Industrial Security Professional (ISP) Certification Exam — Questions and Answers
Question 1: A security manager discovers that a fence line runs within 10 feet of a critical building wall. What is the PRIMARY concern?
- The fence material may corrode near the building
- Emergency responders cannot access the building
- Insufficient lighting between the fence and wall
- The standoff distance is too small to detect intruders or stop vehicle attacks (Correct answer)
Correct answer: The standoff distance is too small to detect intruders or stop vehicle attacks
Inadequate standoff distance reduces response time and may allow a vehicle or individual breaching the perimeter to immediately reach the critical structure.
Question 2: What is the first step in the security risk management process?
- Monitor security systems.
- Implement risk mitigation measures.
- Install additional surveillance equipment.
- Identify and assess risks (Correct answer)
Correct answer: Identify and assess risks
The foundational step in any security risk management process is to thoroughly identify all potential threats and vulnerabilities that could impact an organization's assets. This involves understanding what could go wrong, how likely it is to happen, and what the potential consequences would be. Without this initial assessment, effective mitigation strategies cannot be developed.
Question 3: How can perimeter security help protect a facility?
- By increasing the number of security guards.
- By increasing facility use for non-security purposes.
- By blocking unauthorized access and enhancing protection (Correct answer)
- By reducing security surveillance.
Correct answer: By blocking unauthorized access and enhancing protection
Perimeter security establishes a clear boundary around a facility, acting as the first line of defense against external threats. Elements like fences, gates, and intrusion detection systems are designed to detect, deter, and delay unauthorized entry. This helps to control access to the entire property and provides early warning of potential security breaches.
Question 4: Which phase of an incident response plan involves returning systems to normal operations after a security event?
- Identification
- Recovery (Correct answer)
- Lessons Learned
- Containment
Correct answer: Recovery
The recovery phase restores affected systems and verifies they are clean and functional before returning them to production.
Question 5: An industrial facility's Emergency Operations Center (EOC) differs from the on-scene command post in that the EOC:
- Is responsible solely for public affairs and media management
- Is located at the point of the incident for direct oversight
- Provides strategic coordination and resource support removed from the hazard area (Correct answer)
- Replaces the Incident Commander's authority during the crisis
Correct answer: Provides strategic coordination and resource support removed from the hazard area
The EOC operates at the strategic level, coordinating logistics, policy decisions, and multi-agency support while the command post handles on-scene tactical operations.
Question 6: An OT security program should include an industrial asset inventory because:
- Asset inventories are only needed for IT systems, not OT/ICS
- It is required only for financial depreciation accounting purposes
- Inventories are only required when preparing for a regulatory audit
- You cannot protect what you do not know exists—a complete asset inventory is the foundation of any OT security program (Correct answer)
Correct answer: You cannot protect what you do not know exists—a complete asset inventory is the foundation of any OT security program
Without a comprehensive asset inventory, organizations cannot assess exposure, prioritize patching, or detect unauthorized devices on OT networks.
Question 7: Which background investigation element is MOST critical when determining suitability for a sensitive industrial position?
- Criminal record check
- Employment verification
- All of the above combined (Correct answer)
- Credit history review
Correct answer: All of the above combined
A comprehensive personnel security determination requires combining criminal, credit, and employment checks rather than relying on any single element.
Question 8: When a crisis communication plan is activated, the designated spokesperson should:
- Decline all media contact until the incident is fully resolved
- Provide only confirmed facts and bridge to key messages (Correct answer)
- Speculate on causes to appear knowledgeable to the press
- Allow multiple executives to speak independently to different outlets
Correct answer: Provide only confirmed facts and bridge to key messages
Spokespeople must stick to confirmed facts, avoid speculation, and use message bridging techniques to maintain control and credibility during crisis communications.
Question 9: The 'scalability' principle in emergency response planning means that the response system should:
- Always activate all emergency teams when any incident occurs
- Expand or contract to match the complexity and size of the incident (Correct answer)
- Scale down operations after the first 24 hours automatically
- Use the maximum resources available regardless of incident size
Correct answer: Expand or contract to match the complexity and size of the incident
Scalable response ensures resources are matched to incident needs, preventing both under-response to serious events and costly over-response to minor ones.
Question 10: Encryption of data in transit is BEST enforced in an industrial network by requiring:
- Verbal communication only for classified operational data
- Physical mail delivery for sensitive documents
- All communications to use plaintext for troubleshooting visibility
- Transport Layer Security (TLS) or equivalent cryptographic protocols on all network channels (Correct answer)
Correct answer: Transport Layer Security (TLS) or equivalent cryptographic protocols on all network channels
TLS ensures data integrity and confidentiality while in transit across networks that may traverse untrusted segments.
Question 11: What is the PRIMARY purpose of establishing a security baseline for an industrial facility?
- To satisfy regulatory audit requirements without incurring additional cost
- To document all past security incidents for insurance claims
- To define a minimum standard of security from which deviations can be measured and addressed (Correct answer)
- To create a marketing document demonstrating security investment to clients
Correct answer: To define a minimum standard of security from which deviations can be measured and addressed
A security baseline establishes the minimum acceptable security posture, enabling management to identify gaps and prioritize improvements.
Question 12: Which federal guideline governs adjudicative standards for personnel security clearances in U.S. industrial environments?
- The 13 Adjudicative Guidelines (Security Executive Agent Directive 4) (Correct answer)
- ISO 27001 Annex A
- NIST SP 800-53
- Title 18 U.S. Code Section 1030
Correct answer: The 13 Adjudicative Guidelines (Security Executive Agent Directive 4)
SEAD 4 establishes the 13 Adjudicative Guidelines used to evaluate individuals for U.S. government-related security clearances.
Question 13: What distinguishes a 'passive' infrared (PIR) motion detector from an 'active' infrared detector in industrial perimeter protection?
- PIR works only indoors; active IR works only outdoors
- PIR requires a power source; active IR is battery-free
- PIR emits a microwave signal; active IR uses sound waves
- PIR detects changes in heat signatures; active IR uses a beam that triggers an alarm when broken (Correct answer)
Correct answer: PIR detects changes in heat signatures; active IR uses a beam that triggers an alarm when broken
PIR sensors detect changes in infrared (heat) energy from moving objects, while active IR systems emit a beam and trigger an alarm when that beam is interrupted.
Question 14: Which type of insider threat actor is typically motivated by ideology rather than financial gain?
- The ideological spy acting on behalf of a cause or foreign entity (Correct answer)
- The opportunistic thief stealing for personal enrichment
- The careless employee who accidentally leaks information
- The disgruntled employee seeking revenge
Correct answer: The ideological spy acting on behalf of a cause or foreign entity
Ideological insiders are motivated by beliefs or loyalty to a cause, making them distinct from financially motivated or careless actors.
Question 15: Which framework is widely used in U.S. industrial environments to manage cybersecurity risk?
- NIST Cybersecurity Framework (CSF) (Correct answer)
- OSHA 29 CFR 1910
- ASIS SPC.1
- ISO 45001
Correct answer: NIST Cybersecurity Framework (CSF)
The NIST CSF provides a structured approach to identifying, protecting, detecting, responding to, and recovering from cybersecurity incidents.
Question 16: Which program element is essential to a robust Insider Threat Program (InTP)?
- Installing covert recording devices in break rooms
- Reporting all suspicious behavior directly to law enforcement without internal review
- Establishing a multidisciplinary hub that integrates HR, IT, security, and legal data (Correct answer)
- Reviewing only IT access logs on an annual basis
Correct answer: Establishing a multidisciplinary hub that integrates HR, IT, security, and legal data
An effective InTP requires a cross-functional team that combines data from multiple departments to detect and deter insider threats.
Question 17: Which of the following best describes 'two-person integrity' (TPI) as applied in industrial security?
- Requiring dual-factor authentication for all classified computer systems
- Requiring two FSOs to sign off on all security policies
- Mandating that all classified documents be reviewed by two government officials before release
- Ensuring no single person has unsupervised access to certain sensitive materials or areas (Correct answer)
Correct answer: Ensuring no single person has unsupervised access to certain sensitive materials or areas
Two-person integrity requires at least two authorized, cleared individuals to be present when handling certain sensitive materials to prevent insider threats.
Question 18: Which federal standard or guideline is most commonly referenced for physical protection systems at US government contractor industrial facilities?
- EPA Risk Management Plan
- NFPA 101 Life Safety Code
- OSHA 29 CFR 1910
- NISPOM (National Industrial Security Program Operating Manual) (Correct answer)
Correct answer: NISPOM (National Industrial Security Program Operating Manual)
The NISPOM (DoD 5220.22-M / 32 CFR Part 117) governs physical and personnel security requirements for US government contractors handling classified information and materials.
Question 19: An ISP candidate is reviewing access control lists. Who is responsible for defining WHAT resources a user may access in a role-based access control (RBAC) system?
- The system administrator acting as the data owner's proxy
- The data/resource owner or asset custodian (Correct answer)
- The third-party security vendor
- The end user based on their preference
Correct answer: The data/resource owner or asset custodian
In RBAC, the data owner or asset custodian determines access rights; administrators implement those rights in the system, but ownership of the decision rests with the resource owner.
Question 20: Which document formally communicates the findings of a security risk assessment to organizational leadership and recommends prioritized corrective actions?
- Incident action plan
- Emergency operations plan
- Security risk assessment report (Correct answer)
- Standard operating procedure
Correct answer: Security risk assessment report
A security risk assessment report presents identified risks, their evaluation, and prioritized recommendations to inform decision-makers on resource allocation.
Question 21: In an industrial security context, 'data at rest' refers to:
- Stored data on drives, servers, or removable media not currently in transit (Correct answer)
- Data displayed on a monitor during active use
- Information verbally communicated between employees
- Information actively being transmitted across a network
Correct answer: Stored data on drives, servers, or removable media not currently in transit
Data at rest encompasses all stored information that is not actively moving through a network or being processed.
Question 22: A critical industrial facility learns that its SCADA software vendor will reach end-of-life (EOL) in six months with no patches thereafter. What is the MOST appropriate response?
- Continue operations with the EOL software and monitor for issues
- Develop a migration plan to supported software while implementing compensating controls during transition (Correct answer)
- Immediately shut down all SCADA systems
- Request the vendor extend support indefinitely at no cost
Correct answer: Develop a migration plan to supported software while implementing compensating controls during transition
A structured migration plan with compensating controls (such as enhanced monitoring and network segmentation) addresses the risk while maintaining operational continuity during the transition.
Question 23: Which evidence type has the HIGHEST evidentiary value in a digital security investigation?
- Handwritten notes from the investigating officer
- Forensically verified, bit-for-bit image of the original storage media with verified hash values (Correct answer)
- Eyewitness testimony from coworkers
- Printed screenshots taken from a live system
Correct answer: Forensically verified, bit-for-bit image of the original storage media with verified hash values
A forensic image with cryptographic hash verification proves the copy is identical to the original, giving it strong evidentiary weight.
Question 24: What is the primary purpose of network segmentation in an industrial facility?
- To increase internet bandwidth for all users
- To reduce the number of network switches required
- To limit the lateral movement of attackers and contain breaches to isolated network zones (Correct answer)
- To allow all devices to share a common IP address range
Correct answer: To limit the lateral movement of attackers and contain breaches to isolated network zones
Network segmentation divides infrastructure into zones so a compromise in one area cannot easily spread to critical operational systems.
Question 25: Which type of glass is MOST appropriate for an industrial facility's entry lobby where forced-entry resistance is required?
- Tinted UV-protective glass
- Tempered glass
- Standard float glass
- Laminated security glass with polycarbonate interlayer (Correct answer)
Correct answer: Laminated security glass with polycarbonate interlayer
Laminated security glass bonds multiple layers with a polycarbonate or PVB interlayer that holds shards together under impact, resisting forced entry far longer than tempered or float glass.
Question 26: The primary difference between 'crisis management' and 'consequence management' in industrial security is:
- Crisis management focuses on resolving the immediate threat; consequence management mitigates the effects (Correct answer)
- There is no meaningful distinction between the two terms
- Crisis management is performed by private security; consequence management by government agencies only
- Crisis management addresses root causes; consequence management handles legal liability
Correct answer: Crisis management focuses on resolving the immediate threat; consequence management mitigates the effects
Crisis management resolves the immediate emergency event while consequence management addresses the downstream effects on people, environment, and operations.
Question 27: Mitigating an employee's financial vulnerability to espionage recruitment can BEST be accomplished by:
- Monitoring all personal bank accounts of cleared employees
- Denying clearances to all employees with any debt
- Providing access to financial counseling and encouraging early self-reporting of financial difficulties (Correct answer)
- Requiring employees to submit monthly financial statements
Correct answer: Providing access to financial counseling and encouraging early self-reporting of financial difficulties
Financial counseling and a non-punitive self-reporting culture reduce the exploitation window before a vulnerability becomes a national security risk.
Question 28: A 'continuous evaluation' program in personnel security is designed to:
- Monitor cleared individuals for concerning behaviors between periodic reinvestigations (Correct answer)
- Replace the initial security clearance investigation
- Evaluate employee performance on a monthly basis
- Conduct a new full background investigation every five years
Correct answer: Monitor cleared individuals for concerning behaviors between periodic reinvestigations
Continuous evaluation uses automated record checks to flag relevant derogatory information between reinvestigations without waiting for a scheduled review.
Question 29: How does a security audit contribute to risk management?
- By identifying vulnerabilities and improving security practices (Correct answer)
- By delaying risk management actions.
- By focusing only on technical systems.
- By increasing the number of employees involved.
Correct answer: By identifying vulnerabilities and improving security practices
A security audit systematically evaluates an organization's security posture, identifying weaknesses and vulnerabilities in its systems and processes. By pinpointing these gaps, the organization can implement targeted improvements and strengthen its defenses. This proactive identification and remediation of flaws are crucial for effective risk management, reducing the likelihood and impact of potential security incidents.
Question 30: What does 'two-person integrity' (TPI) primarily protect against in a personnel security context?
- A single insider acting alone to commit theft or sabotage of critical assets (Correct answer)
- Physical injuries during heavy-lifting tasks
- Cyber intrusions from external threat actors
- Unauthorized photography on the production floor
Correct answer: A single insider acting alone to commit theft or sabotage of critical assets
TPI requires two authorized individuals to be present during access to sensitive areas or materials, preventing unilateral insider action.
Question 31: Why is post-crisis evaluation important?
- To focus only on financial recovery.
- To avoid repeating mistakes in future crises (Correct answer)
- To ignore lessons learned.
- To reduce the number of employees.
Correct answer: To avoid repeating mistakes in future crises
Post-crisis evaluation is crucial for organizational learning and resilience. By thoroughly reviewing the crisis response, organizations can identify what worked well and, more importantly, what went wrong. This analysis allows them to implement corrective actions, refine their crisis management plans, and develop better strategies to prevent or more effectively handle similar incidents in the future, ultimately avoiding the repetition of mistakes.
Question 32: When an employee is terminated, which security action should be taken IMMEDIATELY?
- Waiting for HR to file paperwork before notifying IT
- Revoking all logical and physical access simultaneously upon departure (Correct answer)
- Allowing the employee to retain email access to complete handover
- Scheduling a 30-day transition period before revoking access
Correct answer: Revoking all logical and physical access simultaneously upon departure
Simultaneous revocation of all access upon termination prevents a departing employee from exfiltrating data or entering the facility.
Question 33: Which of the following is a key component of a Supply Chain Risk Management (SCRM) plan?
- Identification of critical suppliers, risk assessment criteria, mitigation strategies, and incident response procedures (Correct answer)
- A single point of contact for all procurement activities
- An annual review of vendor marketing materials
- A list of preferred vendors sorted by lowest price
Correct answer: Identification of critical suppliers, risk assessment criteria, mitigation strategies, and incident response procedures
A comprehensive SCRM plan must identify critical suppliers, define how risks are assessed, specify mitigation strategies, and establish how supply chain incidents will be handled.
Question 34: Which perimeter barrier type provides the HIGHEST level of vehicle impact resistance for industrial facilities?
- Anti-ram bollards rated to K12 standard (Correct answer)
- Wooden post-and-rail fence
- Chain-link fence with barbed wire
- Concrete jersey barriers
Correct answer: Anti-ram bollards rated to K12 standard
K12-rated anti-ram bollards are engineered to stop a 15,000-lb vehicle traveling at 50 mph, providing the highest certified vehicle impact resistance.
Question 35: What is the purpose of a security risk assessment in facility protection?
- To reduce the number of employees.
- To identify potential security risks and inform protection strategies (Correct answer)
- To increase the amount of physical security systems.
- To monitor employee attendance.
Correct answer: To identify potential security risks and inform protection strategies
A security risk assessment systematically identifies potential threats, vulnerabilities, and the likelihood and impact of security incidents. By understanding these risks, organizations can prioritize and implement appropriate security measures and allocate resources effectively. This ensures that protection strategies are informed, effective, and tailored to the specific risks faced by the facility.
Question 36: Which category of emergency notification system is MOST critical for alerting off-site communities to an industrial chemical release?
- Internal PA system announcement
- Posted notices at facility entrances
- Employee text message trees
- Outdoor warning sirens combined with Emergency Alert System broadcasts (Correct answer)
Correct answer: Outdoor warning sirens combined with Emergency Alert System broadcasts
Outdoor warning sirens combined with EAS broadcasts reach the surrounding community rapidly regardless of whether residents are indoors or monitoring media.
Question 37: Which of the following is the BEST method for evaluating a new vendor's security posture before awarding a contract?
- Checking the vendor's social media presence
- Relying solely on the vendor's self-reported compliance status
- Conducting a third-party security audit or requiring completion of a standardized security questionnaire (Correct answer)
- Reviewing the vendor's marketing materials and website
Correct answer: Conducting a third-party security audit or requiring completion of a standardized security questionnaire
Third-party audits or standardized questionnaires (such as NIST SP 800-161 aligned assessments) provide objective, verifiable evidence of a vendor's security controls.
Question 38: The 'hot zone' in an industrial emergency is best described as:
- The area designated for media briefings
- The immediately dangerous area requiring highest-level PPE (Correct answer)
- The zone where medical triage occurs
- The perimeter boundary for public exclusion
Correct answer: The immediately dangerous area requiring highest-level PPE
The hot zone is the area of highest contamination or danger where only fully protected responders may operate.
Question 39: Which risk management standard published by ASIS International provides comprehensive guidance specifically for organizational resilience and security management?
- ISO 27001
- ASIS SPC.1-2009 (Correct answer)
- DHS CFATS
- NFPA 730
Correct answer: ASIS SPC.1-2009
ASIS SPC.1-2009 (Organizational Resilience Standard) provides a framework for security, preparedness, and continuity management aligned with ASIS professional practice.
Question 40: Which of the following risk communication techniques is most effective when presenting risk findings to senior executives who have limited time?
- Sending a detailed narrative report with all threat actor profiles
- Delivering a risk heat map with prioritized findings and recommended actions (Correct answer)
- Providing a full technical appendix with all raw assessment data
- Presenting fault tree diagrams for each identified scenario
Correct answer: Delivering a risk heat map with prioritized findings and recommended actions
A risk heat map provides a concise visual summary of risk ratings and priorities, enabling executives to quickly grasp severity and make resource decisions.
Question 41: Multi-factor authentication (MFA) requires users to verify identity using:
- Two different passwords
- Biometrics only, without any secondary factor
- A password and a security question from the same category
- At least two different authentication factors from separate categories (something you know, have, or are) (Correct answer)
Correct answer: At least two different authentication factors from separate categories (something you know, have, or are)
MFA combines factors from different categories—knowledge, possession, and inherence—to ensure one compromised factor does not grant access.
Question 42: A facility security officer (FSO) must ensure visitor escort procedures are followed. What is the MINIMUM requirement for escorting an uncleared visitor in a controlled industrial area?
- Two uncleared visitors may escort each other
- The visitor must sign a non-disclosure agreement only
- Visitors must wear a distinctive badge but may move freely
- A cleared, authorized employee must accompany the visitor at all times within the controlled area (Correct answer)
Correct answer: A cleared, authorized employee must accompany the visitor at all times within the controlled area
Cleared, authorized personnel must escort uncleared visitors continuously within controlled or restricted areas to prevent unauthorized access to sensitive information or assets.
Question 43: Which of the following is a unique security challenge in Operational Technology (OT) environments compared to IT?
- Many OT devices have 20-30 year lifecycles and cannot accept security patches without disrupting operations (Correct answer)
- OT systems have stronger built-in authentication than IT systems
- OT systems are updated more frequently than IT systems
- OT environments have smaller attack surfaces than enterprise IT networks
Correct answer: Many OT devices have 20-30 year lifecycles and cannot accept security patches without disrupting operations
Legacy OT devices were designed for longevity and reliability, not security, making patching difficult or impossible without operational impact.
Question 44: In the context of industrial crisis management, 'continuity of operations' (COOP) planning addresses which core concern?
- Training employees on evacuation procedures
- Sustaining essential functions when primary facilities or systems are unavailable (Correct answer)
- Documenting losses for insurance reimbursement
- Maintaining profitability during normal operations
Correct answer: Sustaining essential functions when primary facilities or systems are unavailable
COOP planning ensures that critical operations continue or resume rapidly when normal infrastructure is disrupted by identifying alternate sites, personnel, and resources.
Question 45: A security director is asked to implement two-person integrity (TPI) for accessing a critical asset vault. TPI primarily protects against:
- Accidental equipment damage by a single worker
- Insider threat and collusion by requiring two authorized people to be present simultaneously (Correct answer)
- External cyber intrusion into vault systems
- Environmental hazards such as chemical spills
Correct answer: Insider threat and collusion by requiring two authorized people to be present simultaneously
Two-person integrity requires two authorized individuals to be present for access, preventing a single insider from acting alone and providing mutual oversight to deter insider threats.
Question 46: Which artifact is MOST useful in reconstructing the timeline of a cyber incident on a Windows system?
- Desktop wallpaper settings
- Windows Event Logs (Security, System, Application) (Correct answer)
- Printer queue history
- Browser bookmarks folder
Correct answer: Windows Event Logs (Security, System, Application)
Windows Event Logs record system events with timestamps, providing the chronological record investigators need to reconstruct an incident.
Question 47: An ISP candidate is conducting a Business Impact Analysis (BIA). The PRIMARY purpose of this analysis is to:
- Rank physical security countermeasures by cost
- Identify all potential threat actors targeting the facility
- Determine the financial and operational consequences of disruptions to critical functions (Correct answer)
- Establish the chain of command during an emergency
Correct answer: Determine the financial and operational consequences of disruptions to critical functions
A BIA identifies critical business functions and quantifies the impact their disruption would have on the organization's operations and finances.
Question 48: Which type of investigation focuses specifically on determining the root cause of a security system failure rather than identifying a perpetrator?
- Grand jury investigation
- Administrative investigation
- Root cause analysis (RCA) / technical investigation (Correct answer)
- Criminal investigation
Correct answer: Root cause analysis (RCA) / technical investigation
RCA investigations analyze system failures, process gaps, or equipment malfunctions to prevent recurrence rather than to assign criminal liability.
Question 49: In industrial emergency planning, a 'tabletop exercise' is MOST useful for:
- Discussing scenario-based decisions without deploying resources (Correct answer)
- Training first responders in hands-on emergency techniques
- Testing physical evacuation routes and timing
- Evaluating equipment readiness and maintenance status
Correct answer: Discussing scenario-based decisions without deploying resources
Tabletop exercises allow key personnel to verbally walk through their roles in a scenario, identifying plan gaps without the cost or disruption of a full-scale drill.
Question 50: Which element is NOT typically required in a written industrial security policy?
- Roles and responsibilities of security personnel
- Personal financial information of cleared employees (Correct answer)
- Consequences for policy violations
- Procedures for reporting security incidents
Correct answer: Personal financial information of cleared employees
Personal financial information of employees is not a component of a security policy document; policies address procedural rules, roles, and compliance requirements.
Question 51: When conducting a physical security survey, the recommended technique for testing door frame integrity is:
- Measuring the door width against fire code minimums
- Reviewing the manufacturer's specification sheet only
- Checking the lock cylinder for corrosion
- Applying lateral pressure to assess flex and gap between door and frame (Correct answer)
Correct answer: Applying lateral pressure to assess flex and gap between door and frame
Physically testing door and frame flex reveals whether the assembly can be forced open by leveraging the gap, which may not be apparent from specifications or visual inspection alone.
Question 52: Under NISPOM, what is the required timeframe for a cleared contractor to report an adverse personnel security action to DCSA?
- Within 5 business days (Correct answer)
- Within 90 calendar days
- Within 30 calendar days
- Within 24 hours
Correct answer: Within 5 business days
NISPOM requires contractors to report adverse information about cleared employees to DCSA within 5 business days of the FSO becoming aware of it.
Question 53: What is the role of confidentiality in security policies?
- To limit the number of employees.
- To increase the level of public access.
- To reduce the use of encryption.
- To protect sensitive information from unauthorized access (Correct answer)
Correct answer: To protect sensitive information from unauthorized access
Confidentiality is a core principle of information security, ensuring that sensitive data is accessible only to authorized individuals. Security policies establish clear rules for handling, storing, and transmitting such information, preventing its unauthorized disclosure to those without a legitimate need-to-know. This safeguards privacy, proprietary data, and intellectual property from compromise.
Question 54: A security manager wants to assess whether employees understand how to report a suspicious contact. The BEST assessment method is:
- A realistic scenario exercise requiring employees to demonstrate the actual reporting process (Correct answer)
- Asking employees informally in the hallway if they know the procedure
- Reviewing attendance records for the last security briefing
- A written multiple-choice test on reporting procedures
Correct answer: A realistic scenario exercise requiring employees to demonstrate the actual reporting process
Practical performance assessments test whether employees can actually execute the reporting process, not just recall it on a test.
Question 55: A contractor employee is approached by a foreign national asking detailed questions about their classified work at a social event. What is the CORRECT immediate action?
- Report the contact to the FSO as a suspicious contact report (Correct answer)
- Politely answer general questions to avoid creating a diplomatic incident
- Provide only publicly available information and decline to discuss specifics
- Contact the FBI directly without informing the FSO first
Correct answer: Report the contact to the FSO as a suspicious contact report
Any suspicious foreign contact must be reported to the FSO, who evaluates whether it constitutes a reportable foreign contact and notifies DCSA if required.
Question 56: What is the primary purpose of CPTED (Crime Prevention Through Environmental Design) in industrial security?
- Training employees in self-defense techniques
- Installing the maximum number of cameras possible
- Designing the physical environment to deter criminal activity naturally (Correct answer)
- Replacing human guards with automated systems
Correct answer: Designing the physical environment to deter criminal activity naturally
CPTED uses environmental design principles—lighting, sightlines, landscaping, and space management—to naturally discourage criminal behavior without purely relying on hardware.
Question 57: Which legal doctrine allows the government to withhold classified information in civil litigation to protect national security?
- Qualified immunity
- The state secrets privilege (Correct answer)
- Executive privilege
- Sovereign immunity
Correct answer: The state secrets privilege
The state secrets privilege allows the government to exclude evidence from court proceedings when disclosure would harm national security.
Question 58: Which type of malware is specifically designed to remain hidden while granting an attacker persistent, privileged access to a system?
- Rootkit (Correct answer)
- Worm
- Adware
- Ransomware
Correct answer: Rootkit
Rootkits are designed to hide their presence and provide an attacker with sustained administrative access to a compromised system.
Question 59: Which type of lock is MOST resistant to picking and considered appropriate for high-security industrial access points?
- Wafer tumbler lock
- High-security disc-detainer or medeco lock (Correct answer)
- Standard pin tumbler lock
- Combination padlock
Correct answer: High-security disc-detainer or medeco lock
High-security locks such as Medeco or disc-detainer designs use complex mechanisms with tight tolerances that resist picking, drilling, and key duplication.
Question 60: Which approach to cybersecurity assumes that no user, device, or network segment should be trusted by default, even inside the perimeter?
- Security through obscurity
- Perimeter-based security
- Defense-in-depth
- Zero Trust Architecture (Correct answer)
Correct answer: Zero Trust Architecture
Zero Trust operates on the principle of 'never trust, always verify,' requiring continuous authentication and authorization regardless of network location.
Question 61: What is the purpose of a security incident log?
- To track employee vacation schedules during incidents
- To create an auditable record of all events, actions taken, and decision points during an investigation (Correct answer)
- To replace the need for an incident response plan
- To publicly share breach information with competitors
Correct answer: To create an auditable record of all events, actions taken, and decision points during an investigation
Incident logs provide the documentary trail needed for post-incident review, legal proceedings, insurance claims, and regulatory reporting.
Question 62: The CARVER matrix used in target vulnerability assessments evaluates targets across six criteria. Which of the following is NOT one of the CARVER criteria?
- Redundancy (Correct answer)
- Criticality
- Accessibility
- Effect
Correct answer: Redundancy
CARVER stands for Criticality, Accessibility, Recuperability, Vulnerability, Effect, and Recognizability — Redundancy is not one of the six criteria.
Question 63: In incident response, 'scope creep' during the containment phase refers to:
- Increasing the severity rating of an incident after new evidence is found
- Documenting more detail than required in the incident report
- Adding additional security analysts to speed up the investigation
- Expanding the investigation to include unrelated systems unnecessarily, prolonging downtime (Correct answer)
Correct answer: Expanding the investigation to include unrelated systems unnecessarily, prolonging downtime
Scope creep in containment can take more systems offline than necessary, causing excessive business disruption beyond what the incident warrants.
Question 64: Which federal regulation requires industrial facilities to develop and maintain Emergency Response Plans for hazardous chemical releases?
- EPA 40 CFR Part 68 (RMP)
- OSHA 29 CFR 1910.119 (PSM)
- Both OSHA 29 CFR 1910.120 and EPA 40 CFR Part 68 (Correct answer)
- OSHA 29 CFR 1910.120 (HAZWOPER)
Correct answer: Both OSHA 29 CFR 1910.120 and EPA 40 CFR Part 68
HAZWOPER (1910.120) governs emergency response operations for hazardous substance releases, while EPA's RMP (40 CFR 68) requires separate emergency response program elements for covered facilities.
Question 65: Which population typically receives the MOST targeted security training in an industrial facility due to their elevated access?
- Cafeteria and janitorial staff
- Marketing and public relations teams
- New employees in their first two weeks
- Systems administrators, security managers, and executives with privileged access (Correct answer)
Correct answer: Systems administrators, security managers, and executives with privileged access
Privileged users with elevated access to critical systems pose greater risk and require role-specific training beyond general awareness.
Question 66: The effectiveness of a security awareness program is BEST measured by:
- The cost per training module delivered
- The number of training hours logged per employee
- Executive approval of the training materials
- Changes in employee behavior, reduction in security incidents, and improved phishing simulation click rates (Correct answer)
Correct answer: Changes in employee behavior, reduction in security incidents, and improved phishing simulation click rates
Behavioral metrics and incident trend data are the true indicators of whether awareness training is producing the desired security outcomes.
Question 67: In an industrial security information classification scheme, which label typically applies to trade secrets and proprietary formulas?
- Confidential / Proprietary (Correct answer)
- Top Secret
- Public
- Internal Use Only
Correct answer: Confidential / Proprietary
Confidential or Proprietary is the standard commercial classification for sensitive business information like trade secrets that require restricted handling.
Question 68: How do physical barriers contribute to facility protection?
- By increasing the amount of security staff.
- By blocking unauthorized access to sensitive areas (Correct answer)
- By improving facility aesthetics.
- By reducing employee productivity.
Correct answer: By blocking unauthorized access to sensitive areas
Physical barriers, such as fences, walls, gates, and reinforced doors, create tangible obstacles to entry. They are specifically designed to delay, deter, or prevent unauthorized individuals from gaining access to a facility or specific secure zones within it. These barriers form a crucial first line of defense in a layered security strategy.
Question 69: Digital forensic investigators use 'write blockers' to:
- Encrypt evidence drives before analysis
- Speed up the forensic imaging process
- Prevent any data from being written to an original evidence drive during imaging, preserving its integrity (Correct answer)
- Block malware from writing to the investigator's workstation
Correct answer: Prevent any data from being written to an original evidence drive during imaging, preserving its integrity
Write blockers create a one-way barrier so the forensic tool can read the drive without modifying any data on it.
Question 70: The 'lessons learned' phase of incident response primarily aims to:
- Notify external media about the security breach
- Assign blame and initiate disciplinary actions against responsible personnel
- Identify what worked, what failed, and how to improve processes and controls to prevent recurrence (Correct answer)
- Archive the incident report and close the ticket permanently
Correct answer: Identify what worked, what failed, and how to improve processes and controls to prevent recurrence
Lessons learned transform incident experience into measurable improvements in security posture, policy, and training.
Question 71: Under the ISP framework, what is 'piggybacking' in the context of access control?
- Mounting cameras on fence posts
- Using two-factor authentication simultaneously
- Installing a secondary badge reader on an existing door
- An authorized person allowing an unauthorized person to follow them through a controlled entry (Correct answer)
Correct answer: An authorized person allowing an unauthorized person to follow them through a controlled entry
Piggybacking (also called tailgating) occurs when an unauthorized person exploits an authorized person's access to pass through a secured door without presenting valid credentials.
Question 72: Which document formally records a facility's security requirements, vulnerabilities, countermeasures, and residual risk after a security assessment?
- Incident response plan
- Occupational safety report
- Business continuity plan
- Security master plan or physical security plan (Correct answer)
Correct answer: Security master plan or physical security plan
A security master plan or physical security plan documents findings from the vulnerability assessment and outlines countermeasures, priorities, costs, and residual risk.
Question 73: Social engineering targeting employees is BEST countered by:
- Restricting all employee communication with external parties
- Ongoing security awareness training and clear reporting procedures (Correct answer)
- Installing email filters that block all external messages
- Requiring managers to approve every employee decision
Correct answer: Ongoing security awareness training and clear reporting procedures
Awareness training equips employees to recognize social engineering tactics and empowers them to report suspicious contacts.
Question 74: A security patch management program is PRIMARILY intended to:
- Remediate known software vulnerabilities before they can be exploited (Correct answer)
- Track employee software license compliance
- Improve application performance and add new features
- Automate system backups on a scheduled basis
Correct answer: Remediate known software vulnerabilities before they can be exploited
Patch management ensures vulnerabilities identified in software are addressed in a timely manner to reduce the attack surface.
Question 75: Pre-employment polygraph examinations in the industrial security context are PRIMARILY used to:
- Measure psychological fitness for high-stress roles
- Provide legally admissible evidence in court
- Detect deception regarding undisclosed past activities relevant to suitability (Correct answer)
- Replace background investigations entirely
Correct answer: Detect deception regarding undisclosed past activities relevant to suitability
Polygraphs are used as an investigative tool to surface undisclosed information, not to replace full background checks or provide court evidence.
Question 76: What is a 'counterfeit part' in the context of supply chain security?
- A surplus part sold at a reduced price
- A part manufactured by an unapproved domestic supplier
- An item that is a copy, imitation, or substitute that has been misrepresented as genuine (Correct answer)
- A part that fails quality inspection due to manufacturing defects
Correct answer: An item that is a copy, imitation, or substitute that has been misrepresented as genuine
A counterfeit part is misrepresented as genuine or authorized, posing safety and security risks especially in critical industrial systems.
Question 77: Why are security personnel an essential part of physical security?
- To provide physical protection and respond to security events (Correct answer)
- To focus only on security system maintenance.
- To manage office supplies.
- To act as customer service representatives.
Correct answer: To provide physical protection and respond to security events
Security personnel are trained professionals who provide a vital human element to physical security. They actively patrol, monitor systems, enforce policies, and are capable of direct intervention during security incidents. Their presence and ability to respond quickly are crucial for mitigating threats, protecting assets, and ensuring the safety of individuals within the facility.
Question 78: Which executive order originally established the current framework for classifying, safeguarding, and declassifying national security information?
- Executive Order 13556
- Executive Order 12958
- Executive Order 13526 (Correct answer)
- Executive Order 12829
Correct answer: Executive Order 13526
Executive Order 13526, signed in 2009, is the current authority governing the classification system for national security information.
Question 79: A security manager is evaluating fence types. Which fence fabric specification provides the BEST intrusion deterrence against cutting tools?
- 9-gauge chain-link, 2-inch mesh with tension wire
- 358 high-security welded wire mesh (3Ă—0.5-inch aperture) (Correct answer)
- Wooden privacy fence, 8 feet tall
- Standard 11-gauge chain-link, 2-inch mesh
Correct answer: 358 high-security welded wire mesh (3Ă—0.5-inch aperture)
358 mesh (anti-climb, anti-cut) has small 76.2Ă—12.7 mm apertures and heavy-gauge wire that resist cutting tools and provide minimal finger/toe holds for climbing.
Question 80: During a security risk assessment of a chemical storage facility, the assessor identifies that a fence line runs only 10 feet from a critical valve manifold. This finding primarily represents a concern about which risk element?
- Asset criticality
- Regulatory compliance
- Threat probability
- Standoff distance and vulnerability (Correct answer)
Correct answer: Standoff distance and vulnerability
Insufficient standoff distance between a perimeter barrier and a critical asset increases vulnerability by reducing response time and blast/intrusion buffer.
Question 81: Why is access control important in facility security?
- To reduce security staff.
- To monitor employee attendance.
- To allow unrestricted access to all employees.
- To limit access to secure areas and protect sensitive information (Correct answer)
Correct answer: To limit access to secure areas and protect sensitive information
Access control systems are fundamental to facility security as they regulate who can enter specific areas and at what times. By restricting entry to only authorized personnel, these systems prevent unauthorized individuals from reaching sensitive information, critical infrastructure, or valuable assets. This is essential for maintaining security, confidentiality, and operational integrity.
Question 82: Which access control model grants permissions based on a user's job function rather than individual identity?
- Role-Based Access Control (RBAC) (Correct answer)
- Attribute-Based Access Control (ABAC)
- Mandatory Access Control (MAC)
- Discretionary Access Control (DAC)
Correct answer: Role-Based Access Control (RBAC)
RBAC assigns permissions to roles rather than individuals, simplifying administration and enforcing least privilege by job function.
Question 83: A cyber-physical attack on an industrial facility is uniquely dangerous because:
- Physical security controls cannot be bypassed through cyber means
- Industrial systems automatically revert to safe states during any cyber incident
- It can cause simultaneous digital and physical consequences, including equipment damage, environmental releases, or personnel injury (Correct answer)
- It can only cause financial losses, unlike physical attacks
Correct answer: It can cause simultaneous digital and physical consequences, including equipment damage, environmental releases, or personnel injury
Cyber-physical attacks bridge digital and physical domains, meaning a cyber intrusion can directly trigger real-world harm in industrial environments.
Question 84: A company's written security policy conflicts with a new DCSA regulation. Which takes precedence?
- The DCSA regulation, because federal regulations supersede internal company policies (Correct answer)
- The company policy, because it is more specific to the facility's operations
- Whichever policy is more restrictive, regardless of source
- The policy in effect at the time the facility clearance was originally granted
Correct answer: The DCSA regulation, because federal regulations supersede internal company policies
Federal regulations like NISPOM have the force of law and always supersede internal company policies; company policies must be updated to reflect new regulatory requirements.
Question 85: The 'need-to-know' principle in personnel security means:
- Managers must know all employees' personal background information
- Any cleared employee may access all information at their clearance level
- Access to specific information is granted only when operationally necessary for assigned duties (Correct answer)
- Employees need to know all security procedures regardless of role
Correct answer: Access to specific information is granted only when operationally necessary for assigned duties
Need-to-know limits access to information to only what is required for a person to perform their specific job functions.
Question 86: Presidential Policy Directive 21 (PPD-21) identifies how many critical infrastructure sectors in the United States?
- 16 (Correct answer)
- 21
- 12
- 8
Correct answer: 16
PPD-21 designates 16 critical infrastructure sectors, each with a designated Sector Risk Management Agency (SRMA) responsible for sector-specific guidance.
Question 87: Which regulatory framework governs the protection of Controlled Unclassified Information (CUI) in non-federal U.S. industrial organizations?
- SOX
- HIPAA
- PCI DSS
- NIST SP 800-171 / CMMC (Correct answer)
Correct answer: NIST SP 800-171 / CMMC
NIST SP 800-171 and its enforcement mechanism CMMC apply to contractors and industrial firms handling CUI on behalf of the U.S. government.
Question 88: Which agency is responsible for adjudicating personnel security clearances for most Department of Defense contractors?
- Defense Counterintelligence and Security Agency (DCSA) (Correct answer)
- Federal Bureau of Investigation (FBI)
- Office of Personnel Management (OPM)
- Department of Homeland Security (DHS)
Correct answer: Defense Counterintelligence and Security Agency (DCSA)
DCSA (formerly DSS) is the primary security oversight agency for the defense industrial base, including adjudicating clearances for DoD contractors.
Question 89: Which practice is MOST effective in verifying the authenticity of hardware components received from a supplier?
- Accepting the supplier's certificate of conformance without inspection
- Storing components in a secure warehouse for 30 days before use
- Testing against known-good baselines and reviewing traceability documentation (Correct answer)
- Visual inspection only by receiving staff
Correct answer: Testing against known-good baselines and reviewing traceability documentation
Testing against known-good baselines and verifying traceability documentation (including provenance records) are the most effective methods for detecting counterfeit or tampered components.
Question 90: A security manager is designing an alarm system for an industrial warehouse. What is the key difference between 'local' and 'central station' alarm monitoring?
- Local alarms alert only on-site personnel; central station monitoring notifies a remote 24/7 monitoring facility that can dispatch responders (Correct answer)
- Local alarms automatically lock all doors; central stations do not
- Central station systems do not require sensors at the facility
- Local alarms are more expensive than central station systems
Correct answer: Local alarms alert only on-site personnel; central station monitoring notifies a remote 24/7 monitoring facility that can dispatch responders
Local alarms sound on site, relying on nearby response, while central station systems transmit alerts to a professionally staffed remote monitoring center that can coordinate emergency response.
Question 91: Which federal regulation requires contractors handling classified information to implement supply chain risk management (SCRM) practices?
- HIPAA Security Rule
- OSHA 1910.119
- SOX Section 404
- NISPOM (32 CFR Part 117) (Correct answer)
Correct answer: NISPOM (32 CFR Part 117)
The National Industrial Security Program Operating Manual (NISPOM), codified at 32 CFR Part 117, governs cleared contractors and includes supply chain risk management requirements.
Question 92: What is the purpose of a Security Classification Guide (SCG) in a classified program?
- To authorize contractor employees to self-classify their own work products
- To document the physical security measures required at the contractor's facility
- To serve as a master list of all cleared employees on a classified contract
- To provide specific guidance on what information within a program is classified and at what level (Correct answer)
Correct answer: To provide specific guidance on what information within a program is classified and at what level
An SCG is a government-issued document that tells contractors exactly which elements of a specific program are classified, at what level, and why.
Question 93: Which clause in a vendor contract BEST helps protect an organization if a supplier experiences a security incident?
- Exclusivity clause
- Force majeure clause
- Net-30 payment terms clause
- Security breach notification requirement clause (Correct answer)
Correct answer: Security breach notification requirement clause
A security breach notification requirement obligates the vendor to promptly inform the organization of incidents, enabling timely response and mitigation of downstream impacts.
Question 94: Which assessment methodology involves attempting to defeat security measures through simulated unauthorized access attempts, often unannounced to site staff?
- Red team / adversarial penetration test (Correct answer)
- Gap analysis audit
- Tabletop exercise
- Business impact analysis
Correct answer: Red team / adversarial penetration test
A red team or penetration test simulates real-world attacks against physical and procedural controls, often without staff foreknowledge, to reveal actual vulnerabilities under realistic conditions.
Question 95: A security risk assessment at an industrial plant identifies 'criticality' of assets. What does criticality PRIMARILY measure?
- The age and depreciation of the asset
- The difficulty of physically securing the asset
- The impact on operations or mission if the asset is lost, damaged, or compromised (Correct answer)
- The replacement cost of an asset
Correct answer: The impact on operations or mission if the asset is lost, damaged, or compromised
Criticality measures how essential an asset is to the organization's mission; a highly critical asset causes severe operational disruption if compromised regardless of its monetary value.
Question 96: Why is it important to have a business continuity plan?
- To decrease operational efficiency.
- To increase the likelihood of a crisis.
- To reduce customer trust.
- To ensure that critical operations continue during a crisis (Correct answer)
Correct answer: To ensure that critical operations continue during a crisis
A business continuity plan (BCP) focuses on maintaining essential business functions during and after a disruptive event, such as a natural disaster or cyberattack. It outlines strategies and procedures to minimize downtime, recover critical systems, and ensure the ongoing delivery of products or services. This safeguards an organization's financial stability, customer relationships, and overall operational resilience.
Question 97: Which component of the risk equation directly measures the probability that a specific threat will materialize within a defined time period?
- Vulnerability rating
- Impact severity
- Threat likelihood (Correct answer)
- Asset value
Correct answer: Threat likelihood
Threat likelihood (or probability) quantifies how often or how probably a specific threat event will occur within a given timeframe.
Question 98: A security policy states that all classified materials must be stored in GSA-approved containers. What type of policy requirement is this?
- Voluntary best practice
- Mandatory control (Correct answer)
- Administrative guideline
- Discretionary control
Correct answer: Mandatory control
GSA-approved container requirements are mandatory controls derived from federal regulation, not discretionary guidelines.
Question 99: What role does communication play in crisis management?
- It ensures that all stakeholders are informed and response efforts are coordinated (Correct answer)
- It helps to escalate the crisis.
- It limits the flow of information.
- It increases confusion during the crisis.
Correct answer: It ensures that all stakeholders are informed and response efforts are coordinated
Effective communication is paramount during a crisis to manage perceptions, provide accurate information, and prevent misinformation. It ensures that all stakeholders, including employees, customers, and media, receive timely updates, fostering trust and enabling coordinated actions. Clear and consistent communication helps maintain control, guides the response effort, and protects the organization's reputation.
Question 100: What is the primary legal reason for maintaining a 'chain of custody' during a security investigation?
- To preserve the integrity and admissibility of evidence in legal or disciplinary proceedings (Correct answer)
- To ensure the fastest possible resolution of the incident
- To assign blame quickly within the organization
- To comply with annual audit requirements
Correct answer: To preserve the integrity and admissibility of evidence in legal or disciplinary proceedings
Proper chain of custody documents who handled evidence and when, ensuring it has not been tampered with and remains legally admissible.
Question 101: In the context of industrial security, what is a 'security baseline'?
- A record of all past security incidents at the facility
- The minimum acceptable level of security measures required across all facility areas (Correct answer)
- The initial cost estimate for installing security systems
- The height specification for perimeter fencing
Correct answer: The minimum acceptable level of security measures required across all facility areas
A security baseline defines the minimum set of security controls and measures that must be in place at all times to meet regulatory, organizational, or risk-based requirements.
Question 102: Which training delivery method is MOST effective for building practical decision-making skills in security scenarios?
- Watching a recorded lecture with no interaction
- Reviewing a policy checklist before signing an acknowledgment form
- Scenario-based and simulation training that mirrors real-world security challenges (Correct answer)
- Reading a printed security manual independently
Correct answer: Scenario-based and simulation training that mirrors real-world security challenges
Scenario-based training engages learners by placing them in realistic situations that develop judgment and response skills.
Question 103: What is the primary goal of physical security in facility protection?
- To increase facility profits.
- To protect facilities and assets from physical threats (Correct answer)
- To reduce energy consumption.
- To minimize employee involvement in security.
Correct answer: To protect facilities and assets from physical threats
Physical security is specifically designed to protect tangible assets, personnel, and the physical environment from harm. Its primary objective is to prevent unauthorized access, theft, vandalism, and other physical threats that could disrupt operations or compromise safety. This ensures the integrity and continuous operation of the facility and its valuable contents.
Question 104: What does the term 'need-to-know' mean in the context of classified information access?
- The individual has completed required security training for that classification level
- Access is required to perform an officially assigned duty or task (Correct answer)
- The individual's supervisor has verbally approved access on request
- The individual holds a clearance at least one level above the classification
Correct answer: Access is required to perform an officially assigned duty or task
Need-to-know means a person must require access to specific classified information to perform their official duties, even if they hold the appropriate clearance level.
Question 105: 'Gamification' in security training programs refers to:
- Replacing security training with recreational activities
- Allowing employees to skip training modules they find difficult
- Using virtual reality for physical security simulations only
- Using game-like elements such as points, leaderboards, and rewards to increase engagement and knowledge retention (Correct answer)
Correct answer: Using game-like elements such as points, leaderboards, and rewards to increase engagement and knowledge retention
Gamification applies motivational elements from game design to training, increasing participation and knowledge retention through competition and reward.
Question 106: What is the role of lighting in facility protection?
- To reduce energy consumption.
- To improve workplace morale.
- To improve employee comfort.
- To enhance security by increasing visibility and deterring crime (Correct answer)
Correct answer: To enhance security by increasing visibility and deterring crime
Proper lighting eliminates dark spots and shadows, which can be exploited by intruders to conceal their activities. Increased visibility makes it harder for unauthorized individuals to approach or operate undetected, thereby deterring criminal activity. It also allows surveillance systems to function more effectively and helps security personnel identify potential threats.
Question 107: When must a security incident be reported to the relevant government authority in a cleared industrial facility?
- Never—all incidents are handled internally without government notification
- Whenever a reportable security incident occurs, per the facility's reporting requirements and DD Form 577 obligations (Correct answer)
- Only after a full internal investigation is complete
- Only if classified information was confirmed as compromised
Correct answer: Whenever a reportable security incident occurs, per the facility's reporting requirements and DD Form 577 obligations
Government-cleared facilities are obligated to report security incidents to their Cognizant Security Agency (CSA) as specified in their facility clearance agreement.
Question 108: What is the purpose of a security clearance adjudication?
- To terminate employees who fail polygraph examinations
- To assign an employee's access level based solely on job title
- To determine whether granting access is clearly consistent with national or industrial security interests (Correct answer)
- To issue an employee identification badge
Correct answer: To determine whether granting access is clearly consistent with national or industrial security interests
Adjudication evaluates all available information to decide if an individual's access is consistent with security interests.
Question 109: An insider threat is BEST defined as a risk posed by which of the following?
- Vendors who deliver supplies to the facility
- External hackers who gain physical access
- Current or former employees, contractors, or partners who misuse authorized access (Correct answer)
- Foreign intelligence agents who never entered the facility
Correct answer: Current or former employees, contractors, or partners who misuse authorized access
Insider threats originate from individuals who already have or recently had authorized access and can abuse that trust.
Question 110: A 'security baseline' in an industrial information security program refers to:
- A benchmark test for measuring network throughput
- The minimum acceptable configuration and security controls applied uniformly to all systems (Correct answer)
- The starting point for a risk assessment before any controls are applied
- The highest security standard applied only to classified networks
Correct answer: The minimum acceptable configuration and security controls applied uniformly to all systems
A security baseline defines the minimum set of controls every system must have, ensuring a consistent security floor across the organization.
Question 111: What is the MAIN advantage of a video analytics system over traditional CCTV monitoring in a large industrial facility?
- Automated detection of predefined behaviors without requiring continuous human monitoring (Correct answer)
- Higher image resolution
- Longer video retention periods
- Lower camera hardware cost
Correct answer: Automated detection of predefined behaviors without requiring continuous human monitoring
Video analytics software analyzes footage in real time to automatically alert on specific behaviors (e.g., perimeter crossing, loitering), reducing human fatigue and missed events.
Question 112: During a facility security survey, a consultant recommends 'natural surveillance.' This refers to:
- Installing hidden cameras in natural-looking housings
- Deploying undercover guards dressed as workers
- Positioning windows, lighting, and landscaping so legitimate users can observe activity (Correct answer)
- Using wildlife cameras to monitor perimeter areas
Correct answer: Positioning windows, lighting, and landscaping so legitimate users can observe activity
Natural surveillance maximizes visibility of people and spaces through thoughtful design of windows, open sightlines, and lighting so occupants and passersby deter crime.
Question 113: Under the NISPOM, how frequently must a Facility Security Officer (FSO) conduct self-inspections?
- Quarterly
- Monthly
- Every two years
- Annually (Correct answer)
Correct answer: Annually
NISPOM requires cleared contractors to conduct annual self-inspections to evaluate the effectiveness of their security programs.
Question 114: What does the term 'vendor lock-in' represent as a supply chain security concern?
- A security feature that limits vendor system access
- A contractual clause preventing vendors from disclosing pricing
- Excessive dependence on a single vendor that limits an organization's ability to switch suppliers (Correct answer)
- A vendor physically securing their facility
Correct answer: Excessive dependence on a single vendor that limits an organization's ability to switch suppliers
Vendor lock-in creates a single point of failure and reduces negotiating leverage, making the organization vulnerable if that vendor is compromised, disrupted, or becomes adversarial.
Question 115: Which behavioral indicator is most commonly associated with a potential malicious insider?
- Requesting additional training on new equipment
- Working overtime during a major project
- Unexplained affluence inconsistent with salary (Correct answer)
- Taking vacation shortly after a performance review
Correct answer: Unexplained affluence inconsistent with salary
Unexplained wealth that cannot be reconciled with an employee's known salary is a classic red flag for theft or espionage.
Question 116: In a cleared facility, a 'security violation' is BEST defined as:
- Only intentional acts of espionage by cleared personnel
- Any act or omission that is contrary to established security regulations, regardless of intent (Correct answer)
- A fire code infraction discovered during an audit
- Any action that results in employee injury on the job
Correct answer: Any act or omission that is contrary to established security regulations, regardless of intent
Security violations include both deliberate and negligent breaches of security requirements and must be reported regardless of intent.
Question 117: What is the importance of regular security audits?
- To increase security breaches.
- To reduce security costs.
- To limit employee involvement.
- To ensure security measures are working and identify areas for improvement (Correct answer)
Correct answer: To ensure security measures are working and identify areas for improvement
Regular security audits are essential for continuously assessing the effectiveness of existing security controls and identifying any vulnerabilities or outdated practices. They help ensure that security measures are functioning as intended and highlight areas that require improvement or updating. This proactive evaluation allows organizations to adapt and strengthen their security posture against evolving threats.
Question 118: In an industrial facility, a 'sally port' or 'mantrap' is primarily used to:
- Provide a secondary fire exit route
- Prevent piggybacking by allowing only one person to enter at a time (Correct answer)
- House security guard shift change records
- Store emergency response equipment
Correct answer: Prevent piggybacking by allowing only one person to enter at a time
A sally port or mantrap uses two interlocking doors so the first must close before the second opens, preventing piggybacking (tailgating) into secure areas.
Question 119: A company discovers that a critical component supplier has been acquired by a foreign entity with potential ties to a nation-state adversary. What is the MOST appropriate immediate action?
- Conduct a supply chain risk assessment and consider alternative suppliers (Correct answer)
- Continue business as usual until the next contract renewal
- Immediately terminate the contract without further review
- Report the acquisition to the media
Correct answer: Conduct a supply chain risk assessment and consider alternative suppliers
A supply chain risk assessment allows the organization to evaluate the actual threat level and develop an informed mitigation strategy, including identifying alternative suppliers if necessary.
Question 120: When conducting a vulnerability assessment as part of emergency planning, the assessment team should:
- Limit the assessment to areas covered by existing insurance policies
- Focus exclusively on natural disaster risks
- Rely solely on historical incident data without considering emerging threats
- Evaluate threats, vulnerabilities, and consequences across all hazard categories (Correct answer)
Correct answer: Evaluate threats, vulnerabilities, and consequences across all hazard categories
A comprehensive vulnerability assessment examines the full spectrum of threats and hazards, assesses existing countermeasure gaps, and evaluates potential consequences to prioritize mitigation.
Question 121: A security investigator discovers a suspicious USB drive in a secured area. The FIRST action should be:
- Plug it into a computer to identify its contents
- Discard it to prevent further risk to the facility
- Photograph it in place, document its location, and secure it as evidence without inserting it into any system (Correct answer)
- Hand it to the nearest employee to identify the owner
Correct answer: Photograph it in place, document its location, and secure it as evidence without inserting it into any system
Documenting and preserving the device without connecting it protects both evidence integrity and facility systems from potential malware.
Question 122: Which training element is MOST effective at reducing successful phishing attacks?
- Regular simulated phishing campaigns followed by immediate targeted training for those who click (Correct answer)
- Requiring employees to read and sign an anti-phishing policy
- Blocking all external email from reaching employee inboxes
- Annual slideshow presentations about phishing statistics
Correct answer: Regular simulated phishing campaigns followed by immediate targeted training for those who click
Simulated phishing with real-time, just-in-time training for those who fall for it creates a teachable moment directly tied to the behavior you want to change.
Question 123: Which security control prevents an employee from reading emails on a personally owned device not approved by the organization?
- Mobile Device Management (MDM) with a BYOD policy restriction (Correct answer)
- Physical security guards at the building entrance
- Antivirus software on company servers
- Data Loss Prevention (DLP)
Correct answer: Mobile Device Management (MDM) with a BYOD policy restriction
MDM combined with a BYOD policy can enforce that only managed, compliant devices can access corporate email and resources.
Question 124: An industrial security investigation MUST remain within which legal boundary when interviewing employees?
- Employees must be informed of their rights, and interviews must comply with applicable labor and employment law (Correct answer)
- Investigators can review employee medical records without consent
- Investigators may use physical coercion if the employee refuses to cooperate
- Employees may be detained indefinitely pending investigation outcomes
Correct answer: Employees must be informed of their rights, and interviews must comply with applicable labor and employment law
Industrial security investigations must respect labor laws, privacy rights, and employee rights to counsel to avoid legal liability.
Question 125: When establishing a command post during an industrial emergency, it should be located:
- Adjacent to the affected area for direct oversight
- Inside the facility to maintain communication with workers
- At the main entrance gate for easy public access
- Upwind and uphill from the incident site (Correct answer)
Correct answer: Upwind and uphill from the incident site
Positioning the command post upwind and uphill keeps responders out of hazardous vapors and runoff from the incident site.
Question 126: What is a 'zero-day vulnerability'?
- A vulnerability discovered exactly at midnight
- A flaw in a zero-trust network architecture
- A vulnerability with no exploits available in any threat database
- A software flaw unknown to the vendor for which no patch exists at the time of discovery or exploitation (Correct answer)
Correct answer: A software flaw unknown to the vendor for which no patch exists at the time of discovery or exploitation
Zero-day vulnerabilities are particularly dangerous because defenders have 'zero days' to patch before the flaw can be exploited.
Question 127: How can businesses prepare for potential crises?
- By focusing on reactive responses only.
- By developing preparedness plans and training staff (Correct answer)
- By reducing the number of employees.
- By ignoring potential risks.
Correct answer: By developing preparedness plans and training staff
Proactive preparation is key to effective crisis management, enabling a rapid and organized response when a crisis inevitably occurs. This involves identifying potential risks, creating detailed crisis plans, and regularly training employees on their roles and responsibilities during an emergency. Such preparedness minimizes confusion, reduces damage, and facilitates a quicker recovery.
Question 128: Which threat actor type poses the GREATEST risk to critical national infrastructure due to their resources and long-term strategic objectives?
- Opportunistic ransomware criminals targeting random organizations
- Nation-state Advanced Persistent Threat (APT) groups (Correct answer)
- Script kiddies using publicly available exploit tools
- Disgruntled former employees with residual access
Correct answer: Nation-state Advanced Persistent Threat (APT) groups
Nation-state APT groups have significant resources, technical sophistication, and long-term strategic patience that makes them uniquely dangerous to critical infrastructure.
Question 129: Which of the following is NOT one of the 13 Adjudicative Guidelines under SEAD 4?
- Physical Fitness Standards (Correct answer)
- Drug Involvement
- Sexual Behavior
- Allegiance to the United States
Correct answer: Physical Fitness Standards
Physical fitness is not an adjudicative guideline; the 13 guidelines focus on loyalty, conduct, and character issues relevant to trustworthiness.
Question 130: What is the role of surveillance systems in physical security?
- To increase the cost of security systems.
- To reduce employee morale.
- To focus only on monitoring employees.
- To monitor and deter unauthorized activities (Correct answer)
Correct answer: To monitor and deter unauthorized activities
Surveillance systems, such as CCTV cameras, serve as a critical tool for continuous monitoring of an area. Their visible presence acts as a deterrent to potential intruders or malicious activities, while also providing crucial visual evidence for investigations if an incident occurs. This enhances overall security by increasing situational awareness and accountability.
Question 131: A security manager at a petrochemical plant wants to evaluate the likelihood and consequence of a chlorine gas release scenario. Which analytical tool is most appropriate for mapping all potential failure pathways leading to that event?
- Cost-benefit analysis
- Fault tree analysis (Correct answer)
- SWOT analysis
- Delphi panel
Correct answer: Fault tree analysis
Fault tree analysis uses a top-down, deductive logic diagram to identify all combinations of component failures or errors that could lead to a defined undesired event.
Question 132: Which law makes it a federal crime to knowingly and willfully misuse or disclose classified information without authorization?
- 18 U.S.C. § 1030
- The Espionage Act (18 U.S.C. §§ 793-798) (Correct answer)
- The Computer Fraud and Abuse Act (CFAA)
- The Trade Secrets Act (18 U.S.C. § 1905)
Correct answer: The Espionage Act (18 U.S.C. §§ 793-798)
The Espionage Act (18 U.S.C. §§ 793-798) is the primary federal statute criminalizing unauthorized disclosure of national defense information.
Question 133: A phishing email that targets a specific senior executive is known as:
- Smishing
- Spear phishing
- Whaling (Correct answer)
- Vishing
Correct answer: Whaling
Whaling is a form of spear phishing specifically aimed at high-value targets such as executives or key decision-makers.
Question 134: An industrial facility uses proximity card readers. Which attack method specifically targets these systems by covertly reading and cloning a valid card from a distance?
- Shoulder surfing
- Dumpster diving
- Relay/skimming attack using an RFID reader (Correct answer)
- Social engineering the receptionist
Correct answer: Relay/skimming attack using an RFID reader
RFID skimming uses a concealed reader to capture card data wirelessly, enabling an attacker to clone a legitimate credential without the cardholder's knowledge.
Question 135: An air-gapped network in an industrial environment means:
- The network operates at lower bandwidth to reduce attack surface
- The network uses encrypted tunnels to connect to the internet
- The network uses wireless frequencies exclusively
- The network is physically isolated with no connections to external or untrusted networks (Correct answer)
Correct answer: The network is physically isolated with no connections to external or untrusted networks
An air gap is a physical security measure that prevents a network from connecting to external systems, limiting remote attack vectors.
Question 136: How does a well-prepared crisis management team impact recovery?
- It delays the crisis response.
- It causes more confusion during the crisis.
- It improves the organization’s ability to recover quickly (Correct answer)
- It focuses on business closure.
Correct answer: It improves the organization’s ability to recover quickly
A well-prepared crisis management team significantly enhances an organization's ability to recover quickly and effectively. Such a team has pre-defined roles, established protocols, and often conducts drills, allowing for a swift and coordinated response when a crisis strikes. This preparedness minimizes confusion, reduces the impact of the crisis, and facilitates a more organized and efficient path back to normal operations, thereby accelerating recovery.
Question 137: What is the primary objective of crisis management?
- To ignore potential risks.
- To manage and mitigate the impact of a crisis (Correct answer)
- To increase the severity of the crisis.
- To delay the response time.
Correct answer: To manage and mitigate the impact of a crisis
Crisis management is a strategic process designed to prepare for, respond to, and recover from significant disruptive events. Its primary objective is to minimize the negative consequences of a crisis on an organization's operations, reputation, and stakeholders. This involves coordinated efforts to control the situation, mitigate damage, and restore normalcy as quickly as possible.
Question 138: Which process is used to verify that employees only retain access rights appropriate to their current role?
- Annual security awareness training
- Visitor log auditing
- Access recertification or entitlement review (Correct answer)
- Periodic reinvestigation
Correct answer: Access recertification or entitlement review
Access recertification (entitlement review) is the formal process of confirming that each user's permissions still match their job requirements.
Question 139: Which security vetting tool requires the subject to disclose foreign contacts, travel, and financial information?
- Form I-9 (Employment Eligibility Verification)
- OSHA 300 Log
- Standard Form 86 (Questionnaire for National Security Positions) (Correct answer)
- IRS Form W-4
Correct answer: Standard Form 86 (Questionnaire for National Security Positions)
SF-86 is the U.S. government form used to collect the personal history needed to conduct a national security background investigation.
Question 140: Which document formally authorizes a system to operate by accepting identified residual risks?
- Incident Response Plan (IRP)
- Authority to Operate (ATO) (Correct answer)
- Business Continuity Plan (BCP)
- System Security Plan (SSP)
Correct answer: Authority to Operate (ATO)
An ATO is an official management decision that a system's risk level is acceptable and it is authorized for operation.
Question 141: The principle of 'least privilege' in cybersecurity means:
- Giving users only the minimum access rights needed to perform their job functions (Correct answer)
- Granting users the maximum access possible to avoid productivity delays
- Allowing all administrators unrestricted access for efficiency
- Applying security controls only to the most critical systems
Correct answer: Giving users only the minimum access rights needed to perform their job functions
Least privilege minimizes the potential damage from accidents, errors, or attacks by limiting what any single account can access or modify.
Question 142: Which industrial control system (ICS) protocol is most commonly targeted by adversaries due to its lack of built-in authentication?
- HTTPS
- TLS 1.3
- Modbus (Correct answer)
- SSH
Correct answer: Modbus
Modbus was designed for reliability in isolated networks and lacks authentication, making it vulnerable when exposed to broader networks.
Question 143: In the context of facility security, which term describes the minimum acceptable level of risk that an organization is willing to tolerate?
- Residual risk floor
- Risk tolerance threshold
- Acceptable risk baseline
- Risk appetite (Correct answer)
Correct answer: Risk appetite
Risk appetite defines the amount and type of risk an organization is willing to accept in pursuit of its objectives before action is required.
Question 144: What is the role of incident response planning in security compliance?
- To reduce the number of incidents.
- To delay incident response.
- To eliminate the need for security audits.
- To ensure a coordinated response and compliance with regulations (Correct answer)
Correct answer: To ensure a coordinated response and compliance with regulations
Incident response planning outlines the structured steps an organization will take when a security incident occurs. In the context of compliance, it ensures that the response adheres to legal and regulatory mandates for reporting, data breach notification, and evidence preservation. A well-defined plan minimizes legal exposure, facilitates a structured recovery, and demonstrates due diligence to regulatory bodies.
Question 145: Which NIST publication provides a cybersecurity framework specifically tailored for ICS and SCADA systems?
- NIST SP 800-171
- NIST SP 800-82 (Guide to ICS Security) (Correct answer)
- NIST SP 800-61
- NIST SP 800-53
Correct answer: NIST SP 800-82 (Guide to ICS Security)
NIST SP 800-82 provides specific guidance on applying security controls to industrial control systems, SCADA, and other OT environments.
Question 146: An adversarial simulation in which a team attempts to bypass physical and electronic security controls to reach a target within a facility is called a:
- Red team assessment (Correct answer)
- Gap analysis
- Tabletop exercise
- Security survey
Correct answer: Red team assessment
A red team assessment employs adversarial tactics to test physical, electronic, and human security controls under realistic attack conditions.
Question 147: A security manager discovers that a former employee's access credentials were used to log in two weeks after termination. This indicates a failure in:
- Annual penetration testing processes
- Access termination and offboarding procedures (Correct answer)
- Physical perimeter control
- Fire suppression system maintenance
Correct answer: Access termination and offboarding procedures
Access that survives beyond an employee's departure indicates the offboarding process failed to revoke credentials in a timely manner.
Question 148: What does 'triage' mean in the context of security incident management?
- Escalating every incident to executive leadership immediately
- Quickly assessing and prioritizing incidents based on severity and potential impact to allocate response resources (Correct answer)
- Eliminating all infected systems from the network immediately
- Documenting every detail before taking any action
Correct answer: Quickly assessing and prioritizing incidents based on severity and potential impact to allocate response resources
Triage allows security teams to focus limited resources on the most critical incidents first by rapidly assessing severity.
Question 149: Which communication method is MOST appropriate for distributing urgent security threat warnings to all employees quickly?
- Holding monthly all-hands meetings to discuss new threats
- Mailing printed advisories to employees' home addresses
- Mass notification system reaching all employees via email, SMS, and PA announcement simultaneously (Correct answer)
- Posting a notice on the physical security bulletin board only
Correct answer: Mass notification system reaching all employees via email, SMS, and PA announcement simultaneously
Mass notification systems that use multiple simultaneous channels ensure the broadest, fastest reach for time-sensitive security alerts.
Question 150: Why is compliance with legal and regulatory requirements important for security management?
- To avoid legal penalties and protect organizational reputation (Correct answer)
- To avoid employee accountability.
- To increase the number of security personnel.
- To limit security system installation.
Correct answer: To avoid legal penalties and protect organizational reputation
Compliance with legal and regulatory requirements is crucial because failure to adhere to these standards can result in significant financial penalties, legal action, and severe damage to an organization's reputation. Adhering to these mandates demonstrates due diligence and a commitment to security, fostering trust with customers, partners, and stakeholders. It also helps avoid operational disruptions caused by non-compliance issues.
Question 151: An employee reports that a coworker has been downloading large volumes of proprietary schematics to a personal USB drive. The FIRST security response should be:
- Disable the entire facility's USB ports without investigation
- Post a notice about USB policies on the bulletin board
- Document the observation and report it to the insider threat officer or security manager (Correct answer)
- Immediately confront the coworker in front of the team
Correct answer: Document the observation and report it to the insider threat officer or security manager
Proper reporting to the designated security authority allows a structured investigation without tipping off the subject or compromising evidence.
Industrial Security Professional (ISP) Certification Exam
The ISP certification validates an individual's expertise in industrial security practices, demonstrating a comprehensive understanding of security principles, regulations, and risk management within industrial environments.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds