleared facility to be escorted at all times in classified areas. What security principle does this BEST represent?
- Physical access control (Correct answer)
- Defense in depth
- Compartmentalization
- Least privilege
Correct answer: Physical access control
Escort requirements are a physical access control measure that prevents unauthorized individuals from accessing classified areas or information unattended.
Question 20: Which of the following is a key element of a classified information handling briefing?
- Budget planning procedures for the security department
- Marketing strategies for the company's products
- How to access personal social media accounts from work devices
- Proper techniques for destroying classified documents, including approved shredding and burning procedures (Correct answer)
Correct answer: Proper techniques for destroying classified documents, including approved shredding and burning procedures
Classified handling briefings must cover proper destruction methods to prevent inadvertent disclosure through improper disposal.
Question 21: Why are security personnel an essential part of physical security?
- To act as customer service representatives.
- To manage office supplies.
- To focus only on security system maintenance.
- To provide physical protection and respond to security events (Correct answer)
Correct answer: To provide physical protection and respond to security events
Security personnel are trained professionals who provide a vital human element to physical security. They actively patrol, monitor systems, enforce policies, and are capable of direct intervention during security incidents. Their presence and ability to respond quickly are crucial for mitigating threats, protecting assets, and ensuring the safety of individuals within the facility.
Question 22: A security risk assessment at an industrial plant identifies 'criticality' of assets. What does criticality PRIMARILY measure?
- The replacement cost of an asset
- The age and depreciation of the asset
- The impact on operations or mission if the asset is lost, damaged, or compromised (Correct answer)
- The difficulty of physically securing the asset
Correct answer: The impact on operations or mission if the asset is lost, damaged, or compromised
Criticality measures how essential an asset is to the organization's mission; a highly critical asset causes severe operational disruption if compromised regardless of its monetary value.
Question 23: An industrial facility uses proximity card readers. Which attack method specifically targets these systems by covertly reading and cloning a valid card from a distance?
- Relay/skimming attack using an RFID reader (Correct answer)
- Social engineering the receptionist
- Shoulder surfing
- Dumpster diving
Correct answer: Relay/skimming attack using an RFID reader
RFID skimming uses a concealed reader to capture card data wirelessly, enabling an attacker to clone a legitimate credential without the cardholder's knowledge.
Question 24: Which risk treatment option involves sharing the financial impact of a risk with a third party such as an insurance provider?
- Risk transference (Correct answer)
- Risk avoidance
- Risk acceptance
- Risk mitigation
Correct answer: Risk transference
Risk transference shifts the financial burden of a risk to another party, typically through insurance or contracts.
Question 25: The principle of 'least privilege' in cybersecurity means:
- Granting users the maximum access possible to avoid productivity delays
- Applying security controls only to the most critical systems
- Giving users only the minimum access rights needed to perform their job functions (Correct answer)
- Allowing all administrators unrestricted access for efficiency
Correct answer: Giving users only the minimum access rights needed to perform their job functions
Least privilege minimizes the potential damage from accidents, errors, or attacks by limiting what any single account can access or modify.
Question 26: Under CFATS (Chemical Facility Anti-Terrorism Standards), facilities are ranked into tiers primarily based on:
- Proximity to critical infrastructure such as ports and airports
- Type of ownership — public, private, or government
- Annual revenue and number of employees
- The risk posed by the chemicals they hold relative to terrorist attack potential (Correct answer)
Correct answer: The risk posed by the chemicals they hold relative to terrorist attack potential
CFATS assigns facilities to Tiers 1–4 based on the level of security risk their chemicals of interest present, with Tier 1 being the highest risk.
Question 27: What is the primary purpose of CPTED (Crime Prevention Through Environmental Design) in industrial security?
- Replacing human guards with automated systems
- Training employees in self-defense techniques
- Designing the physical environment to deter criminal activity naturally (Correct answer)
- Installing the maximum number of cameras possible
Correct answer: Designing the physical environment to deter criminal activity naturally
CPTED uses environmental design principles—lighting, sightlines, landscaping, and space management—to naturally discourage criminal behavior without purely relying on hardware.
Question 28: Which access control model grants permissions based on a user's job function rather than individual identity?
- Mandatory Access Control (MAC)
- Attribute-Based Access Control (ABAC)
- Discretionary Access Control (DAC)
- Role-Based Access Control (RBAC) (Correct answer)
Correct answer: Role-Based Access Control (RBAC)
RBAC assigns permissions to roles rather than individuals, simplifying administration and enforcing least privilege by job function.
Question 29: The 'Security In Depth' training concept teaches employees to:
- Rely exclusively on perimeter security controls to stop threats
- Apply multiple overlapping security behaviors so the failure of one control is caught by another (Correct answer)
- Focus security attention only on the most classified systems
- Specialize in a single security domain rather than understanding the whole picture
Correct answer: Apply multiple overlapping security behaviors so the failure of one control is caught by another
Defense-in-depth training reinforces that no single control is perfect and that layered behaviors provide resilience against security failures.
Question 30: In an industrial security information classification scheme, which label typically applies to trade secrets and proprietary formulas?
- Top Secret
- Confidential / Proprietary (Correct answer)
- Public
- Internal Use Only
Correct answer: Confidential / Proprietary
Confidential or Proprietary is the standard commercial classification for sensitive business information like trade secrets that require restricted handling.
Question 31: When establishing a command post during an industrial emergency, it should be located:
- Upwind and uphill from the incident site (Correct answer)
- At the main entrance gate for easy public access
- Adjacent to the affected area for direct oversight
- Inside the facility to maintain communication with workers
Correct answer: Upwind and uphill from the incident site
Positioning the command post upwind and uphill keeps responders out of hazardous vapors and runoff from the incident site.
Question 32: How can risk assessments help in preventing security breaches?
- By increasing the frequency of security patrols.
- By increasing the number of security personnel.
- By identifying and addressing potential threats and vulnerabilities (Correct answer)
- By reducing the number of access points.
Correct answer: By identifying and addressing potential threats and vulnerabilities
Risk assessments systematically pinpoint weaknesses in an organization's security posture and potential external or internal dangers. By understanding these threats and vulnerabilities, organizations can proactively implement targeted controls and measures to prevent breaches before they occur. This proactive approach is crucial for robust security.
Question 33: Which federal guideline governs adjudicative standards for personnel security clearances in U.S. industrial environments?
- Title 18 U.S. Code Section 1030
- ISO 27001 Annex A
- NIST SP 800-53
- The 13 Adjudicative Guidelines (Security Executive Agent Directive 4) (Correct answer)
Correct answer: The 13 Adjudicative Guidelines (Security Executive Agent Directive 4)
SEAD 4 establishes the 13 Adjudicative Guidelines used to evaluate individuals for U.S. government-related security clearances.
Question 34: What is the importance of security policy enforcement?
- To ensure that security measures are followed consistently (Correct answer)
- To reduce the number of security breaches.
- To eliminate the need for employee training.
- To limit employee access to security systems.
Correct answer: To ensure that security measures are followed consistently
Policy enforcement translates written security policies into actionable and consistently followed practices. Without consistent enforcement, policies become ineffective, creating vulnerabilities that can be exploited by malicious actors. It ensures accountability, reinforces the importance of security, and guarantees that all employees adhere to the established rules and procedures, thereby strengthening the overall security posture.
Question 35: Which of the following is NOT one of the 13 Adjudicative Guidelines under SEAD 4?
- Drug Involvement
- Allegiance to the United States
- Physical Fitness Standards (Correct answer)
- Sexual Behavior
Correct answer: Physical Fitness Standards
Physical fitness is not an adjudicative guideline; the 13 guidelines focus on loyalty, conduct, and character issues relevant to trustworthiness.
Question 36: When investigating a suspected theft of trade secrets, which type of specialist should typically be involved?
- Legal counsel with IP and employment law expertise (Correct answer)
- Payroll administrator
- Customer service manager
- Marketing analyst
Correct answer: Legal counsel with IP and employment law expertise
IP theft investigations have significant legal dimensions requiring attorneys familiar with trade secret law, employment agreements, and evidence handling.
Question 37: Under ISP principles, 'target hardening' refers to:
- Making an asset more difficult or costly to attack by adding physical and procedural barriers (Correct answer)
- Hardening digital systems against cyberattacks only
- Increasing the frequency of security audits
- Psychologically preparing security staff for high-stress incidents
Correct answer: Making an asset more difficult or costly to attack by adding physical and procedural barriers
Target hardening involves increasing physical and procedural barriers—locks, reinforced doors, access controls, lighting—to raise the effort and risk required for an attacker to succeed.
Question 38: An ISP candidate is reviewing access control lists. Who is responsible for defining WHAT resources a user may access in a role-based access control (RBAC) system?
- The third-party security vendor
- The end user based on their preference
- The data/resource owner or asset custodian (Correct answer)
- The system administrator acting as the data owner's proxy
Correct answer: The data/resource owner or asset custodian
In RBAC, the data owner or asset custodian determines access rights; administrators implement those rights in the system, but ownership of the decision rests with the resource owner.
Question 39: What is the primary goal of physical security in facility protection?
- To protect facilities and assets from physical threats (Correct answer)
- To increase facility profits.
- To reduce energy consumption.
- To minimize employee involvement in security.
Correct answer: To protect facilities and assets from physical threats
Physical security is specifically designed to protect tangible assets, personnel, and the physical environment from harm. Its primary objective is to prevent unauthorized access, theft, vandalism, and other physical threats that could disrupt operations or compromise safety. This ensures the integrity and continuous operation of the facility and its valuable contents.
Question 40: Which federal regulation requires contractors handling classified information to implement supply chain risk management (SCRM) practices?
- SOX Section 404
- NISPOM (32 CFR Part 117) (Correct answer)
- OSHA 1910.119
- HIPAA Security Rule
Correct answer: NISPOM (32 CFR Part 117)
The National Industrial Security Program Operating Manual (NISPOM), codified at 32 CFR Part 117, governs cleared contractors and includes supply chain risk management requirements.
Question 41: Which process is used to verify that employees only retain access rights appropriate to their current role?
- Periodic reinvestigation
- Visitor log auditing
- Annual security awareness training
- Access recertification or entitlement review (Correct answer)
Correct answer: Access recertification or entitlement review
Access recertification (entitlement review) is the formal process of confirming that each user's permissions still match their job requirements.
Question 42: Under NIMS, 'unified command' is used when an incident:
- Is classified as a Level 1 minor incident only
- Involves multiple jurisdictions or agencies with shared authority (Correct answer)
- Involves only a single agency with no mutual aid
- Requires immediate evacuation of all personnel
Correct answer: Involves multiple jurisdictions or agencies with shared authority
Unified command under NIMS allows multiple agencies or jurisdictions to jointly manage an incident while maintaining individual authority and accountability.
Question 43: What is the role of lighting in facility protection?
- To enhance security by increasing visibility and deterring crime (Correct answer)
- To reduce energy consumption.
- To improve workplace morale.
- To improve employee comfort.
Correct answer: To enhance security by increasing visibility and deterring crime
Proper lighting eliminates dark spots and shadows, which can be exploited by intruders to conceal their activities. Increased visibility makes it harder for unauthorized individuals to approach or operate undetected, thereby deterring criminal activity. It also allows surveillance systems to function more effectively and helps security personnel identify potential threats.
Question 44: What is the primary purpose of a security awareness training program in an industrial security context?
- To serve as a substitute for background investigations
- To fulfill a contractual billing requirement to the government
- To ensure employees recognize threats and understand their security responsibilities (Correct answer)
- To qualify employees for access to higher classification levels
Correct answer: To ensure employees recognize threats and understand their security responsibilities
Security awareness training ensures all personnel understand threats like insider threats, social engineering, and their duty to protect classified information.
Question 45: Under NISPOM, which document formally authorizes a cleared contractor to perform classified work at a specific location?
- Classified Facility Authorization Letter (CFAL)
- Security Classification Guide (SCG)
- Certificate of Clearance (COC)
- Contract Security Classification Specification (DD Form 254) (Correct answer)
Correct answer: Contract Security Classification Specification (DD Form 254)
The DD Form 254 is the official government document that specifies the security requirements and classification levels applicable to a classified contract.
Question 46: During an industrial facility crisis, the Incident Command System (ICS) designates a single person as Incident Commander primarily to:
- Ensure unified command and clear accountability (Correct answer)
- Reduce costs by eliminating multiple managers
- Satisfy OSHA regulatory requirements only
- Prevent employees from contacting media
Correct answer: Ensure unified command and clear accountability
ICS uses a single Incident Commander to establish unified command, clear span of control, and unambiguous accountability during emergencies.
Question 47: A security manager is designing an alarm system for an industrial warehouse. What is the key difference between 'local' and 'central station' alarm monitoring?
- Central station systems do not require sensors at the facility
- Local alarms are more expensive than central station systems
- Local alarms alert only on-site personnel; central station monitoring notifies a remote 24/7 monitoring facility that can dispatch responders (Correct answer)
- Local alarms automatically lock all doors; central stations do not
Correct answer: Local alarms alert only on-site personnel; central station monitoring notifies a remote 24/7 monitoring facility that can dispatch responders
Local alarms sound on site, relying on nearby response, while central station systems transmit alerts to a professionally staffed remote monitoring center that can coordinate emergency response.
Question 48: What is the importance of regular security audits?
- To reduce security costs.
- To increase security breaches.
- To ensure security measures are working and identify areas for improvement (Correct answer)
- To limit employee involvement.
Correct answer: To ensure security measures are working and identify areas for improvement
Regular security audits are essential for continuously assessing the effectiveness of existing security controls and identifying any vulnerabilities or outdated practices. They help ensure that security measures are functioning as intended and highlight areas that require improvement or updating. This proactive evaluation allows organizations to adapt and strengthen their security posture against evolving threats.
Question 49: Why is compliance with legal and regulatory requirements important for security management?
- To avoid employee accountability.
- To increase the number of security personnel.
- To avoid legal penalties and protect organizational reputation (Correct answer)
- To limit security system installation.
Correct answer: To avoid legal penalties and protect organizational reputation
Compliance with legal and regulatory requirements is crucial because failure to adhere to these standards can result in significant financial penalties, legal action, and severe damage to an organization's reputation. Adhering to these mandates demonstrates due diligence and a commitment to security, fostering trust with customers, partners, and stakeholders. It also helps avoid operational disruptions caused by non-compliance issues.
Question 50: In an industrial facility, a 'sally port' or 'mantrap' is primarily used to:
- Store emergency response equipment
- Provide a secondary fire exit route
- Prevent piggybacking by allowing only one person to enter at a time (Correct answer)
- House security guard shift change records
Correct answer: Prevent piggybacking by allowing only one person to enter at a time
A sally port or mantrap uses two interlocking doors so the first must close before the second opens, preventing piggybacking (tailgating) into secure areas.
Question 51: What is the MAIN advantage of a video analytics system over traditional CCTV monitoring in a large industrial facility?
- Higher image resolution
- Longer video retention periods
- Lower camera hardware cost
- Automated detection of predefined behaviors without requiring continuous human monitoring (Correct answer)
Correct answer: Automated detection of predefined behaviors without requiring continuous human monitoring
Video analytics software analyzes footage in real time to automatically alert on specific behaviors (e.g., perimeter crossing, loitering), reducing human fatigue and missed events.
Question 52: Under the Privacy Act of 1974, what right do U.S. citizens have regarding federal agency records about them?
- The right to access and request amendments to their records (Correct answer)
- The right to prevent any government agency from collecting personal data
- The right to financial compensation for any data stored about them
- The right to have all records about them permanently deleted
Correct answer: The right to access and request amendments to their records
The Privacy Act gives individuals the right to access federal records about themselves and request corrections to inaccurate information.
Question 53: What is the key distinction between a 'security violation' and a 'security deviation' under NISPOM?
- A violation is a confirmed unauthorized disclosure; a deviation is a procedural failure that did not necessarily compromise information (Correct answer)
- A deviation is more serious and requires DCSA reporting; a violation can be handled internally
- There is no distinction — the terms are interchangeable
- A violation involves classified information; a deviation involves only unclassified information
Correct answer: A violation is a confirmed unauthorized disclosure; a deviation is a procedural failure that did not necessarily compromise information
A security deviation is a procedural failure (e.g., open vault door), while a security violation involves an actual or suspected unauthorized disclosure of classified information.
Question 54: Why is it important to have a business continuity plan?
- To ensure that critical operations continue during a crisis (Correct answer)
- To decrease operational efficiency.
- To reduce customer trust.
- To increase the likelihood of a crisis.
Correct answer: To ensure that critical operations continue during a crisis
A business continuity plan (BCP) focuses on maintaining essential business functions during and after a disruptive event, such as a natural disaster or cyberattack. It outlines strategies and procedures to minimize downtime, recover critical systems, and ensure the ongoing delivery of products or services. This safeguards an organization's financial stability, customer relationships, and overall operational resilience.
Question 55: Which phase of an incident response plan involves returning systems to normal operations after a security event?
- Containment
- Identification
- Recovery (Correct answer)
- Lessons Learned
Correct answer: Recovery
The recovery phase restores affected systems and verifies they are clean and functional before returning them to production.
Question 56: Which security control is MOST critical when allowing third-party vendors to remotely access ICS/OT systems for maintenance?
- Implementing time-limited, monitored, and audited remote access sessions with least-privilege accounts specific to the maintenance task (Correct answer)
- Granting vendors permanent administrative access to reduce service call delays
- Using unencrypted direct modem connections for legacy system compatibility
- Allowing vendors to use their own VPN credentials for convenience
Correct answer: Implementing time-limited, monitored, and audited remote access sessions with least-privilege accounts specific to the maintenance task
Vendor remote access is a major ICS attack vector; time-limited, monitored sessions with just-in-time access dramatically reduce the risk window.
Question 57: An air-gapped network in an industrial environment means:
- The network uses wireless frequencies exclusively
- The network operates at lower bandwidth to reduce attack surface
- The network is physically isolated with no connections to external or untrusted networks (Correct answer)
- The network uses encrypted tunnels to connect to the internet
Correct answer: The network is physically isolated with no connections to external or untrusted networks
An air gap is a physical security measure that prevents a network from connecting to external systems, limiting remote attack vectors.
Question 58: Encryption of data in transit is BEST enforced in an industrial network by requiring:
- All communications to use plaintext for troubleshooting visibility
- Verbal communication only for classified operational data
- Transport Layer Security (TLS) or equivalent cryptographic protocols on all network channels (Correct answer)
- Physical mail delivery for sensitive documents
Correct answer: Transport Layer Security (TLS) or equivalent cryptographic protocols on all network channels
TLS ensures data integrity and confidentiality while in transit across networks that may traverse untrusted segments.
Question 59: What is the primary legal reason for maintaining a 'chain of custody' during a security investigation?
- To comply with annual audit requirements
- To ensure the fastest possible resolution of the incident
- To preserve the integrity and admissibility of evidence in legal or disciplinary proceedings (Correct answer)
- To assign blame quickly within the organization
Correct answer: To preserve the integrity and admissibility of evidence in legal or disciplinary proceedings
Proper chain of custody documents who handled evidence and when, ensuring it has not been tampered with and remains legally admissible.
Question 60: An employee discovers a coworker has taken classified documents home without authorization. Under NISPOM, what is the employee's FIRST obligation?
- Wait to see if the coworker returns the documents before reporting
- Confront the coworker directly and demand return of the documents
- File a report directly with DCSA, bypassing the FSO
- Report the incident to the Facility Security Officer (FSO) immediately (Correct answer)
Correct answer: Report the incident to the Facility Security Officer (FSO) immediately
Employees have a mandatory duty to report security violations to the FSO, who then determines appropriate escalation steps.
Question 61: The 'need-to-know' principle in personnel security means:
- Any cleared employee may access all information at their clearance level
- Access to specific information is granted only when operationally necessary for assigned duties (Correct answer)
- Employees need to know all security procedures regardless of role
- Managers must know all employees' personal background information
Correct answer: Access to specific information is granted only when operationally necessary for assigned duties
Need-to-know limits access to information to only what is required for a person to perform their specific job functions.
Question 62: What is the role of confidentiality in security policies?
- To increase the level of public access.
- To reduce the use of encryption.
- To protect sensitive information from unauthorized access (Correct answer)
- To limit the number of employees.
Correct answer: To protect sensitive information from unauthorized access
Confidentiality is a core principle of information security, ensuring that sensitive data is accessible only to authorized individuals. Security policies establish clear rules for handling, storing, and transmitting such information, preventing its unauthorized disclosure to those without a legitimate need-to-know. This safeguards privacy, proprietary data, and intellectual property from compromise.
Question 63: Which program element is essential to a robust Insider Threat Program (InTP)?
- Installing covert recording devices in break rooms
- Reporting all suspicious behavior directly to law enforcement without internal review
- Reviewing only IT access logs on an annual basis
- Establishing a multidisciplinary hub that integrates HR, IT, security, and legal data (Correct answer)
Correct answer: Establishing a multidisciplinary hub that integrates HR, IT, security, and legal data
An effective InTP requires a cross-functional team that combines data from multiple departments to detect and deter insider threats.
Question 64: Which element is considered the cornerstone of an effective Business Continuity Plan (BCP) for an industrial facility?
- A Business Impact Analysis (BIA) identifying critical functions (Correct answer)
- Employee personal contact information
- Insurance policy coverage limits
- A detailed list of all facility assets
Correct answer: A Business Impact Analysis (BIA) identifying critical functions
The Business Impact Analysis identifies critical business functions, acceptable downtime, and recovery priorities, forming the foundation of any BCP.
Question 65: An industrial security professional recommends installing vehicle barriers at a facility entrance after a vehicle-ramming threat is identified. This recommendation is an example of which risk treatment strategy?
- Risk mitigation (Correct answer)
- Risk avoidance
- Risk acceptance
- Risk transference
Correct answer: Risk mitigation
Installing vehicle barriers reduces the likelihood or impact of a vehicle-ramming attack, making it a risk mitigation (reduction) strategy.
Question 66: A security manager discovers that a fence line runs within 10 feet of a critical building wall. What is the PRIMARY concern?
- The standoff distance is too small to detect intruders or stop vehicle attacks (Correct answer)
- Emergency responders cannot access the building
- Insufficient lighting between the fence and wall
- The fence material may corrode near the building
Correct answer: The standoff distance is too small to detect intruders or stop vehicle attacks
Inadequate standoff distance reduces response time and may allow a vehicle or individual breaching the perimeter to immediately reach the critical structure.
Question 67: Under the General Duty Clause of OSHA, employers in industrial settings are required to:
- Submit risk assessments to OSHA quarterly
- Maintain a minimum of two armed security officers per shift
- Conduct annual security audits audited by a certified third party
- Provide a workplace free from recognized hazards likely to cause death or serious harm (Correct answer)
Correct answer: Provide a workplace free from recognized hazards likely to cause death or serious harm
The General Duty Clause requires employers to provide a workplace free from recognized serious hazards, forming the baseline obligation for industrial security.
Question 68: An industrial security investigation MUST remain within which legal boundary when interviewing employees?
- Employees may be detained indefinitely pending investigation outcomes
- Investigators may use physical coercion if the employee refuses to cooperate
- Investigators can review employee medical records without consent
- Employees must be informed of their rights, and interviews must comply with applicable labor and employment law (Correct answer)
Correct answer: Employees must be informed of their rights, and interviews must comply with applicable labor and employment law
Industrial security investigations must respect labor laws, privacy rights, and employee rights to counsel to avoid legal liability.
Question 69: What is the primary function of a 'security operations center' (SOC) in a large industrial facility?
- Storing classified documents securely
- Centrally monitoring alarms, cameras, and access control events and coordinating security responses (Correct answer)
- Conducting background investigations on new hires
- Managing employee payroll and HR functions
Correct answer: Centrally monitoring alarms, cameras, and access control events and coordinating security responses
An SOC serves as the nerve center for real-time monitoring of all security systems and coordinating responses to alarms, incidents, and anomalies across the facility.
Question 70: What does 'triage' mean in the context of security incident management?
- Escalating every incident to executive leadership immediately
- Eliminating all infected systems from the network immediately
- Documenting every detail before taking any action
- Quickly assessing and prioritizing incidents based on severity and potential impact to allocate response resources (Correct answer)
Correct answer: Quickly assessing and prioritizing incidents based on severity and potential impact to allocate response resources
Triage allows security teams to focus limited resources on the most critical incidents first by rapidly assessing severity.
Question 71: A 'security baseline' in an industrial information security program refers to:
- A benchmark test for measuring network throughput
- The highest security standard applied only to classified networks
- The minimum acceptable configuration and security controls applied uniformly to all systems (Correct answer)
- The starting point for a risk assessment before any controls are applied
Correct answer: The minimum acceptable configuration and security controls applied uniformly to all systems
A security baseline defines the minimum set of controls every system must have, ensuring a consistent security floor across the organization.
Question 72: Which type of insider threat actor is typically motivated by ideology rather than financial gain?
- The ideological spy acting on behalf of a cause or foreign entity (Correct answer)
- The disgruntled employee seeking revenge
- The opportunistic thief stealing for personal enrichment
- The careless employee who accidentally leaks information
Correct answer: The ideological spy acting on behalf of a cause or foreign entity
Ideological insiders are motivated by beliefs or loyalty to a cause, making them distinct from financially motivated or careless actors.
Question 73: Which component of the risk equation directly measures the probability that a specific threat will materialize within a defined time period?
- Threat likelihood (Correct answer)
- Impact severity
- Vulnerability rating
- Asset value
Correct answer: Threat likelihood
Threat likelihood (or probability) quantifies how often or how probably a specific threat event will occur within a given timeframe.
Question 74: Which training delivery method is MOST effective for building practical decision-making skills in security scenarios?
- Scenario-based and simulation training that mirrors real-world security challenges (Correct answer)
- Reviewing a policy checklist before signing an acknowledgment form
- Reading a printed security manual independently
- Watching a recorded lecture with no interaction
Correct answer: Scenario-based and simulation training that mirrors real-world security challenges
Scenario-based training engages learners by placing them in realistic situations that develop judgment and response skills.
Question 75: A mass casualty incident at an industrial facility overwhelms on-site medical resources. The correct triage system used by first responders to rapidly categorize victims is:
- START (Simple Triage and Rapid Treatment) (Correct answer)
- ICS Form 201 documentation
- CBRN decontamination protocol
- SALUTE reporting
Correct answer: START (Simple Triage and Rapid Treatment)
START triage categorizes victims into immediate, delayed, minimal, and expectant groups in under 60 seconds per patient to maximize survivability with limited resources.
Question 76: An Industrial Control System (ICS) SCADA network differs from a traditional IT network primarily because:
- ICS networks exclusively use wireless communication protocols
- ICS/SCADA systems control physical processes with real-time requirements where downtime or errors can have safety consequences (Correct answer)
- SCADA networks require faster internet connectivity
- SCADA systems are always connected to the public internet for remote monitoring
Correct answer: ICS/SCADA systems control physical processes with real-time requirements where downtime or errors can have safety consequences
ICS/SCADA systems manage physical processes—pipelines, power grids, manufacturing lines—where cyber failures can directly cause physical harm or safety incidents.
Question 77: In risk management, the 'single loss expectancy' (SLE) is calculated by multiplying:
- Asset value by annualized rate of occurrence
- Threat likelihood by countermeasure cost
- Asset value by exposure factor (Correct answer)
- Exposure factor by annualized rate of occurrence
Correct answer: Asset value by exposure factor
SLE = Asset Value Ă— Exposure Factor, representing the expected monetary loss from a single occurrence of a specific threat.
Question 78: What is a 'zero-day vulnerability'?
- A vulnerability with no exploits available in any threat database
- A software flaw unknown to the vendor for which no patch exists at the time of discovery or exploitation (Correct answer)
- A vulnerability discovered exactly at midnight
- A flaw in a zero-trust network architecture
Correct answer: A software flaw unknown to the vendor for which no patch exists at the time of discovery or exploitation
Zero-day vulnerabilities are particularly dangerous because defenders have 'zero days' to patch before the flaw can be exploited.
Question 79: Why is incident response planning important in security risk management?
- To avoid making security decisions.
- To ensure a coordinated and effective response to security incidents (Correct answer)
- To delay response times.
- To increase the number of security breaches.
Correct answer: To ensure a coordinated and effective response to security incidents
Incident response planning provides a structured framework for how an organization will react to a security breach or event. A well-defined plan ensures that all necessary steps are taken in a timely and organized manner, minimizing damage, facilitating recovery, and maintaining business continuity. It outlines roles, responsibilities, and procedures, preventing chaos during a crisis.
Question 80: A facility security officer (FSO) must ensure visitor escort procedures are followed. What is the MINIMUM requirement for escorting an uncleared visitor in a controlled industrial area?
- Two uncleared visitors may escort each other
- A cleared, authorized employee must accompany the visitor at all times within the controlled area (Correct answer)
- The visitor must sign a non-disclosure agreement only
- Visitors must wear a distinctive badge but may move freely
Correct answer: A cleared, authorized employee must accompany the visitor at all times within the controlled area
Cleared, authorized personnel must escort uncleared visitors continuously within controlled or restricted areas to prevent unauthorized access to sensitive information or assets.
Question 81: The concept of 'functional safety' in an industrial security context refers to:
- Ensuring the security team's workstations are ergonomically designed
- The correct functioning of safety-critical systems that depend on automated protective actions to prevent hazardous conditions (Correct answer)
- Personal protective equipment requirements for maintenance staff
- Annual safety drills for fire evacuations
Correct answer: The correct functioning of safety-critical systems that depend on automated protective actions to prevent hazardous conditions
Functional safety ensures safety instrumented systems (SIS) operate correctly to automatically protect personnel and equipment from dangerous process conditions.
Question 82: What does the term 'need-to-know' mean in the context of classified information access?
- The individual holds a clearance at least one level above the classification
- The individual's supervisor has verbally approved access on request
- Access is required to perform an officially assigned duty or task (Correct answer)
- The individual has completed required security training for that classification level
Correct answer: Access is required to perform an officially assigned duty or task
Need-to-know means a person must require access to specific classified information to perform their official duties, even if they hold the appropriate clearance level.
Question 83: What is the role of surveillance systems in physical security?
- To increase the cost of security systems.
- To reduce employee morale.
- To focus only on monitoring employees.
- To monitor and deter unauthorized activities (Correct answer)
Correct answer: To monitor and deter unauthorized activities
Surveillance systems, such as CCTV cameras, serve as a critical tool for continuous monitoring of an area. Their visible presence acts as a deterrent to potential intruders or malicious activities, while also providing crucial visual evidence for investigations if an incident occurs. This enhances overall security by increasing situational awareness and accountability.
Question 84: During a crisis, 'rumor control' is best managed by:
- Releasing partial information in stages to control panic
- Prohibiting all employee communications during the incident
- Establishing a Joint Information Center with consistent, timely messaging (Correct answer)
- Delegating media relations to individual department heads
Correct answer: Establishing a Joint Information Center with consistent, timely messaging
A Joint Information Center coordinates consistent messaging from all responding agencies, reducing information gaps that allow harmful rumors to spread.
Question 85: Why is leadership important in crisis management?
- To delay the decision-making process.
- To ignore the crisis until it passes.
- To focus only on business continuity.
- To ensure that decisions are made quickly and effectively (Correct answer)
Correct answer: To ensure that decisions are made quickly and effectively
Strong leadership is critical during a crisis to provide clear direction, make swift and informed decisions under immense pressure, and maintain calm among the team. Leaders guide the crisis management team, allocate resources effectively, and communicate the organization's stance to internal and external stakeholders. Their decisive actions are essential for navigating the crisis successfully and minimizing its impact.
Question 86: An employee reports that a coworker has been downloading large volumes of proprietary schematics to a personal USB drive. The FIRST security response should be:
- Immediately confront the coworker in front of the team
- Post a notice about USB policies on the bulletin board
- Disable the entire facility's USB ports without investigation
- Document the observation and report it to the insider threat officer or security manager (Correct answer)
Correct answer: Document the observation and report it to the insider threat officer or security manager
Proper reporting to the designated security authority allows a structured investigation without tipping off the subject or compromising evidence.
Question 87: Which executive order originally established the current framework for classifying, safeguarding, and declassifying national security information?
- Executive Order 12958
- Executive Order 13526 (Correct answer)
- Executive Order 12829
- Executive Order 13556
Correct answer: Executive Order 13526
Executive Order 13526, signed in 2009, is the current authority governing the classification system for national security information.
Question 88: Which approach to cybersecurity assumes that no user, device, or network segment should be trusted by default, even inside the perimeter?
- Perimeter-based security
- Zero Trust Architecture (Correct answer)
- Security through obscurity
- Defense-in-depth
Correct answer: Zero Trust Architecture
Zero Trust operates on the principle of 'never trust, always verify,' requiring continuous authentication and authorization regardless of network location.
Question 89: How can perimeter security help protect a facility?
- By blocking unauthorized access and enhancing protection (Correct answer)
- By reducing security surveillance.
- By increasing facility use for non-security purposes.
- By increasing the number of security guards.
Correct answer: By blocking unauthorized access and enhancing protection
Perimeter security establishes a clear boundary around a facility, acting as the first line of defense against external threats. Elements like fences, gates, and intrusion detection systems are designed to detect, deter, and delay unauthorized entry. This helps to control access to the entire property and provides early warning of potential security breaches.
Question 90: Social engineering targeting employees is BEST countered by:
- Installing email filters that block all external messages
- Requiring managers to approve every employee decision
- Restricting all employee communication with external parties
- Ongoing security awareness training and clear reporting procedures (Correct answer)
Correct answer: Ongoing security awareness training and clear reporting procedures
Awareness training equips employees to recognize social engineering tactics and empowers them to report suspicious contacts.
Question 91: Which risk management standard published by ASIS International provides comprehensive guidance specifically for organizational resilience and security management?
- DHS CFATS
- NFPA 730
- ASIS SPC.1-2009 (Correct answer)
- ISO 27001
Correct answer: ASIS SPC.1-2009
ASIS SPC.1-2009 (Organizational Resilience Standard) provides a framework for security, preparedness, and continuity management aligned with ASIS professional practice.
Question 92: Which regulatory framework governs the protection of Controlled Unclassified Information (CUI) in non-federal U.S. industrial organizations?
- PCI DSS
- HIPAA
- SOX
- NIST SP 800-171 / CMMC (Correct answer)
Correct answer: NIST SP 800-171 / CMMC
NIST SP 800-171 and its enforcement mechanism CMMC apply to contractors and industrial firms handling CUI on behalf of the U.S. government.
Question 93: How does a security audit contribute to risk management?
- By increasing the number of employees involved.
- By delaying risk management actions.
- By focusing only on technical systems.
- By identifying vulnerabilities and improving security practices (Correct answer)
Correct answer: By identifying vulnerabilities and improving security practices
A security audit systematically evaluates an organization's security posture, identifying weaknesses and vulnerabilities in its systems and processes. By pinpointing these gaps, the organization can implement targeted improvements and strengthen its defenses. This proactive identification and remediation of flaws are crucial for effective risk management, reducing the likelihood and impact of potential security incidents.
Question 94: When an employee is terminated, which security action should be taken IMMEDIATELY?
- Allowing the employee to retain email access to complete handover
- Revoking all logical and physical access simultaneously upon departure (Correct answer)
- Scheduling a 30-day transition period before revoking access
- Waiting for HR to file paperwork before notifying IT
Correct answer: Revoking all logical and physical access simultaneously upon departure
Simultaneous revocation of all access upon termination prevents a departing employee from exfiltrating data or entering the facility.
Question 95: What does the ISP body of knowledge define as the OUTER layer of the 'defense-in-depth' model for physical security?
- Electronic access control systems
- Perimeter barriers and boundary definition (Correct answer)
- Asset storage vaults
- Building interior controls
Correct answer: Perimeter barriers and boundary definition
Defense-in-depth layers security from outer perimeter barriers inward through building envelope controls to inner asset protection, with the perimeter being the outermost layer.
Question 96: Which type of lock is MOST resistant to picking and considered appropriate for high-security industrial access points?
- Wafer tumbler lock
- Combination padlock
- High-security disc-detainer or medeco lock (Correct answer)
- Standard pin tumbler lock
Correct answer: High-security disc-detainer or medeco lock
High-security locks such as Medeco or disc-detainer designs use complex mechanisms with tight tolerances that resist picking, drilling, and key duplication.
Question 97: Which lighting standard is commonly referenced for industrial perimeter security to ensure adequate illumination for camera systems and guard patrol?
- Flood lighting at 50 foot-candles everywhere on site
- No standard exists; lighting is purely discretionary
- Minimum 5 foot-candles at all exterior doors only
- Minimum 0.2 foot-candles at grade level along the perimeter (Correct answer)
Correct answer: Minimum 0.2 foot-candles at grade level along the perimeter
Industry guidelines (including ASIS standards) typically recommend a minimum of 0.2 foot-candles at grade along perimeters to support detection by cameras and patrol.
Question 98: What is a 'security poster campaign' PRIMARILY used for in an industrial security program?
- Displaying emergency evacuation routes only
- Advertising security department job openings
- Reinforcing key security messages and maintaining awareness through constant visual reminders in the workplace (Correct answer)
- Replacing mandatory formal training requirements
Correct answer: Reinforcing key security messages and maintaining awareness through constant visual reminders in the workplace
Poster campaigns serve as low-cost, persistent reinforcement tools that keep security top-of-mind between formal training events.
Question 99: When integrating cybersecurity into a new industrial system design, the approach of building security in from the start rather than adding it later is known as:
- Security theater
- Compliance-driven patching
- Secure-by-design (or security-by-design) (Correct answer)
- Retrospective security hardening
Correct answer: Secure-by-design (or security-by-design)
Secure-by-design embeds security requirements into system architecture from the earliest design phase, reducing the cost and risk of retrofitting controls later.
Question 100: Mitigating an employee's financial vulnerability to espionage recruitment can BEST be accomplished by:
- Requiring employees to submit monthly financial statements
- Monitoring all personal bank accounts of cleared employees
- Providing access to financial counseling and encouraging early self-reporting of financial difficulties (Correct answer)
- Denying clearances to all employees with any debt
Correct answer: Providing access to financial counseling and encouraging early self-reporting of financial difficulties
Financial counseling and a non-punitive self-reporting culture reduce the exploitation window before a vulnerability becomes a national security risk.
Question 101: A classified contract is completed and the contractor retains classified materials. What should the FSO do?
- Archive the materials in a commercial off-site storage facility
- Return, transfer, or destroy the materials per the government contracting officer's instructions (Correct answer)
- Retain the materials indefinitely in case the contract is reopened
- Destroy the materials immediately without notification
Correct answer: Return, transfer, or destroy the materials per the government contracting officer's instructions
Upon contract completion, classified materials must be dispositioned (returned, transferred, or destroyed) in accordance with government direction, not retained by the contractor.
Question 102: A termination security briefing (debriefing) of a cleared employee should PRIMARILY cover:
- Continuing obligations to protect classified information and prohibited post-employment disclosures (Correct answer)
- Performance review documentation
- Future employment opportunities within the company
- Employee benefits continuation options (COBRA)
Correct answer: Continuing obligations to protect classified information and prohibited post-employment disclosures
Termination debriefings remind departing cleared employees that their security obligations do not end with employment and may be lifelong.
Question 103: What is the primary purpose of network segmentation in an industrial facility?
- To allow all devices to share a common IP address range
- To reduce the number of network switches required
- To limit the lateral movement of attackers and contain breaches to isolated network zones (Correct answer)
- To increase internet bandwidth for all users
Correct answer: To limit the lateral movement of attackers and contain breaches to isolated network zones
Network segmentation divides infrastructure into zones so a compromise in one area cannot easily spread to critical operational systems.
Question 104: Which security control prevents an employee from reading emails on a personally owned device not approved by the organization?
- Mobile Device Management (MDM) with a BYOD policy restriction (Correct answer)
- Data Loss Prevention (DLP)
- Physical security guards at the building entrance
- Antivirus software on company servers
Correct answer: Mobile Device Management (MDM) with a BYOD policy restriction
MDM combined with a BYOD policy can enforce that only managed, compliant devices can access corporate email and resources.
Question 105: Which law makes it a federal crime to knowingly and willfully misuse or disclose classified information without authorization?
- The Computer Fraud and Abuse Act (CFAA)
- The Trade Secrets Act (18 U.S.C. § 1905)
- 18 U.S.C. § 1030
- The Espionage Act (18 U.S.C. §§ 793-798) (Correct answer)
Correct answer: The Espionage Act (18 U.S.C. §§ 793-798)
The Espionage Act (18 U.S.C. §§ 793-798) is the primary federal statute criminalizing unauthorized disclosure of national defense information.
Question 106: Which federal standard or guideline is most commonly referenced for physical protection systems at US government contractor industrial facilities?
- EPA Risk Management Plan
- NISPOM (National Industrial Security Program Operating Manual) (Correct answer)
- NFPA 101 Life Safety Code
- OSHA 29 CFR 1910
Correct answer: NISPOM (National Industrial Security Program Operating Manual)
The NISPOM (DoD 5220.22-M / 32 CFR Part 117) governs physical and personnel security requirements for US government contractors handling classified information and materials.
Question 107: Why is access control important in facility security?
- To monitor employee attendance.
- To limit access to secure areas and protect sensitive information (Correct answer)
- To allow unrestricted access to all employees.
- To reduce security staff.
Correct answer: To limit access to secure areas and protect sensitive information
Access control systems are fundamental to facility security as they regulate who can enter specific areas and at what times. By restricting entry to only authorized personnel, these systems prevent unauthorized individuals from reaching sensitive information, critical infrastructure, or valuable assets. This is essential for maintaining security, confidentiality, and operational integrity.
Question 108: A security manager wants to assess whether employees understand how to report a suspicious contact. The BEST assessment method is:
- Asking employees informally in the hallway if they know the procedure
- Reviewing attendance records for the last security briefing
- A written multiple-choice test on reporting procedures
- A realistic scenario exercise requiring employees to demonstrate the actual reporting process (Correct answer)
Correct answer: A realistic scenario exercise requiring employees to demonstrate the actual reporting process
Practical performance assessments test whether employees can actually execute the reporting process, not just recall it on a test.
Question 109: Which of the following scenarios would MOST likely trigger a mandatory security policy review and update?
- A new federal regulation changing classified information handling requirements (Correct answer)
- A change in the facility's fire suppression system
- A change in the facility's commercial cleaning service contractor
- The annual rotation of security staff assigned to classified areas
Correct answer: A new federal regulation changing classified information handling requirements
New or revised federal regulations (such as NISPOM changes) directly impact legal compliance requirements and mandate corresponding updates to the facility's security policies.
Question 110: What is the legal consequence under 18 U.S.C. § 798 for knowingly and willfully communicating classified communications intelligence to an unauthorized person?
- Up to 10 years imprisonment and/or fines (Correct answer)
- Civil fines up to $50,000
- Mandatory enrollment in a security rehabilitation program
- Administrative suspension of clearance only
Correct answer: Up to 10 years imprisonment and/or fines
18 U.S.C. § 798 specifically protects classified communications intelligence (SIGINT/COMINT) and carries a penalty of up to 10 years imprisonment and fines.
Question 111: A phishing email that targets a specific senior executive is known as:
- Whaling (Correct answer)
- Vishing
- Spear phishing
- Smishing
Correct answer: Whaling
Whaling is a form of spear phishing specifically aimed at high-value targets such as executives or key decision-makers.
Question 112: Multi-factor authentication (MFA) requires users to verify identity using:
- Two different passwords
- At least two different authentication factors from separate categories (something you know, have, or are) (Correct answer)
- Biometrics only, without any secondary factor
- A password and a security question from the same category
Correct answer: At least two different authentication factors from separate categories (something you know, have, or are)
MFA combines factors from different categories—knowledge, possession, and inherence—to ensure one compromised factor does not grant access.
Question 113: What is the purpose of a security incident log?
- To track employee vacation schedules during incidents
- To create an auditable record of all events, actions taken, and decision points during an investigation (Correct answer)
- To publicly share breach information with competitors
- To replace the need for an incident response plan
Correct answer: To create an auditable record of all events, actions taken, and decision points during an investigation
Incident logs provide the documentary trail needed for post-incident review, legal proceedings, insurance claims, and regulatory reporting.
Question 114: How can technology support security risk management?
- By limiting access to sensitive areas.
- By focusing only on physical barriers.
- By reducing the number of security guards.
- By enhancing monitoring, detection, and response capabilities (Correct answer)
Correct answer: By enhancing monitoring, detection, and response capabilities
Technology provides advanced tools like surveillance systems, access control, intrusion detection, and cybersecurity software that significantly bolster security efforts. These technologies enable continuous monitoring, rapid detection of anomalies, and automated responses to potential threats. They extend the reach and effectiveness of human security personnel, creating a more robust defense.
Question 115: What is the primary goal of security risk management?
- To increase surveillance systems only.
- To protect assets, personnel, and information from potential risks (Correct answer)
- To reduce the number of security staff.
- To increase company profits.
Correct answer: To protect assets, personnel, and information from potential risks
Security risk management is a systematic process designed to identify, assess, and mitigate potential threats to an organization's valuable assets. Its core objective is to safeguard physical assets, ensure the safety of personnel, and protect sensitive information from various forms of harm, thereby maintaining operational continuity and integrity.
Question 116: Pre-employment polygraph examinations in the industrial security context are PRIMARILY used to:
- Provide legally admissible evidence in court
- Replace background investigations entirely
- Measure psychological fitness for high-stress roles
- Detect deception regarding undisclosed past activities relevant to suitability (Correct answer)
Correct answer: Detect deception regarding undisclosed past activities relevant to suitability
Polygraphs are used as an investigative tool to surface undisclosed information, not to replace full background checks or provide court evidence.
Question 117: A critical industrial facility learns that its SCADA software vendor will reach end-of-life (EOL) in six months with no patches thereafter. What is the MOST appropriate response?
- Immediately shut down all SCADA systems
- Continue operations with the EOL software and monitor for issues
- Request the vendor extend support indefinitely at no cost
- Develop a migration plan to supported software while implementing compensating controls during transition (Correct answer)
Correct answer: Develop a migration plan to supported software while implementing compensating controls during transition
A structured migration plan with compensating controls (such as enhanced monitoring and network segmentation) addresses the risk while maintaining operational continuity during the transition.
Question 118: A security director is asked to implement two-person integrity (TPI) for accessing a critical asset vault. TPI primarily protects against:
- Accidental equipment damage by a single worker
- Environmental hazards such as chemical spills
- External cyber intrusion into vault systems
- Insider threat and collusion by requiring two authorized people to be present simultaneously (Correct answer)
Correct answer: Insider threat and collusion by requiring two authorized people to be present simultaneously
Two-person integrity requires two authorized individuals to be present for access, preventing a single insider from acting alone and providing mutual oversight to deter insider threats.
Question 119: The 'lessons learned' phase of incident response primarily aims to:
- Notify external media about the security breach
- Identify what worked, what failed, and how to improve processes and controls to prevent recurrence (Correct answer)
- Archive the incident report and close the ticket permanently
- Assign blame and initiate disciplinary actions against responsible personnel
Correct answer: Identify what worked, what failed, and how to improve processes and controls to prevent recurrence
Lessons learned transform incident experience into measurable improvements in security posture, policy, and training.
Question 120: A hazardous material release at an industrial site triggers shelter-in-place orders. Which action should be taken FIRST?
- Call local fire department before taking any protective action
- Evacuate all personnel immediately through the main gate
- Distribute personal protective equipment to all employees
- Seal air intakes and move personnel to interior rooms (Correct answer)
Correct answer: Seal air intakes and move personnel to interior rooms
Shelter-in-place requires immediately sealing ventilation pathways and moving personnel to protected interior areas before any outward-facing actions.
Question 121: In the ASIS Risk Analysis framework, what does the term 'vulnerability' specifically refer to?
- A weakness that could be exploited by a threat (Correct answer)
- The potential loss resulting from an incident
- The cost of implementing countermeasures
- The likelihood that a threat will occur
Correct answer: A weakness that could be exploited by a threat
A vulnerability is a weakness or gap in a security system that a threat agent can exploit to cause harm.
Question 122: Which behavioral indicator is most commonly associated with a potential malicious insider?
- Requesting additional training on new equipment
- Unexplained affluence inconsistent with salary (Correct answer)
- Taking vacation shortly after a performance review
- Working overtime during a major project
Correct answer: Unexplained affluence inconsistent with salary
Unexplained wealth that cannot be reconciled with an employee's known salary is a classic red flag for theft or espionage.
Question 123: When conducting a physical security survey, the recommended technique for testing door frame integrity is:
- Checking the lock cylinder for corrosion
- Measuring the door width against fire code minimums
- Applying lateral pressure to assess flex and gap between door and frame (Correct answer)
- Reviewing the manufacturer's specification sheet only
Correct answer: Applying lateral pressure to assess flex and gap between door and frame
Physically testing door and frame flex reveals whether the assembly can be forced open by leveraging the gap, which may not be apparent from specifications or visual inspection alone.
Question 124: When an industrial security professional recommends 'defense in depth,' they are advocating for:
- Installing the deepest underground vault available for asset storage
- Layering multiple independent security controls so that failure of one does not compromise overall security (Correct answer)
- Concentrating all security resources at the outer perimeter
- Prioritizing cyber defenses over physical security measures
Correct answer: Layering multiple independent security controls so that failure of one does not compromise overall security
Defense in depth uses multiple overlapping layers of security controls so that an attacker must defeat several independent barriers to reach a target.
Question 125: Which security vetting tool requires the subject to disclose foreign contacts, travel, and financial information?
- IRS Form W-4
- Standard Form 86 (Questionnaire for National Security Positions) (Correct answer)
- Form I-9 (Employment Eligibility Verification)
- OSHA 300 Log
Correct answer: Standard Form 86 (Questionnaire for National Security Positions)
SF-86 is the U.S. government form used to collect the personal history needed to conduct a national security background investigation.
Question 126: How can businesses prepare for potential crises?
- By focusing on reactive responses only.
- By developing preparedness plans and training staff (Correct answer)
- By reducing the number of employees.
- By ignoring potential risks.
Correct answer: By developing preparedness plans and training staff
Proactive preparation is key to effective crisis management, enabling a rapid and organized response when a crisis inevitably occurs. This involves identifying potential risks, creating detailed crisis plans, and regularly training employees on their roles and responsibilities during an emergency. Such preparedness minimizes confusion, reduces damage, and facilitates a quicker recovery.
Question 127: A security investigator discovers a suspicious USB drive in a secured area. The FIRST action should be:
- Hand it to the nearest employee to identify the owner
- Plug it into a computer to identify its contents
- Photograph it in place, document its location, and secure it as evidence without inserting it into any system (Correct answer)
- Discard it to prevent further risk to the facility
Correct answer: Photograph it in place, document its location, and secure it as evidence without inserting it into any system
Documenting and preserving the device without connecting it protects both evidence integrity and facility systems from potential malware.
Question 128: An Initial Security Briefing for a newly cleared employee should ALWAYS cover:
- IT helpdesk contact information and printer setup
- Responsibilities, classification levels, reporting requirements, and the consequences of security violations (Correct answer)
- Company financial performance and stock options
- Benefits enrollment and vacation accrual policies
Correct answer: Responsibilities, classification levels, reporting requirements, and the consequences of security violations
Initial briefings establish the employee's foundational security responsibilities and set expectations for behavior from day one.
Question 129: During a facility security survey, a consultant recommends 'natural surveillance.' This refers to:
- Deploying undercover guards dressed as workers
- Positioning windows, lighting, and landscaping so legitimate users can observe activity (Correct answer)
- Using wildlife cameras to monitor perimeter areas
- Installing hidden cameras in natural-looking housings
Correct answer: Positioning windows, lighting, and landscaping so legitimate users can observe activity
Natural surveillance maximizes visibility of people and spaces through thoughtful design of windows, open sightlines, and lighting so occupants and passersby deter crime.
Question 130: What distinguishes a 'passive' infrared (PIR) motion detector from an 'active' infrared detector in industrial perimeter protection?
- PIR emits a microwave signal; active IR uses sound waves
- PIR detects changes in heat signatures; active IR uses a beam that triggers an alarm when broken (Correct answer)
- PIR works only indoors; active IR works only outdoors
- PIR requires a power source; active IR is battery-free
Correct answer: PIR detects changes in heat signatures; active IR uses a beam that triggers an alarm when broken
PIR sensors detect changes in infrared (heat) energy from moving objects, while active IR systems emit a beam and trigger an alarm when that beam is interrupted.
Question 131: What is the purpose of a security clearance adjudication?
- To assign an employee's access level based solely on job title
- To terminate employees who fail polygraph examinations
- To determine whether granting access is clearly consistent with national or industrial security interests (Correct answer)
- To issue an employee identification badge
Correct answer: To determine whether granting access is clearly consistent with national or industrial security interests
Adjudication evaluates all available information to decide if an individual's access is consistent with security interests.
Question 132: Which framework is widely used in U.S. industrial environments to manage cybersecurity risk?
- ASIS SPC.1
- OSHA 29 CFR 1910
- ISO 45001
- NIST Cybersecurity Framework (CSF) (Correct answer)
Correct answer: NIST Cybersecurity Framework (CSF)
The NIST CSF provides a structured approach to identifying, protecting, detecting, responding to, and recovering from cybersecurity incidents.
Question 133: Which federal law establishes the baseline requirements for protecting classified national security information in industry?
- Occupational Safety and Health Act (OSHA)
- Sarbanes-Oxley Act (SOX)
- National Industrial Security Program Operating Manual (NISPOM) (Correct answer)
- Freedom of Information Act (FOIA)
Correct answer: National Industrial Security Program Operating Manual (NISPOM)
The NISPOM (32 CFR Part 117) is the primary federal regulation governing the protection of classified information in the defense industrial base.
Question 134: Which artifact is MOST useful in reconstructing the timeline of a cyber incident on a Windows system?
- Desktop wallpaper settings
- Browser bookmarks folder
- Printer queue history
- Windows Event Logs (Security, System, Application) (Correct answer)
Correct answer: Windows Event Logs (Security, System, Application)
Windows Event Logs record system events with timestamps, providing the chronological record investigators need to reconstruct an incident.
Question 135: Which evidence type has the HIGHEST evidentiary value in a digital security investigation?
- Handwritten notes from the investigating officer
- Eyewitness testimony from coworkers
- Forensically verified, bit-for-bit image of the original storage media with verified hash values (Correct answer)
- Printed screenshots taken from a live system
Correct answer: Forensically verified, bit-for-bit image of the original storage media with verified hash values
A forensic image with cryptographic hash verification proves the copy is identical to the original, giving it strong evidentiary weight.
Question 136: When must a security incident be reported to the relevant government authority in a cleared industrial facility?
- Only after a full internal investigation is complete
- Whenever a reportable security incident occurs, per the facility's reporting requirements and DD Form 577 obligations (Correct answer)
- Only if classified information was confirmed as compromised
- Never—all incidents are handled internally without government notification
Correct answer: Whenever a reportable security incident occurs, per the facility's reporting requirements and DD Form 577 obligations
Government-cleared facilities are obligated to report security incidents to their Cognizant Security Agency (CSA) as specified in their facility clearance agreement.
Question 137: What is the purpose of maintaining an approved vendor list (AVL) in an industrial security program?
- To restrict procurement to suppliers who have been vetted and approved based on security and quality criteria (Correct answer)
- To track vendor invoice payment status
- To identify vendors eligible for volume discounts
- To publicly disclose all vendors for transparency
Correct answer: To restrict procurement to suppliers who have been vetted and approved based on security and quality criteria
An AVL limits procurement to pre-vetted suppliers, reducing the risk of introducing unvetted or compromised components into the supply chain.
Question 138: During a declared emergency at an industrial facility, mutual aid agreements with neighboring facilities and local agencies are MOST valuable because they:
- Transfer legal liability to the assisting organization
- Eliminate the need for the facility's own emergency plan
- Provide pre-authorized access to additional resources when internal capacity is exceeded (Correct answer)
- Satisfy regulatory requirements without additional planning
Correct answer: Provide pre-authorized access to additional resources when internal capacity is exceeded
Mutual aid agreements pre-authorize resource sharing—personnel, equipment, supplies—ensuring help is available quickly when the facility's own capacity is overwhelmed.
Question 139: Which perimeter barrier type provides the HIGHEST level of vehicle impact resistance for industrial facilities?
- Anti-ram bollards rated to K12 standard (Correct answer)
- Wooden post-and-rail fence
- Concrete jersey barriers
- Chain-link fence with barbed wire
Correct answer: Anti-ram bollards rated to K12 standard
K12-rated anti-ram bollards are engineered to stop a 15,000-lb vehicle traveling at 50 mph, providing the highest certified vehicle impact resistance.
Question 140: Which document formally authorizes a system to operate by accepting identified residual risks?
- Incident Response Plan (IRP)
- Business Continuity Plan (BCP)
- Authority to Operate (ATO) (Correct answer)
- System Security Plan (SSP)
Correct answer: Authority to Operate (ATO)
An ATO is an official management decision that a system's risk level is acceptable and it is authorized for operation.
Question 141: What is the purpose of a Security Classification Guide (SCG) in a classified program?
- To document the physical security measures required at the contractor's facility
- To serve as a master list of all cleared employees on a classified contract
- To authorize contractor employees to self-classify their own work products
- To provide specific guidance on what information within a program is classified and at what level (Correct answer)
Correct answer: To provide specific guidance on what information within a program is classified and at what level
An SCG is a government-issued document that tells contractors exactly which elements of a specific program are classified, at what level, and why.
Question 142: In a cleared facility, a 'security violation' is BEST defined as:
- Only intentional acts of espionage by cleared personnel
- A fire code infraction discovered during an audit
- Any act or omission that is contrary to established security regulations, regardless of intent (Correct answer)
- Any action that results in employee injury on the job
Correct answer: Any act or omission that is contrary to established security regulations, regardless of intent
Security violations include both deliberate and negligent breaches of security requirements and must be reported regardless of intent.
Question 143: A security patch management program is PRIMARILY intended to:
- Automate system backups on a scheduled basis
- Track employee software license compliance
- Remediate known software vulnerabilities before they can be exploited (Correct answer)
- Improve application performance and add new features
Correct answer: Remediate known software vulnerabilities before they can be exploited
Patch management ensures vulnerabilities identified in software are addressed in a timely manner to reduce the attack surface.
Question 144: In an industrial security context, 'data at rest' refers to:
- Information actively being transmitted across a network
- Information verbally communicated between employees
- Stored data on drives, servers, or removable media not currently in transit (Correct answer)
- Data displayed on a monitor during active use
Correct answer: Stored data on drives, servers, or removable media not currently in transit
Data at rest encompasses all stored information that is not actively moving through a network or being processed.
Question 145: An insider threat is BEST defined as a risk posed by which of the following?
- Current or former employees, contractors, or partners who misuse authorized access (Correct answer)
- Vendors who deliver supplies to the facility
- External hackers who gain physical access
- Foreign intelligence agents who never entered the facility
Correct answer: Current or former employees, contractors, or partners who misuse authorized access
Insider threats originate from individuals who already have or recently had authorized access and can abuse that trust.
Question 146: Which industrial control system (ICS) protocol is most commonly targeted by adversaries due to its lack of built-in authentication?
- HTTPS
- TLS 1.3
- Modbus (Correct answer)
- SSH
Correct answer: Modbus
Modbus was designed for reliability in isolated networks and lacks authentication, making it vulnerable when exposed to broader networks.
Question 147: Which type of malware is specifically designed to remain hidden while granting an attacker persistent, privileged access to a system?
- Ransomware
- Worm
- Rootkit (Correct answer)
- Adware
Correct answer: Rootkit
Rootkits are designed to hide their presence and provide an attacker with sustained administrative access to a compromised system.
Question 148: During a security assessment, an evaluator finds that employee security training was last conducted 18 months ago. This gap is best categorized as which type of vulnerability?
- Administrative or procedural vulnerability (Correct answer)
- Physical vulnerability
- Environmental vulnerability
- Technical vulnerability
Correct answer: Administrative or procedural vulnerability
A lapse in required security training reflects a weakness in administrative or procedural controls, which govern human behavior and compliance.
Question 149: When a vendor's security certification (e.g., ISO 27001) expires without renewal, what should an industrial security professional do?
- Continue using the vendor with no action until the next scheduled review
- Immediately terminate the vendor relationship
- Initiate a re-evaluation of the vendor's security posture and request remediation or updated certification (Correct answer)
- Automatically assume the vendor remains compliant based on past performance
Correct answer: Initiate a re-evaluation of the vendor's security posture and request remediation or updated certification
An expired certification means the vendor's controls have not been independently verified recently; re-evaluation ensures the vendor still meets required security standards before continuing the relationship.
Question 150: How do physical barriers contribute to facility protection?
- By improving facility aesthetics.
- By reducing employee productivity.
- By increasing the amount of security staff.
- By blocking unauthorized access to sensitive areas (Correct answer)
Correct answer: By blocking unauthorized access to sensitive areas
Physical barriers, such as fences, walls, gates, and reinforced doors, create tangible obstacles to entry. They are specifically designed to delay, deter, or prevent unauthorized individuals from gaining access to a facility or specific secure zones within it. These barriers form a crucial first line of defense in a layered security strategy.
Question 151: A 'DMZ' (Demilitarized Zone) between IT and OT networks is PRIMARILY designed to:
- Allow unrestricted internet access to control systems for remote monitoring
- Increase data transfer speeds between enterprise and control networks
- Provide a controlled buffer zone where data can be exchanged between IT and OT without direct connectivity (Correct answer)
- Replace the need for firewalls in industrial environments
Correct answer: Provide a controlled buffer zone where data can be exchanged between IT and OT without direct connectivity
An OT DMZ allows necessary data flows between IT and OT while preventing direct connectivity that could enable lateral movement of attackers.
Industrial Security Professional (ISP) Certification Exam
The ISP certification validates an individual's expertise in industrial security practices, demonstrating a comprehensive understanding of security principles, regulations, and risk management within industrial environments.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds