Industrial Security Professional (ISP) Certification Exam — Questions and Answers
Question 1: Which category of emergency notification system is MOST critical for alerting off-site communities to an industrial chemical release?
- Posted notices at facility entrances
- Internal PA system announcement
- Employee text message trees
- Outdoor warning sirens combined with Emergency Alert System broadcasts (Correct answer)
Correct answer: Outdoor warning sirens combined with Emergency Alert System broadcasts
Outdoor warning sirens combined with EAS broadcasts reach the surrounding community rapidly regardless of whether residents are indoors or monitoring media.
Question 2: Which of the following BEST describes a 'trusted supplier program' in an industrial security context?
- A financial incentive program for suppliers who meet delivery deadlines
- A formal vetting and approval process that authorizes suppliers to provide goods or services with reduced oversight (Correct answer)
- A program requiring all suppliers to be located domestically
- A marketing program where suppliers pay for a certification badge
Correct answer: A formal vetting and approval process that authorizes suppliers to provide goods or services with reduced oversight
A trusted supplier program formally vets and approves suppliers based on security criteria, allowing the organization to reduce redundant controls for pre-approved vendors while maintaining assurance.
Question 3: Which framework is widely used in U.S. industrial environments to manage cybersecurity risk?
- OSHA 29 CFR 1910
- ISO 45001
- ASIS SPC.1
- NIST Cybersecurity Framework (CSF) (Correct answer)
Correct answer: NIST Cybersecurity Framework (CSF)
The NIST CSF provides a structured approach to identifying, protecting, detecting, responding to, and recovering from cybersecurity incidents.
Question 4: What does the ISP body of knowledge define as the OUTER layer of the 'defense-in-depth' model for physical security?
- Electronic access control systems
- Building interior controls
- Perimeter barriers and boundary definition (Correct answer)
- Asset storage vaults
Correct answer: Perimeter barriers and boundary definition
Defense-in-depth layers security from outer perimeter barriers inward through building envelope controls to inner asset protection, with the perimeter being the outermost layer.
Question 5: Encryption of data in transit is BEST enforced in an industrial network by requiring:
- Transport Layer Security (TLS) or equivalent cryptographic protocols on all network channels (Correct answer)
- Verbal communication only for classified operational data
- Physical mail delivery for sensitive documents
- All communications to use plaintext for troubleshooting visibility
Correct answer: Transport Layer Security (TLS) or equivalent cryptographic protocols on all network channels
TLS ensures data integrity and confidentiality while in transit across networks that may traverse untrusted segments.
Question 6: A 'unidirectional gateway' (data diode) in an OT network is BEST described as:
- A backup power supply for network switches in control rooms
- A software-based VPN tunnel for secure OT remote access
- A two-way firewall configured to allow only approved traffic in both directions
- A hardware device that physically allows data to flow in only one direction, preventing any reverse communication (Correct answer)
Correct answer: A hardware device that physically allows data to flow in only one direction, preventing any reverse communication
Data diodes enforce unidirectional data flow at the hardware level, making it physically impossible for data to travel back from the secure OT network to the IT network.
Question 7: What does the term 'need-to-know' mean in the context of classified information access?
- The individual holds a clearance at least one level above the classification
- Access is required to perform an officially assigned duty or task (Correct answer)
- The individual has completed required security training for that classification level
- The individual's supervisor has verbally approved access on request
Correct answer: Access is required to perform an officially assigned duty or task
Need-to-know means a person must require access to specific classified information to perform their official duties, even if they hold the appropriate clearance level.
Question 8: Which federal standard or guideline is most commonly referenced for physical protection systems at US government contractor industrial facilities?
- NFPA 101 Life Safety Code
- EPA Risk Management Plan
- OSHA 29 CFR 1910
- NISPOM (National Industrial Security Program Operating Manual) (Correct answer)
Correct answer: NISPOM (National Industrial Security Program Operating Manual)
The NISPOM (DoD 5220.22-M / 32 CFR Part 117) governs physical and personnel security requirements for US government contractors handling classified information and materials.
Question 9: Under CFATS (Chemical Facility Anti-Terrorism Standards), facilities are ranked into tiers primarily based on:
- Annual revenue and number of employees
- Proximity to critical infrastructure such as ports and airports
- Type of ownership — public, private, or government
- The risk posed by the chemicals they hold relative to terrorist attack potential (Correct answer)
Correct answer: The risk posed by the chemicals they hold relative to terrorist attack potential
CFATS assigns facilities to Tiers 1–4 based on the level of security risk their chemicals of interest present, with Tier 1 being the highest risk.
Question 10: Which program element is essential to a robust Insider Threat Program (InTP)?
- Reporting all suspicious behavior directly to law enforcement without internal review
- Installing covert recording devices in break rooms
- Establishing a multidisciplinary hub that integrates HR, IT, security, and legal data (Correct answer)
- Reviewing only IT access logs on an annual basis
Correct answer: Establishing a multidisciplinary hub that integrates HR, IT, security, and legal data
An effective InTP requires a cross-functional team that combines data from multiple departments to detect and deter insider threats.
Question 11: What role does communication play in crisis management?
- It limits the flow of information.
- It increases confusion during the crisis.
- It helps to escalate the crisis.
- It ensures that all stakeholders are informed and response efforts are coordinated (Correct answer)
Correct answer: It ensures that all stakeholders are informed and response efforts are coordinated
Effective communication is paramount during a crisis to manage perceptions, provide accurate information, and prevent misinformation. It ensures that all stakeholders, including employees, customers, and media, receive timely updates, fostering trust and enabling coordinated actions. Clear and consistent communication helps maintain control, guides the response effort, and protects the organization's reputation.
Question 12: An employee discovers a coworker has taken classified documents home without authorization. Under NISPOM, what is the employee's FIRST obligation?
- File a report directly with DCSA, bypassing the FSO
- Confront the coworker directly and demand return of the documents
- Wait to see if the coworker returns the documents before reporting
- Report the incident to the Facility Security Officer (FSO) immediately (Correct answer)
Correct answer: Report the incident to the Facility Security Officer (FSO) immediately
Employees have a mandatory duty to report security violations to the FSO, who then determines appropriate escalation steps.
Question 13: Which security vetting tool requires the subject to disclose foreign contacts, travel, and financial information?
- IRS Form W-4
- OSHA 300 Log
- Standard Form 86 (Questionnaire for National Security Positions) (Correct answer)
- Form I-9 (Employment Eligibility Verification)
Correct answer: Standard Form 86 (Questionnaire for National Security Positions)
SF-86 is the U.S. government form used to collect the personal history needed to conduct a national security background investigation.
Question 14: Under NISPOM, what is the required timeframe for a cleared contractor to report an adverse personnel security action to DCSA?
- Within 24 hours
- Within 30 calendar days
- Within 90 calendar days
- Within 5 business days (Correct answer)
Correct answer: Within 5 business days
NISPOM requires contractors to report adverse information about cleared employees to DCSA within 5 business days of the FSO becoming aware of it.
Question 15: In an industrial security information classification scheme, which label typically applies to trade secrets and proprietary formulas?
- Confidential / Proprietary (Correct answer)
- Internal Use Only
- Public
- Top Secret
Correct answer: Confidential / Proprietary
Confidential or Proprietary is the standard commercial classification for sensitive business information like trade secrets that require restricted handling.
Question 16: Multi-factor authentication (MFA) requires users to verify identity using:
- At least two different authentication factors from separate categories (something you know, have, or are) (Correct answer)
- Biometrics only, without any secondary factor
- A password and a security question from the same category
- Two different passwords
Correct answer: At least two different authentication factors from separate categories (something you know, have, or are)
MFA combines factors from different categories—knowledge, possession, and inherence—to ensure one compromised factor does not grant access.
Question 17: A security director is asked to implement two-person integrity (TPI) for accessing a critical asset vault. TPI primarily protects against:
- Accidental equipment damage by a single worker
- External cyber intrusion into vault systems
- Insider threat and collusion by requiring two authorized people to be present simultaneously (Correct answer)
- Environmental hazards such as chemical spills
Correct answer: Insider threat and collusion by requiring two authorized people to be present simultaneously
Two-person integrity requires two authorized individuals to be present for access, preventing a single insider from acting alone and providing mutual oversight to deter insider threats.
Question 18: When a crisis communication plan is activated, the designated spokesperson should:
- Allow multiple executives to speak independently to different outlets
- Provide only confirmed facts and bridge to key messages (Correct answer)
- Decline all media contact until the incident is fully resolved
- Speculate on causes to appear knowledgeable to the press
Correct answer: Provide only confirmed facts and bridge to key messages
Spokespeople must stick to confirmed facts, avoid speculation, and use message bridging techniques to maintain control and credibility during crisis communications.
Question 19: An employee reports that a coworker has been downloading large volumes of proprietary schematics to a personal USB drive. The FIRST security response should be:
- Immediately confront the coworker in front of the team
- Post a notice about USB policies on the bulletin board
- Document the observation and report it to the insider threat officer or security manager (Correct answer)
- Disable the entire facility's USB ports without investigation
Correct answer: Document the observation and report it to the insider threat officer or security manager
Proper reporting to the designated security authority allows a structured investigation without tipping off the subject or compromising evidence.
Question 20: What is the role of crisis communication in maintaining organizational reputation?
- It focuses on covering up the crisis.
- It minimizes transparency.
- It provides accurate updates and reassures stakeholders (Correct answer)
- It delays informing stakeholders.
Correct answer: It provides accurate updates and reassures stakeholders
Crisis communication is essential for maintaining organizational reputation by ensuring transparency and building trust during challenging times. It involves providing timely, accurate updates to stakeholders, which helps manage public perception and demonstrates accountability. Reassuring stakeholders through clear and consistent messaging mitigates panic and fosters confidence in the organization's ability to handle the situation responsibly, thereby protecting its image.
Question 21: What is the role of confidentiality in security policies?
- To increase the level of public access.
- To protect sensitive information from unauthorized access (Correct answer)
- To reduce the use of encryption.
- To limit the number of employees.
Correct answer: To protect sensitive information from unauthorized access
Confidentiality is a core principle of information security, ensuring that sensitive data is accessible only to authorized individuals. Security policies establish clear rules for handling, storing, and transmitting such information, preventing its unauthorized disclosure to those without a legitimate need-to-know. This safeguards privacy, proprietary data, and intellectual property from compromise.
Question 22: What is the first step in the security risk management process?
- Identify and assess risks (Correct answer)
- Monitor security systems.
- Install additional surveillance equipment.
- Implement risk mitigation measures.
Correct answer: Identify and assess risks
The foundational step in any security risk management process is to thoroughly identify all potential threats and vulnerabilities that could impact an organization's assets. This involves understanding what could go wrong, how likely it is to happen, and what the potential consequences would be. Without this initial assessment, effective mitigation strategies cannot be developed.
Question 23: Which type of insider threat actor is typically motivated by ideology rather than financial gain?
- The disgruntled employee seeking revenge
- The ideological spy acting on behalf of a cause or foreign entity (Correct answer)
- The careless employee who accidentally leaks information
- The opportunistic thief stealing for personal enrichment
Correct answer: The ideological spy acting on behalf of a cause or foreign entity
Ideological insiders are motivated by beliefs or loyalty to a cause, making them distinct from financially motivated or careless actors.
Question 24: How does a well-prepared crisis management team impact recovery?
- It improves the organization’s ability to recover quickly (Correct answer)
- It focuses on business closure.
- It causes more confusion during the crisis.
- It delays the crisis response.
Correct answer: It improves the organization’s ability to recover quickly
A well-prepared crisis management team significantly enhances an organization's ability to recover quickly and effectively. Such a team has pre-defined roles, established protocols, and often conducts drills, allowing for a swift and coordinated response when a crisis strikes. This preparedness minimizes confusion, reduces the impact of the crisis, and facilitates a more organized and efficient path back to normal operations, thereby accelerating recovery.
Question 25: The 'need-to-know' principle in personnel security means:
- Access to specific information is granted only when operationally necessary for assigned duties (Correct answer)
- Employees need to know all security procedures regardless of role
- Any cleared employee may access all information at their clearance level
- Managers must know all employees' personal background information
Correct answer: Access to specific information is granted only when operationally necessary for assigned duties
Need-to-know limits access to information to only what is required for a person to perform their specific job functions.
Question 26: When an employee is terminated, which security action should be taken IMMEDIATELY?
- Waiting for HR to file paperwork before notifying IT
- Revoking all logical and physical access simultaneously upon departure (Correct answer)
- Allowing the employee to retain email access to complete handover
- Scheduling a 30-day transition period before revoking access
Correct answer: Revoking all logical and physical access simultaneously upon departure
Simultaneous revocation of all access upon termination prevents a departing employee from exfiltrating data or entering the facility.
Question 27: Which security control is MOST critical when allowing third-party vendors to remotely access ICS/OT systems for maintenance?
- Implementing time-limited, monitored, and audited remote access sessions with least-privilege accounts specific to the maintenance task (Correct answer)
- Using unencrypted direct modem connections for legacy system compatibility
- Allowing vendors to use their own VPN credentials for convenience
- Granting vendors permanent administrative access to reduce service call delays
Correct answer: Implementing time-limited, monitored, and audited remote access sessions with least-privilege accounts specific to the maintenance task
Vendor remote access is a major ICS attack vector; time-limited, monitored sessions with just-in-time access dramatically reduce the risk window.
Question 28: Which population typically receives the MOST targeted security training in an industrial facility due to their elevated access?
- Systems administrators, security managers, and executives with privileged access (Correct answer)
- Cafeteria and janitorial staff
- Marketing and public relations teams
- New employees in their first two weeks
Correct answer: Systems administrators, security managers, and executives with privileged access
Privileged users with elevated access to critical systems pose greater risk and require role-specific training beyond general awareness.
Question 29: A security manager discovers that a former employee's access credentials were used to log in two weeks after termination. This indicates a failure in:
- Fire suppression system maintenance
- Annual penetration testing processes
- Physical perimeter control
- Access termination and offboarding procedures (Correct answer)
Correct answer: Access termination and offboarding procedures
Access that survives beyond an employee's departure indicates the offboarding process failed to revoke credentials in a timely manner.
Question 30: Which security control prevents an employee from reading emails on a personally owned device not approved by the organization?
- Physical security guards at the building entrance
- Mobile Device Management (MDM) with a BYOD policy restriction (Correct answer)
- Antivirus software on company servers
- Data Loss Prevention (DLP)
Correct answer: Mobile Device Management (MDM) with a BYOD policy restriction
MDM combined with a BYOD policy can enforce that only managed, compliant devices can access corporate email and resources.
Question 31: An OT security program should include an industrial asset inventory because:
- Asset inventories are only needed for IT systems, not OT/ICS
- It is required only for financial depreciation accounting purposes
- You cannot protect what you do not know exists—a complete asset inventory is the foundation of any OT security program (Correct answer)
- Inventories are only required when preparing for a regulatory audit
Correct answer: You cannot protect what you do not know exists—a complete asset inventory is the foundation of any OT security program
Without a comprehensive asset inventory, organizations cannot assess exposure, prioritize patching, or detect unauthorized devices on OT networks.
Question 32: A security patch management program is PRIMARILY intended to:
- Improve application performance and add new features
- Remediate known software vulnerabilities before they can be exploited (Correct answer)
- Automate system backups on a scheduled basis
- Track employee software license compliance
Correct answer: Remediate known software vulnerabilities before they can be exploited
Patch management ensures vulnerabilities identified in software are addressed in a timely manner to reduce the attack surface.
Question 33: A facility security manager discovers that an access control system has not been updated in three years. This situation is best classified as which type of risk factor?
- Hazard
- Consequence
- Threat
- Vulnerability (Correct answer)
Correct answer: Vulnerability
An outdated access control system represents a vulnerability — a weakness in the security posture that increases exposure to threats.
Question 34: What is a 'zero-day vulnerability'?
- A vulnerability with no exploits available in any threat database
- A flaw in a zero-trust network architecture
- A vulnerability discovered exactly at midnight
- A software flaw unknown to the vendor for which no patch exists at the time of discovery or exploitation (Correct answer)
Correct answer: A software flaw unknown to the vendor for which no patch exists at the time of discovery or exploitation
Zero-day vulnerabilities are particularly dangerous because defenders have 'zero days' to patch before the flaw can be exploited.
Question 35: An air-gapped network in an industrial environment means:
- The network operates at lower bandwidth to reduce attack surface
- The network is physically isolated with no connections to external or untrusted networks (Correct answer)
- The network uses wireless frequencies exclusively
- The network uses encrypted tunnels to connect to the internet
Correct answer: The network is physically isolated with no connections to external or untrusted networks
An air gap is a physical security measure that prevents a network from connecting to external systems, limiting remote attack vectors.
Question 36: A security risk assessment at an industrial plant identifies 'criticality' of assets. What does criticality PRIMARILY measure?
- The impact on operations or mission if the asset is lost, damaged, or compromised (Correct answer)
- The difficulty of physically securing the asset
- The age and depreciation of the asset
- The replacement cost of an asset
Correct answer: The impact on operations or mission if the asset is lost, damaged, or compromised
Criticality measures how essential an asset is to the organization's mission; a highly critical asset causes severe operational disruption if compromised regardless of its monetary value.
Question 37: What is the purpose of security awareness training?
- To improve employee efficiency.
- To minimize the need for security cameras.
- To help employees recognize and respond to security risks (Correct answer)
- To reduce employee turnover.
Correct answer: To help employees recognize and respond to security risks
Employees are often the first line of defense against security threats, whether physical or cyber. Security awareness training educates them on common risks, best practices, and how to report suspicious activities. This knowledge empowers them to make informed decisions and act as proactive contributors to the organization's overall security posture.
Question 38: In the context of industrial crisis management, 'continuity of operations' (COOP) planning addresses which core concern?
- Maintaining profitability during normal operations
- Sustaining essential functions when primary facilities or systems are unavailable (Correct answer)
- Documenting losses for insurance reimbursement
- Training employees on evacuation procedures
Correct answer: Sustaining essential functions when primary facilities or systems are unavailable
COOP planning ensures that critical operations continue or resume rapidly when normal infrastructure is disrupted by identifying alternate sites, personnel, and resources.
Question 39: What does 'triage' mean in the context of security incident management?
- Escalating every incident to executive leadership immediately
- Documenting every detail before taking any action
- Quickly assessing and prioritizing incidents based on severity and potential impact to allocate response resources (Correct answer)
- Eliminating all infected systems from the network immediately
Correct answer: Quickly assessing and prioritizing incidents based on severity and potential impact to allocate response resources
Triage allows security teams to focus limited resources on the most critical incidents first by rapidly assessing severity.
Question 40: Under the ISP framework, what is 'piggybacking' in the context of access control?
- Using two-factor authentication simultaneously
- Installing a secondary badge reader on an existing door
- Mounting cameras on fence posts
- An authorized person allowing an unauthorized person to follow them through a controlled entry (Correct answer)
Correct answer: An authorized person allowing an unauthorized person to follow them through a controlled entry
Piggybacking (also called tailgating) occurs when an unauthorized person exploits an authorized person's access to pass through a secured door without presenting valid credentials.
Question 41: In an industrial security context, 'data at rest' refers to:
- Information verbally communicated between employees
- Data displayed on a monitor during active use
- Stored data on drives, servers, or removable media not currently in transit (Correct answer)
- Information actively being transmitted across a network
Correct answer: Stored data on drives, servers, or removable media not currently in transit
Data at rest encompasses all stored information that is not actively moving through a network or being processed.
Question 42: What is the role of incident response planning in security compliance?
- To ensure a coordinated response and compliance with regulations (Correct answer)
- To reduce the number of incidents.
- To eliminate the need for security audits.
- To delay incident response.
Correct answer: To ensure a coordinated response and compliance with regulations
Incident response planning outlines the structured steps an organization will take when a security incident occurs. In the context of compliance, it ensures that the response adheres to legal and regulatory mandates for reporting, data breach notification, and evidence preservation. A well-defined plan minimizes legal exposure, facilitates a structured recovery, and demonstrates due diligence to regulatory bodies.
Question 43: What is the primary purpose of CPTED (Crime Prevention Through Environmental Design) in industrial security?
- Designing the physical environment to deter criminal activity naturally (Correct answer)
- Replacing human guards with automated systems
- Training employees in self-defense techniques
- Installing the maximum number of cameras possible
Correct answer: Designing the physical environment to deter criminal activity naturally
CPTED uses environmental design principles—lighting, sightlines, landscaping, and space management—to naturally discourage criminal behavior without purely relying on hardware.
Question 44: A company's written security policy conflicts with a new DCSA regulation. Which takes precedence?
- The policy in effect at the time the facility clearance was originally granted
- Whichever policy is more restrictive, regardless of source
- The company policy, because it is more specific to the facility's operations
- The DCSA regulation, because federal regulations supersede internal company policies (Correct answer)
Correct answer: The DCSA regulation, because federal regulations supersede internal company policies
Federal regulations like NISPOM have the force of law and always supersede internal company policies; company policies must be updated to reflect new regulatory requirements.
Question 45: Travel briefings for employees visiting high-threat countries should include information on:
- Airline loyalty program benefits for frequent travelers
- Foreign intelligence collection techniques, communication security, and procedures for reporting suspicious contacts during travel (Correct answer)
- Currency exchange rates and tourist attractions
- Visa application fees and baggage allowance policies
Correct answer: Foreign intelligence collection techniques, communication security, and procedures for reporting suspicious contacts during travel
Travel briefings prepare employees to recognize and counter foreign intelligence threats that commonly target business travelers in high-threat countries.
Question 46: What is the role of mitigation strategies in security risk management?
- To reduce the impact of identified risks (Correct answer)
- To increase costs for security measures.
- To delay security actions.
- To eliminate all security threats.
Correct answer: To reduce the impact of identified risks
Mitigation strategies are specific actions or controls implemented to lessen the likelihood or severity of a security incident once a risk has been identified. While it's often impossible to eliminate all risks, mitigation aims to bring them down to an acceptable level. This involves implementing safeguards, policies, and procedures to minimize potential harm.
Question 47: Which artifact is MOST useful in reconstructing the timeline of a cyber incident on a Windows system?
- Desktop wallpaper settings
- Browser bookmarks folder
- Printer queue history
- Windows Event Logs (Security, System, Application) (Correct answer)
Correct answer: Windows Event Logs (Security, System, Application)
Windows Event Logs record system events with timestamps, providing the chronological record investigators need to reconstruct an incident.
Question 48: Which lighting standard is commonly referenced for industrial perimeter security to ensure adequate illumination for camera systems and guard patrol?
- Minimum 0.2 foot-candles at grade level along the perimeter (Correct answer)
- Flood lighting at 50 foot-candles everywhere on site
- Minimum 5 foot-candles at all exterior doors only
- No standard exists; lighting is purely discretionary
Correct answer: Minimum 0.2 foot-candles at grade level along the perimeter
Industry guidelines (including ASIS standards) typically recommend a minimum of 0.2 foot-candles at grade along perimeters to support detection by cameras and patrol.
Question 49: Under NISPOM (32 CFR Part 117), Facility Security Officers (FSOs) are required to provide security training to cleared employees:
- Only during the facility's annual security self-inspection
- Only if the employee requests it
- Prior to granting initial access to classified information and at least annually thereafter (Correct answer)
- Exclusively through government-run training programs
Correct answer: Prior to granting initial access to classified information and at least annually thereafter
NISPOM mandates initial training before classified access and annual refresher training as a condition of maintaining a facility clearance.
Question 50: A security manager at a petrochemical plant wants to evaluate the likelihood and consequence of a chlorine gas release scenario. Which analytical tool is most appropriate for mapping all potential failure pathways leading to that event?
- Fault tree analysis (Correct answer)
- Cost-benefit analysis
- SWOT analysis
- Delphi panel
Correct answer: Fault tree analysis
Fault tree analysis uses a top-down, deductive logic diagram to identify all combinations of component failures or errors that could lead to a defined undesired event.
Question 51: Which legal doctrine allows the government to withhold classified information in civil litigation to protect national security?
- Executive privilege
- Sovereign immunity
- Qualified immunity
- The state secrets privilege (Correct answer)
Correct answer: The state secrets privilege
The state secrets privilege allows the government to exclude evidence from court proceedings when disclosure would harm national security.
Question 52: Mitigating an employee's financial vulnerability to espionage recruitment can BEST be accomplished by:
- Requiring employees to submit monthly financial statements
- Monitoring all personal bank accounts of cleared employees
- Providing access to financial counseling and encouraging early self-reporting of financial difficulties (Correct answer)
- Denying clearances to all employees with any debt
Correct answer: Providing access to financial counseling and encouraging early self-reporting of financial difficulties
Financial counseling and a non-punitive self-reporting culture reduce the exploitation window before a vulnerability becomes a national security risk.
Question 53: What is the purpose of a security clearance adjudication?
- To assign an employee's access level based solely on job title
- To terminate employees who fail polygraph examinations
- To determine whether granting access is clearly consistent with national or industrial security interests (Correct answer)
- To issue an employee identification badge
Correct answer: To determine whether granting access is clearly consistent with national or industrial security interests
Adjudication evaluates all available information to decide if an individual's access is consistent with security interests.
Question 54: An adversarial simulation in which a team attempts to bypass physical and electronic security controls to reach a target within a facility is called a:
- Gap analysis
- Security survey
- Red team assessment (Correct answer)
- Tabletop exercise
Correct answer: Red team assessment
A red team assessment employs adversarial tactics to test physical, electronic, and human security controls under realistic attack conditions.
Question 55: When investigating a suspected theft of trade secrets, which type of specialist should typically be involved?
- Customer service manager
- Marketing analyst
- Legal counsel with IP and employment law expertise (Correct answer)
- Payroll administrator
Correct answer: Legal counsel with IP and employment law expertise
IP theft investigations have significant legal dimensions requiring attorneys familiar with trade secret law, employment agreements, and evidence handling.
Question 56: What is the importance of regular security audits?
- To reduce security costs.
- To increase security breaches.
- To ensure security measures are working and identify areas for improvement (Correct answer)
- To limit employee involvement.
Correct answer: To ensure security measures are working and identify areas for improvement
Regular security audits are essential for continuously assessing the effectiveness of existing security controls and identifying any vulnerabilities or outdated practices. They help ensure that security measures are functioning as intended and highlight areas that require improvement or updating. This proactive evaluation allows organizations to adapt and strengthen their security posture against evolving threats.
Question 57: What is the purpose of a security risk assessment in facility protection?
- To reduce the number of employees.
- To monitor employee attendance.
- To identify potential security risks and inform protection strategies (Correct answer)
- To increase the amount of physical security systems.
Correct answer: To identify potential security risks and inform protection strategies
A security risk assessment systematically identifies potential threats, vulnerabilities, and the likelihood and impact of security incidents. By understanding these risks, organizations can prioritize and implement appropriate security measures and allocate resources effectively. This ensures that protection strategies are informed, effective, and tailored to the specific risks faced by the facility.
Question 58: An industrial security investigation MUST remain within which legal boundary when interviewing employees?
- Investigators can review employee medical records without consent
- Employees must be informed of their rights, and interviews must comply with applicable labor and employment law (Correct answer)
- Investigators may use physical coercion if the employee refuses to cooperate
- Employees may be detained indefinitely pending investigation outcomes
Correct answer: Employees must be informed of their rights, and interviews must comply with applicable labor and employment law
Industrial security investigations must respect labor laws, privacy rights, and employee rights to counsel to avoid legal liability.
Question 59: What is the primary purpose of network segmentation in an industrial facility?
- To reduce the number of network switches required
- To allow all devices to share a common IP address range
- To limit the lateral movement of attackers and contain breaches to isolated network zones (Correct answer)
- To increase internet bandwidth for all users
Correct answer: To limit the lateral movement of attackers and contain breaches to isolated network zones
Network segmentation divides infrastructure into zones so a compromise in one area cannot easily spread to critical operational systems.
Question 60: A 'continuous evaluation' program in personnel security is designed to:
- Monitor cleared individuals for concerning behaviors between periodic reinvestigations (Correct answer)
- Replace the initial security clearance investigation
- Evaluate employee performance on a monthly basis
- Conduct a new full background investigation every five years
Correct answer: Monitor cleared individuals for concerning behaviors between periodic reinvestigations
Continuous evaluation uses automated record checks to flag relevant derogatory information between reinvestigations without waiting for a scheduled review.
Question 61: When conducting a vulnerability assessment of an OT/ICS environment, which approach is PREFERRED over active network scanning?
- Running automated vulnerability scanners at maximum speed during peak production hours
- Physically unplugging all devices to examine them individually
- Conducting assessments only on IT systems while excluding OT networks
- Passive network monitoring and asset inventory using non-intrusive methods to avoid disrupting real-time control processes (Correct answer)
Correct answer: Passive network monitoring and asset inventory using non-intrusive methods to avoid disrupting real-time control processes
Active scanning can crash legacy OT devices or disrupt time-sensitive control processes, making passive monitoring the preferred approach in live OT environments.
Question 62: A mass casualty incident at an industrial facility overwhelms on-site medical resources. The correct triage system used by first responders to rapidly categorize victims is:
- CBRN decontamination protocol
- SALUTE reporting
- ICS Form 201 documentation
- START (Simple Triage and Rapid Treatment) (Correct answer)
Correct answer: START (Simple Triage and Rapid Treatment)
START triage categorizes victims into immediate, delayed, minimal, and expectant groups in under 60 seconds per patient to maximize survivability with limited resources.
Question 63: Which type of malware is specifically designed to remain hidden while granting an attacker persistent, privileged access to a system?
- Adware
- Worm
- Ransomware
- Rootkit (Correct answer)
Correct answer: Rootkit
Rootkits are designed to hide their presence and provide an attacker with sustained administrative access to a compromised system.
Question 64: Which approach to cybersecurity assumes that no user, device, or network segment should be trusted by default, even inside the perimeter?
- Defense-in-depth
- Security through obscurity
- Perimeter-based security
- Zero Trust Architecture (Correct answer)
Correct answer: Zero Trust Architecture
Zero Trust operates on the principle of 'never trust, always verify,' requiring continuous authentication and authorization regardless of network location.
Question 65: During an industrial facility crisis, the Incident Command System (ICS) designates a single person as Incident Commander primarily to:
- Prevent employees from contacting media
- Reduce costs by eliminating multiple managers
- Satisfy OSHA regulatory requirements only
- Ensure unified command and clear accountability (Correct answer)
Correct answer: Ensure unified command and clear accountability
ICS uses a single Incident Commander to establish unified command, clear span of control, and unambiguous accountability during emergencies.
Question 66: A 'security baseline' in an industrial information security program refers to:
- The starting point for a risk assessment before any controls are applied
- A benchmark test for measuring network throughput
- The minimum acceptable configuration and security controls applied uniformly to all systems (Correct answer)
- The highest security standard applied only to classified networks
Correct answer: The minimum acceptable configuration and security controls applied uniformly to all systems
A security baseline defines the minimum set of controls every system must have, ensuring a consistent security floor across the organization.
Question 67: Which perimeter barrier type provides the HIGHEST level of vehicle impact resistance for industrial facilities?
- Concrete jersey barriers
- Anti-ram bollards rated to K12 standard (Correct answer)
- Wooden post-and-rail fence
- Chain-link fence with barbed wire
Correct answer: Anti-ram bollards rated to K12 standard
K12-rated anti-ram bollards are engineered to stop a 15,000-lb vehicle traveling at 50 mph, providing the highest certified vehicle impact resistance.
Question 68: A critical industrial facility learns that its SCADA software vendor will reach end-of-life (EOL) in six months with no patches thereafter. What is the MOST appropriate response?
- Immediately shut down all SCADA systems
- Request the vendor extend support indefinitely at no cost
- Continue operations with the EOL software and monitor for issues
- Develop a migration plan to supported software while implementing compensating controls during transition (Correct answer)
Correct answer: Develop a migration plan to supported software while implementing compensating controls during transition
A structured migration plan with compensating controls (such as enhanced monitoring and network segmentation) addresses the risk while maintaining operational continuity during the transition.
Question 69: A termination security briefing (debriefing) of a cleared employee should PRIMARILY cover:
- Future employment opportunities within the company
- Employee benefits continuation options (COBRA)
- Continuing obligations to protect classified information and prohibited post-employment disclosures (Correct answer)
- Performance review documentation
Correct answer: Continuing obligations to protect classified information and prohibited post-employment disclosures
Termination debriefings remind departing cleared employees that their security obligations do not end with employment and may be lifelong.
Question 70: Which clause in a vendor contract BEST helps protect an organization if a supplier experiences a security incident?
- Exclusivity clause
- Net-30 payment terms clause
- Force majeure clause
- Security breach notification requirement clause (Correct answer)
Correct answer: Security breach notification requirement clause
A security breach notification requirement obligates the vendor to promptly inform the organization of incidents, enabling timely response and mitigation of downstream impacts.
Question 71: An ISP candidate is reviewing access control lists. Who is responsible for defining WHAT resources a user may access in a role-based access control (RBAC) system?
- The third-party security vendor
- The data/resource owner or asset custodian (Correct answer)
- The system administrator acting as the data owner's proxy
- The end user based on their preference
Correct answer: The data/resource owner or asset custodian
In RBAC, the data owner or asset custodian determines access rights; administrators implement those rights in the system, but ownership of the decision rests with the resource owner.
Question 72: Under ISP principles, 'target hardening' refers to:
- Increasing the frequency of security audits
- Making an asset more difficult or costly to attack by adding physical and procedural barriers (Correct answer)
- Psychologically preparing security staff for high-stress incidents
- Hardening digital systems against cyberattacks only
Correct answer: Making an asset more difficult or costly to attack by adding physical and procedural barriers
Target hardening involves increasing physical and procedural barriers—locks, reinforced doors, access controls, lighting—to raise the effort and risk required for an attacker to succeed.
Question 73: How can perimeter security help protect a facility?
- By reducing security surveillance.
- By increasing facility use for non-security purposes.
- By blocking unauthorized access and enhancing protection (Correct answer)
- By increasing the number of security guards.
Correct answer: By blocking unauthorized access and enhancing protection
Perimeter security establishes a clear boundary around a facility, acting as the first line of defense against external threats. Elements like fences, gates, and intrusion detection systems are designed to detect, deter, and delay unauthorized entry. This helps to control access to the entire property and provides early warning of potential security breaches.
Question 74: What is the key distinction between a 'security violation' and a 'security deviation' under NISPOM?
- A violation is a confirmed unauthorized disclosure; a deviation is a procedural failure that did not necessarily compromise information (Correct answer)
- A deviation is more serious and requires DCSA reporting; a violation can be handled internally
- There is no distinction — the terms are interchangeable
- A violation involves classified information; a deviation involves only unclassified information
Correct answer: A violation is a confirmed unauthorized disclosure; a deviation is a procedural failure that did not necessarily compromise information
A security deviation is a procedural failure (e.g., open vault door), while a security violation involves an actual or suspected unauthorized disclosure of classified information.
Question 75: A hazardous material release at an industrial site triggers shelter-in-place orders. Which action should be taken FIRST?
- Distribute personal protective equipment to all employees
- Seal air intakes and move personnel to interior rooms (Correct answer)
- Evacuate all personnel immediately through the main gate
- Call local fire department before taking any protective action
Correct answer: Seal air intakes and move personnel to interior rooms
Shelter-in-place requires immediately sealing ventilation pathways and moving personnel to protected interior areas before any outward-facing actions.
Question 76: What is the role of security audits in ensuring compliance?
- To increase security costs.
- To reduce the number of security cameras.
- To ensure security measures meet legal standards and identify gaps (Correct answer)
- To monitor employee productivity.
Correct answer: To ensure security measures meet legal standards and identify gaps
Security audits specifically assess whether an organization's security practices align with relevant laws, regulations, and industry standards. They help identify any deviations or gaps in compliance, allowing the organization to implement corrective actions before they lead to penalties or legal issues. This proactive approach ensures that security measures meet legal requirements and helps maintain a strong compliance posture.
Question 77: The concept of 'functional safety' in an industrial security context refers to:
- The correct functioning of safety-critical systems that depend on automated protective actions to prevent hazardous conditions (Correct answer)
- Ensuring the security team's workstations are ergonomically designed
- Annual safety drills for fire evacuations
- Personal protective equipment requirements for maintenance staff
Correct answer: The correct functioning of safety-critical systems that depend on automated protective actions to prevent hazardous conditions
Functional safety ensures safety instrumented systems (SIS) operate correctly to automatically protect personnel and equipment from dangerous process conditions.
Question 78: What is the purpose of a 'clear zone' on both sides of an industrial perimeter fence?
- To provide a decorative landscaping buffer
- To create a drainage channel for stormwater
- To designate a fire department access lane
- To eliminate concealment and allow clear observation of anyone approaching or crossing the fence (Correct answer)
Correct answer: To eliminate concealment and allow clear observation of anyone approaching or crossing the fence
Clear zones (typically 20 feet on each side) remove vegetation and obstructions so guards, patrols, and cameras have unobstructed visibility of the fence line.
Question 79: The 'lessons learned' phase of incident response primarily aims to:
- Archive the incident report and close the ticket permanently
- Notify external media about the security breach
- Identify what worked, what failed, and how to improve processes and controls to prevent recurrence (Correct answer)
- Assign blame and initiate disciplinary actions against responsible personnel
Correct answer: Identify what worked, what failed, and how to improve processes and controls to prevent recurrence
Lessons learned transform incident experience into measurable improvements in security posture, policy, and training.
Question 80: In the context of industrial security risk management, 'consequence analysis' is primarily used to:
- Determine the probability that a control will fail
- Estimate the severity of harm or loss resulting from a specific incident scenario (Correct answer)
- Calculate the return on investment of security expenditures
- Identify the threat actors most likely to target a facility
Correct answer: Estimate the severity of harm or loss resulting from a specific incident scenario
Consequence analysis evaluates the potential human, financial, operational, and reputational impact of a security event occurring at a facility.
Question 81: A security investigator discovers a suspicious USB drive in a secured area. The FIRST action should be:
- Plug it into a computer to identify its contents
- Photograph it in place, document its location, and secure it as evidence without inserting it into any system (Correct answer)
- Discard it to prevent further risk to the facility
- Hand it to the nearest employee to identify the owner
Correct answer: Photograph it in place, document its location, and secure it as evidence without inserting it into any system
Documenting and preserving the device without connecting it protects both evidence integrity and facility systems from potential malware.
Question 82: During an active shooter event at an industrial facility, the widely recommended response protocol for employees is:
- Lock down and wait for law enforcement without moving
- Gather coworkers and exit together in a single group
- Run, Hide, Fight — in that priority order (Correct answer)
- Attempt to negotiate with the shooter to de-escalate
Correct answer: Run, Hide, Fight — in that priority order
The Run-Hide-Fight protocol, endorsed by DHS and ALERRT, prioritizes evacuation, then barricading, then fighting as a last resort when no other options exist.
Question 83: How do physical barriers contribute to facility protection?
- By blocking unauthorized access to sensitive areas (Correct answer)
- By improving facility aesthetics.
- By increasing the amount of security staff.
- By reducing employee productivity.
Correct answer: By blocking unauthorized access to sensitive areas
Physical barriers, such as fences, walls, gates, and reinforced doors, create tangible obstacles to entry. They are specifically designed to delay, deter, or prevent unauthorized individuals from gaining access to a facility or specific secure zones within it. These barriers form a crucial first line of defense in a layered security strategy.
Question 84: What is the purpose of maintaining an approved vendor list (AVL) in an industrial security program?
- To track vendor invoice payment status
- To publicly disclose all vendors for transparency
- To identify vendors eligible for volume discounts
- To restrict procurement to suppliers who have been vetted and approved based on security and quality criteria (Correct answer)
Correct answer: To restrict procurement to suppliers who have been vetted and approved based on security and quality criteria
An AVL limits procurement to pre-vetted suppliers, reducing the risk of introducing unvetted or compromised components into the supply chain.
Question 85: Which phase of an incident response plan involves returning systems to normal operations after a security event?
- Identification
- Lessons Learned
- Containment
- Recovery (Correct answer)
Correct answer: Recovery
The recovery phase restores affected systems and verifies they are clean and functional before returning them to production.
Question 86: Which component of the risk equation directly measures the probability that a specific threat will materialize within a defined time period?
- Impact severity
- Asset value
- Vulnerability rating
- Threat likelihood (Correct answer)
Correct answer: Threat likelihood
Threat likelihood (or probability) quantifies how often or how probably a specific threat event will occur within a given timeframe.
Question 87: Which type of glass is MOST appropriate for an industrial facility's entry lobby where forced-entry resistance is required?
- Laminated security glass with polycarbonate interlayer (Correct answer)
- Standard float glass
- Tinted UV-protective glass
- Tempered glass
Correct answer: Laminated security glass with polycarbonate interlayer
Laminated security glass bonds multiple layers with a polycarbonate or PVB interlayer that holds shards together under impact, resisting forced entry far longer than tempered or float glass.
Question 88: A phishing email that targets a specific senior executive is known as:
- Smishing
- Spear phishing
- Whaling (Correct answer)
- Vishing
Correct answer: Whaling
Whaling is a form of spear phishing specifically aimed at high-value targets such as executives or key decision-makers.
Question 89: An industrial facility uses proximity card readers. Which attack method specifically targets these systems by covertly reading and cloning a valid card from a distance?
- Relay/skimming attack using an RFID reader (Correct answer)
- Dumpster diving
- Shoulder surfing
- Social engineering the receptionist
Correct answer: Relay/skimming attack using an RFID reader
RFID skimming uses a concealed reader to capture card data wirelessly, enabling an attacker to clone a legitimate credential without the cardholder's knowledge.
Question 90: When must a security incident be reported to the relevant government authority in a cleared industrial facility?
- Only after a full internal investigation is complete
- Whenever a reportable security incident occurs, per the facility's reporting requirements and DD Form 577 obligations (Correct answer)
- Only if classified information was confirmed as compromised
- Never—all incidents are handled internally without government notification
Correct answer: Whenever a reportable security incident occurs, per the facility's reporting requirements and DD Form 577 obligations
Government-cleared facilities are obligated to report security incidents to their Cognizant Security Agency (CSA) as specified in their facility clearance agreement.
Question 91: Which of the following BEST mitigates the risk of a software supply chain attack, such as the SolarWinds-type attack?
- Implementing software bill of materials (SBOM) reviews and code integrity verification before deployment (Correct answer)
- Banning all software updates from third-party vendors
- Using a single antivirus product on all systems
- Requiring vendors to use only open-source software
Correct answer: Implementing software bill of materials (SBOM) reviews and code integrity verification before deployment
An SBOM provides a detailed inventory of software components, allowing organizations to identify vulnerable or compromised components, while code integrity verification (e.g., hash checking) detects unauthorized modifications.
Question 92: What distinguishes a 'passive' infrared (PIR) motion detector from an 'active' infrared detector in industrial perimeter protection?
- PIR detects changes in heat signatures; active IR uses a beam that triggers an alarm when broken (Correct answer)
- PIR emits a microwave signal; active IR uses sound waves
- PIR requires a power source; active IR is battery-free
- PIR works only indoors; active IR works only outdoors
Correct answer: PIR detects changes in heat signatures; active IR uses a beam that triggers an alarm when broken
PIR sensors detect changes in infrared (heat) energy from moving objects, while active IR systems emit a beam and trigger an alarm when that beam is interrupted.
Question 93: What does 'two-person integrity' (TPI) primarily protect against in a personnel security context?
- A single insider acting alone to commit theft or sabotage of critical assets (Correct answer)
- Cyber intrusions from external threat actors
- Unauthorized photography on the production floor
- Physical injuries during heavy-lifting tasks
Correct answer: A single insider acting alone to commit theft or sabotage of critical assets
TPI requires two authorized individuals to be present during access to sensitive areas or materials, preventing unilateral insider action.
Question 94: In incident response, 'scope creep' during the containment phase refers to:
- Expanding the investigation to include unrelated systems unnecessarily, prolonging downtime (Correct answer)
- Increasing the severity rating of an incident after new evidence is found
- Documenting more detail than required in the incident report
- Adding additional security analysts to speed up the investigation
Correct answer: Expanding the investigation to include unrelated systems unnecessarily, prolonging downtime
Scope creep in containment can take more systems offline than necessary, causing excessive business disruption beyond what the incident warrants.
Question 95: An industrial facility's Emergency Operations Center (EOC) differs from the on-scene command post in that the EOC:
- Is located at the point of the incident for direct oversight
- Provides strategic coordination and resource support removed from the hazard area (Correct answer)
- Replaces the Incident Commander's authority during the crisis
- Is responsible solely for public affairs and media management
Correct answer: Provides strategic coordination and resource support removed from the hazard area
The EOC operates at the strategic level, coordinating logistics, policy decisions, and multi-agency support while the command post handles on-scene tactical operations.
Question 96: In a cleared facility, a 'security violation' is BEST defined as:
- A fire code infraction discovered during an audit
- Any act or omission that is contrary to established security regulations, regardless of intent (Correct answer)
- Any action that results in employee injury on the job
- Only intentional acts of espionage by cleared personnel
Correct answer: Any act or omission that is contrary to established security regulations, regardless of intent
Security violations include both deliberate and negligent breaches of security requirements and must be reported regardless of intent.
Question 97: In industrial emergency planning, a 'tabletop exercise' is MOST useful for:
- Testing physical evacuation routes and timing
- Training first responders in hands-on emergency techniques
- Evaluating equipment readiness and maintenance status
- Discussing scenario-based decisions without deploying resources (Correct answer)
Correct answer: Discussing scenario-based decisions without deploying resources
Tabletop exercises allow key personnel to verbally walk through their roles in a scenario, identifying plan gaps without the cost or disruption of a full-scale drill.
Question 98: Which process is used to verify that employees only retain access rights appropriate to their current role?
- Visitor log auditing
- Periodic reinvestigation
- Access recertification or entitlement review (Correct answer)
- Annual security awareness training
Correct answer: Access recertification or entitlement review
Access recertification (entitlement review) is the formal process of confirming that each user's permissions still match their job requirements.
Question 99: What is the primary function of a 'security operations center' (SOC) in a large industrial facility?
- Centrally monitoring alarms, cameras, and access control events and coordinating security responses (Correct answer)
- Storing classified documents securely
- Conducting background investigations on new hires
- Managing employee payroll and HR functions
Correct answer: Centrally monitoring alarms, cameras, and access control events and coordinating security responses
An SOC serves as the nerve center for real-time monitoring of all security systems and coordinating responses to alarms, incidents, and anomalies across the facility.
Question 100: In the context of industrial security, what is a 'security baseline'?
- The height specification for perimeter fencing
- A record of all past security incidents at the facility
- The initial cost estimate for installing security systems
- The minimum acceptable level of security measures required across all facility areas (Correct answer)
Correct answer: The minimum acceptable level of security measures required across all facility areas
A security baseline defines the minimum set of security controls and measures that must be in place at all times to meet regulatory, organizational, or risk-based requirements.
Question 101: Pre-employment polygraph examinations in the industrial security context are PRIMARILY used to:
- Measure psychological fitness for high-stress roles
- Replace background investigations entirely
- Detect deception regarding undisclosed past activities relevant to suitability (Correct answer)
- Provide legally admissible evidence in court
Correct answer: Detect deception regarding undisclosed past activities relevant to suitability
Polygraphs are used as an investigative tool to surface undisclosed information, not to replace full background checks or provide court evidence.
Question 102: Why is incident response planning important in security risk management?
- To ensure a coordinated and effective response to security incidents (Correct answer)
- To avoid making security decisions.
- To delay response times.
- To increase the number of security breaches.
Correct answer: To ensure a coordinated and effective response to security incidents
Incident response planning provides a structured framework for how an organization will react to a security breach or event. A well-defined plan ensures that all necessary steps are taken in a timely and organized manner, minimizing damage, facilitating recovery, and maintaining business continuity. It outlines roles, responsibilities, and procedures, preventing chaos during a crisis.
Question 103: Which security risk management concept requires that countermeasures be proportional to the level of risk they are intended to address?
- Proportionality of response (Correct answer)
- Defense in depth
- Risk transfer
- Principle of least privilege
Correct answer: Proportionality of response
Proportionality of response ensures that security investments and countermeasures are appropriately scaled to the magnitude of the risk, avoiding under- or over-investment.
Question 104: Which U.S. government agency is the primary authority for protecting critical infrastructure cybersecurity and coordinates sector-specific agencies?
- Department of Justice (DOJ)
- Federal Bureau of Investigation (FBI)
- Cybersecurity and Infrastructure Security Agency (CISA) (Correct answer)
- National Security Agency (NSA)
Correct answer: Cybersecurity and Infrastructure Security Agency (CISA)
CISA leads national efforts to understand, manage, and reduce risk to cyber and physical infrastructure across the 16 critical infrastructure sectors.
Question 105: Stuxnet is historically significant in ICS security because it demonstrated that:
- Nuclear power plants are immune to cyberattack due to physical isolation
- Cyber operations against industrial systems require nation-state resources and are therefore rare
- SCADA vulnerabilities are only exploitable from within the facility network
- Air-gapped industrial control systems can be compromised through physical media, causing real-world physical damage (Correct answer)
Correct answer: Air-gapped industrial control systems can be compromised through physical media, causing real-world physical damage
Stuxnet proved that air gaps can be crossed via infected USB drives and that malware can cause physical destruction to industrial equipment.
Question 106: A 'tabletop exercise' in incident response is BEST described as:
- A performance review of the security team's annual metrics
- A discussion-based exercise where participants walk through a scenario to evaluate plans and decision-making (Correct answer)
- An unannounced drill designed to test employee reaction without prior notice
- A live simulation where physical intrusion attempts are made on the facility
Correct answer: A discussion-based exercise where participants walk through a scenario to evaluate plans and decision-making
Tabletop exercises are low-cost, discussion-based sessions that test plans and communication without disrupting operations.
Question 107: Which document formally communicates the findings of a security risk assessment to organizational leadership and recommends prioritized corrective actions?
- Standard operating procedure
- Incident action plan
- Emergency operations plan
- Security risk assessment report (Correct answer)
Correct answer: Security risk assessment report
A security risk assessment report presents identified risks, their evaluation, and prioritized recommendations to inform decision-makers on resource allocation.
Question 108: An industrial security professional is reviewing a vendor's security self-assessment. Which of the following responses would be the GREATEST red flag?
- The vendor references NIST SP 800-53 controls
- The vendor uses a third-party data center
- The vendor cannot provide evidence of any security policies, procedures, or past audits (Correct answer)
- The vendor has fewer than 50 employees
Correct answer: The vendor cannot provide evidence of any security policies, procedures, or past audits
The inability to provide documented security policies, procedures, or audit history suggests the vendor has no established security program, representing a significant risk.
Question 109: How can risk assessments help in preventing security breaches?
- By reducing the number of access points.
- By identifying and addressing potential threats and vulnerabilities (Correct answer)
- By increasing the frequency of security patrols.
- By increasing the number of security personnel.
Correct answer: By identifying and addressing potential threats and vulnerabilities
Risk assessments systematically pinpoint weaknesses in an organization's security posture and potential external or internal dangers. By understanding these threats and vulnerabilities, organizations can proactively implement targeted controls and measures to prevent breaches before they occur. This proactive approach is crucial for robust security.
Question 110: During an industrial facility lockdown, the FIRST priority of security personnel should be:
- Gathering evidence of the threat
- Accounting for all personnel and securing entry points (Correct answer)
- Evacuating all assets to an offsite location
- Contacting the media to prevent panic
Correct answer: Accounting for all personnel and securing entry points
Personnel accountability and securing entry/exit points to control movement are the immediate priorities during a facility lockdown to protect life and prevent further threat infiltration.
Question 111: The principle of 'least privilege' in cybersecurity means:
- Granting users the maximum access possible to avoid productivity delays
- Applying security controls only to the most critical systems
- Allowing all administrators unrestricted access for efficiency
- Giving users only the minimum access rights needed to perform their job functions (Correct answer)
Correct answer: Giving users only the minimum access rights needed to perform their job functions
Least privilege minimizes the potential damage from accidents, errors, or attacks by limiting what any single account can access or modify.
Question 112: What is the primary purpose of a security awareness training program in an industrial security context?
- To fulfill a contractual billing requirement to the government
- To qualify employees for access to higher classification levels
- To serve as a substitute for background investigations
- To ensure employees recognize threats and understand their security responsibilities (Correct answer)
Correct answer: To ensure employees recognize threats and understand their security responsibilities
Security awareness training ensures all personnel understand threats like insider threats, social engineering, and their duty to protect classified information.
Question 113: Which behavioral indicator is most commonly associated with a potential malicious insider?
- Taking vacation shortly after a performance review
- Working overtime during a major project
- Requesting additional training on new equipment
- Unexplained affluence inconsistent with salary (Correct answer)
Correct answer: Unexplained affluence inconsistent with salary
Unexplained wealth that cannot be reconciled with an employee's known salary is a classic red flag for theft or espionage.
Question 114: During a facility security survey, a consultant recommends 'natural surveillance.' This refers to:
- Deploying undercover guards dressed as workers
- Positioning windows, lighting, and landscaping so legitimate users can observe activity (Correct answer)
- Installing hidden cameras in natural-looking housings
- Using wildlife cameras to monitor perimeter areas
Correct answer: Positioning windows, lighting, and landscaping so legitimate users can observe activity
Natural surveillance maximizes visibility of people and spaces through thoughtful design of windows, open sightlines, and lighting so occupants and passersby deter crime.
Question 115: What is the role of lighting in facility protection?
- To reduce energy consumption.
- To improve workplace morale.
- To improve employee comfort.
- To enhance security by increasing visibility and deterring crime (Correct answer)
Correct answer: To enhance security by increasing visibility and deterring crime
Proper lighting eliminates dark spots and shadows, which can be exploited by intruders to conceal their activities. Increased visibility makes it harder for unauthorized individuals to approach or operate undetected, thereby deterring criminal activity. It also allows surveillance systems to function more effectively and helps security personnel identify potential threats.
Question 116: Social engineering targeting employees is BEST countered by:
- Ongoing security awareness training and clear reporting procedures (Correct answer)
- Requiring managers to approve every employee decision
- Installing email filters that block all external messages
- Restricting all employee communication with external parties
Correct answer: Ongoing security awareness training and clear reporting procedures
Awareness training equips employees to recognize social engineering tactics and empowers them to report suspicious contacts.
Question 117: Which assessment methodology involves attempting to defeat security measures through simulated unauthorized access attempts, often unannounced to site staff?
- Gap analysis audit
- Red team / adversarial penetration test (Correct answer)
- Tabletop exercise
- Business impact analysis
Correct answer: Red team / adversarial penetration test
A red team or penetration test simulates real-world attacks against physical and procedural controls, often without staff foreknowledge, to reveal actual vulnerabilities under realistic conditions.
Question 118: What is the primary goal of physical security in facility protection?
- To minimize employee involvement in security.
- To protect facilities and assets from physical threats (Correct answer)
- To reduce energy consumption.
- To increase facility profits.
Correct answer: To protect facilities and assets from physical threats
Physical security is specifically designed to protect tangible assets, personnel, and the physical environment from harm. Its primary objective is to prevent unauthorized access, theft, vandalism, and other physical threats that could disrupt operations or compromise safety. This ensures the integrity and continuous operation of the facility and its valuable contents.
Question 119: What is the role of surveillance systems in physical security?
- To increase the cost of security systems.
- To monitor and deter unauthorized activities (Correct answer)
- To reduce employee morale.
- To focus only on monitoring employees.
Correct answer: To monitor and deter unauthorized activities
Surveillance systems, such as CCTV cameras, serve as a critical tool for continuous monitoring of an area. Their visible presence acts as a deterrent to potential intruders or malicious activities, while also providing crucial visual evidence for investigations if an incident occurs. This enhances overall security by increasing situational awareness and accountability.
Question 120: Which document formally authorizes a system to operate by accepting identified residual risks?
- Authority to Operate (ATO) (Correct answer)
- System Security Plan (SSP)
- Incident Response Plan (IRP)
- Business Continuity Plan (BCP)
Correct answer: Authority to Operate (ATO)
An ATO is an official management decision that a system's risk level is acceptable and it is authorized for operation.
Question 121: When a vendor's security certification (e.g., ISO 27001) expires without renewal, what should an industrial security professional do?
- Immediately terminate the vendor relationship
- Initiate a re-evaluation of the vendor's security posture and request remediation or updated certification (Correct answer)
- Continue using the vendor with no action until the next scheduled review
- Automatically assume the vendor remains compliant based on past performance
Correct answer: Initiate a re-evaluation of the vendor's security posture and request remediation or updated certification
An expired certification means the vendor's controls have not been independently verified recently; re-evaluation ensures the vendor still meets required security standards before continuing the relationship.
Question 122: Which industrial control system (ICS) protocol is most commonly targeted by adversaries due to its lack of built-in authentication?
- TLS 1.3
- HTTPS
- Modbus (Correct answer)
- SSH
Correct answer: Modbus
Modbus was designed for reliability in isolated networks and lacks authentication, making it vulnerable when exposed to broader networks.
Question 123: An Initial Security Briefing for a newly cleared employee should ALWAYS cover:
- Responsibilities, classification levels, reporting requirements, and the consequences of security violations (Correct answer)
- Company financial performance and stock options
- Benefits enrollment and vacation accrual policies
- IT helpdesk contact information and printer setup
Correct answer: Responsibilities, classification levels, reporting requirements, and the consequences of security violations
Initial briefings establish the employee's foundational security responsibilities and set expectations for behavior from day one.
Question 124: Which of the following risk communication techniques is most effective when presenting risk findings to senior executives who have limited time?
- Sending a detailed narrative report with all threat actor profiles
- Providing a full technical appendix with all raw assessment data
- Delivering a risk heat map with prioritized findings and recommended actions (Correct answer)
- Presenting fault tree diagrams for each identified scenario
Correct answer: Delivering a risk heat map with prioritized findings and recommended actions
A risk heat map provides a concise visual summary of risk ratings and priorities, enabling executives to quickly grasp severity and make resource decisions.
Question 125: Which practice is MOST effective in verifying the authenticity of hardware components received from a supplier?
- Visual inspection only by receiving staff
- Testing against known-good baselines and reviewing traceability documentation (Correct answer)
- Accepting the supplier's certificate of conformance without inspection
- Storing components in a secure warehouse for 30 days before use
Correct answer: Testing against known-good baselines and reviewing traceability documentation
Testing against known-good baselines and verifying traceability documentation (including provenance records) are the most effective methods for detecting counterfeit or tampered components.
Question 126: How can technology support security risk management?
- By reducing the number of security guards.
- By limiting access to sensitive areas.
- By focusing only on physical barriers.
- By enhancing monitoring, detection, and response capabilities (Correct answer)
Correct answer: By enhancing monitoring, detection, and response capabilities
Technology provides advanced tools like surveillance systems, access control, intrusion detection, and cybersecurity software that significantly bolster security efforts. These technologies enable continuous monitoring, rapid detection of anomalies, and automated responses to potential threats. They extend the reach and effectiveness of human security personnel, creating a more robust defense.
Question 127: What is the importance of security policy enforcement?
- To reduce the number of security breaches.
- To limit employee access to security systems.
- To ensure that security measures are followed consistently (Correct answer)
- To eliminate the need for employee training.
Correct answer: To ensure that security measures are followed consistently
Policy enforcement translates written security policies into actionable and consistently followed practices. Without consistent enforcement, policies become ineffective, creating vulnerabilities that can be exploited by malicious actors. It ensures accountability, reinforces the importance of security, and guarantees that all employees adhere to the established rules and procedures, thereby strengthening the overall security posture.
Question 128: What does the term 'vendor lock-in' represent as a supply chain security concern?
- A contractual clause preventing vendors from disclosing pricing
- A vendor physically securing their facility
- Excessive dependence on a single vendor that limits an organization's ability to switch suppliers (Correct answer)
- A security feature that limits vendor system access
Correct answer: Excessive dependence on a single vendor that limits an organization's ability to switch suppliers
Vendor lock-in creates a single point of failure and reduces negotiating leverage, making the organization vulnerable if that vendor is compromised, disrupted, or becomes adversarial.
Question 129: Under the General Duty Clause of OSHA, employers in industrial settings are required to:
- Maintain a minimum of two armed security officers per shift
- Submit risk assessments to OSHA quarterly
- Provide a workplace free from recognized hazards likely to cause death or serious harm (Correct answer)
- Conduct annual security audits audited by a certified third party
Correct answer: Provide a workplace free from recognized hazards likely to cause death or serious harm
The General Duty Clause requires employers to provide a workplace free from recognized serious hazards, forming the baseline obligation for industrial security.
Question 130: Digital forensic investigators use 'write blockers' to:
- Speed up the forensic imaging process
- Prevent any data from being written to an original evidence drive during imaging, preserving its integrity (Correct answer)
- Block malware from writing to the investigator's workstation
- Encrypt evidence drives before analysis
Correct answer: Prevent any data from being written to an original evidence drive during imaging, preserving its integrity
Write blockers create a one-way barrier so the forensic tool can read the drive without modifying any data on it.
Question 131: When an industrial security professional recommends 'defense in depth,' they are advocating for:
- Layering multiple independent security controls so that failure of one does not compromise overall security (Correct answer)
- Prioritizing cyber defenses over physical security measures
- Installing the deepest underground vault available for asset storage
- Concentrating all security resources at the outer perimeter
Correct answer: Layering multiple independent security controls so that failure of one does not compromise overall security
Defense in depth uses multiple overlapping layers of security controls so that an attacker must defeat several independent barriers to reach a target.
Question 132: A security manager is designing an alarm system for an industrial warehouse. What is the key difference between 'local' and 'central station' alarm monitoring?
- Local alarms are more expensive than central station systems
- Local alarms automatically lock all doors; central stations do not
- Central station systems do not require sensors at the facility
- Local alarms alert only on-site personnel; central station monitoring notifies a remote 24/7 monitoring facility that can dispatch responders (Correct answer)
Correct answer: Local alarms alert only on-site personnel; central station monitoring notifies a remote 24/7 monitoring facility that can dispatch responders
Local alarms sound on site, relying on nearby response, while central station systems transmit alerts to a professionally staffed remote monitoring center that can coordinate emergency response.
Question 133: A security manager is evaluating fence types. Which fence fabric specification provides the BEST intrusion deterrence against cutting tools?
- 358 high-security welded wire mesh (3Ă—0.5-inch aperture) (Correct answer)
- Standard 11-gauge chain-link, 2-inch mesh
- Wooden privacy fence, 8 feet tall
- 9-gauge chain-link, 2-inch mesh with tension wire
Correct answer: 358 high-security welded wire mesh (3Ă—0.5-inch aperture)
358 mesh (anti-climb, anti-cut) has small 76.2Ă—12.7 mm apertures and heavy-gauge wire that resist cutting tools and provide minimal finger/toe holds for climbing.
Question 134: Under NISPOM, what is the term for a company that has been granted authority to access classified information by the U.S. government?
- Authorized Contractor
- Trusted Industry Partner (TIP)
- Cleared Defense Contractor (CDC) (Correct answer)
- Classified Access Entity (CAE)
Correct answer: Cleared Defense Contractor (CDC)
A Cleared Defense Contractor (CDC) is a company that holds a Facility Clearance (FCL) and is authorized to access classified information.
Question 135: The 'hot zone' in an industrial emergency is best described as:
- The area designated for media briefings
- The perimeter boundary for public exclusion
- The zone where medical triage occurs
- The immediately dangerous area requiring highest-level PPE (Correct answer)
Correct answer: The immediately dangerous area requiring highest-level PPE
The hot zone is the area of highest contamination or danger where only fully protected responders may operate.
Question 136: The 'scalability' principle in emergency response planning means that the response system should:
- Expand or contract to match the complexity and size of the incident (Correct answer)
- Always activate all emergency teams when any incident occurs
- Scale down operations after the first 24 hours automatically
- Use the maximum resources available regardless of incident size
Correct answer: Expand or contract to match the complexity and size of the incident
Scalable response ensures resources are matched to incident needs, preventing both under-response to serious events and costly over-response to minor ones.
Question 137: An Industrial Control System (ICS) SCADA network differs from a traditional IT network primarily because:
- SCADA systems are always connected to the public internet for remote monitoring
- ICS networks exclusively use wireless communication protocols
- SCADA networks require faster internet connectivity
- ICS/SCADA systems control physical processes with real-time requirements where downtime or errors can have safety consequences (Correct answer)
Correct answer: ICS/SCADA systems control physical processes with real-time requirements where downtime or errors can have safety consequences
ICS/SCADA systems manage physical processes—pipelines, power grids, manufacturing lines—where cyber failures can directly cause physical harm or safety incidents.
Question 138: Which background investigation element is MOST critical when determining suitability for a sensitive industrial position?
- Employment verification
- All of the above combined (Correct answer)
- Criminal record check
- Credit history review
Correct answer: All of the above combined
A comprehensive personnel security determination requires combining criminal, credit, and employment checks rather than relying on any single element.
Question 139: Which federal law establishes the baseline requirements for protecting classified national security information in industry?
- Freedom of Information Act (FOIA)
- Occupational Safety and Health Act (OSHA)
- Sarbanes-Oxley Act (SOX)
- National Industrial Security Program Operating Manual (NISPOM) (Correct answer)
Correct answer: National Industrial Security Program Operating Manual (NISPOM)
The NISPOM (32 CFR Part 117) is the primary federal regulation governing the protection of classified information in the defense industrial base.
Question 140: What is the significance of the 'adjudicative guidelines' under Security Executive Agent Directive 4 (SEAD 4)?
- They define minimum physical security standards for cleared facilities
- They establish the classification levels for national security information
- They set the minimum training requirements for Facility Security Officers
- They provide the 13 criteria used to evaluate an individual's eligibility for a security clearance (Correct answer)
Correct answer: They provide the 13 criteria used to evaluate an individual's eligibility for a security clearance
SEAD 4's 13 adjudicative guidelines are the criteria used to evaluate whether granting a security clearance is clearly consistent with national security interests.
Question 141: Which access control model grants permissions based on a user's job function rather than individual identity?
- Mandatory Access Control (MAC)
- Attribute-Based Access Control (ABAC)
- Discretionary Access Control (DAC)
- Role-Based Access Control (RBAC) (Correct answer)
Correct answer: Role-Based Access Control (RBAC)
RBAC assigns permissions to roles rather than individuals, simplifying administration and enforcing least privilege by job function.
Question 142: What does a 'security culture' in an organization reflect?
- Shared values, attitudes, and behaviors that prioritize security as everyone's responsibility (Correct answer)
- The physical appearance of the security operations center
- The number of security guards employed per square foot
- The frequency of executive security briefings
Correct answer: Shared values, attitudes, and behaviors that prioritize security as everyone's responsibility
Security culture describes the collective mindset where security is embedded in daily decisions and seen as a shared responsibility across all levels.
Question 143: A classified contract is completed and the contractor retains classified materials. What should the FSO do?
- Return, transfer, or destroy the materials per the government contracting officer's instructions (Correct answer)
- Archive the materials in a commercial off-site storage facility
- Retain the materials indefinitely in case the contract is reopened
- Destroy the materials immediately without notification
Correct answer: Return, transfer, or destroy the materials per the government contracting officer's instructions
Upon contract completion, classified materials must be dispositioned (returned, transferred, or destroyed) in accordance with government direction, not retained by the contractor.
Question 144: During a security risk assessment of a chemical storage facility, the assessor identifies that a fence line runs only 10 feet from a critical valve manifold. This finding primarily represents a concern about which risk element?
- Regulatory compliance
- Standoff distance and vulnerability (Correct answer)
- Asset criticality
- Threat probability
Correct answer: Standoff distance and vulnerability
Insufficient standoff distance between a perimeter barrier and a critical asset increases vulnerability by reducing response time and blast/intrusion buffer.
Question 145: Which of the following is NOT one of the 13 Adjudicative Guidelines under SEAD 4?
- Physical Fitness Standards (Correct answer)
- Sexual Behavior
- Allegiance to the United States
- Drug Involvement
Correct answer: Physical Fitness Standards
Physical fitness is not an adjudicative guideline; the 13 guidelines focus on loyalty, conduct, and character issues relevant to trustworthiness.
Question 146: Which federal guideline governs adjudicative standards for personnel security clearances in U.S. industrial environments?
- ISO 27001 Annex A
- The 13 Adjudicative Guidelines (Security Executive Agent Directive 4) (Correct answer)
- Title 18 U.S. Code Section 1030
- NIST SP 800-53
Correct answer: The 13 Adjudicative Guidelines (Security Executive Agent Directive 4)
SEAD 4 establishes the 13 Adjudicative Guidelines used to evaluate individuals for U.S. government-related security clearances.
Question 147: An insider threat is BEST defined as a risk posed by which of the following?
- Current or former employees, contractors, or partners who misuse authorized access (Correct answer)
- Vendors who deliver supplies to the facility
- External hackers who gain physical access
- Foreign intelligence agents who never entered the facility
Correct answer: Current or former employees, contractors, or partners who misuse authorized access
Insider threats originate from individuals who already have or recently had authorized access and can abuse that trust.
Question 148: Which regulatory framework governs the protection of Controlled Unclassified Information (CUI) in non-federal U.S. industrial organizations?
- HIPAA
- PCI DSS
- SOX
- NIST SP 800-171 / CMMC (Correct answer)
Correct answer: NIST SP 800-171 / CMMC
NIST SP 800-171 and its enforcement mechanism CMMC apply to contractors and industrial firms handling CUI on behalf of the U.S. government.
Question 149: An industrial security professional recommends installing vehicle barriers at a facility entrance after a vehicle-ramming threat is identified. This recommendation is an example of which risk treatment strategy?
- Risk avoidance
- Risk mitigation (Correct answer)
- Risk transference
- Risk acceptance
Correct answer: Risk mitigation
Installing vehicle barriers reduces the likelihood or impact of a vehicle-ramming attack, making it a risk mitigation (reduction) strategy.
Question 150: In the ASIS Risk Analysis framework, what does the term 'vulnerability' specifically refer to?
- A weakness that could be exploited by a threat (Correct answer)
- The cost of implementing countermeasures
- The potential loss resulting from an incident
- The likelihood that a threat will occur
Correct answer: A weakness that could be exploited by a threat
A vulnerability is a weakness or gap in a security system that a threat agent can exploit to cause harm.
Question 151: Which type of investigation focuses specifically on determining the root cause of a security system failure rather than identifying a perpetrator?
- Grand jury investigation
- Administrative investigation
- Criminal investigation
- Root cause analysis (RCA) / technical investigation (Correct answer)
Correct answer: Root cause analysis (RCA) / technical investigation
RCA investigations analyze system failures, process gaps, or equipment malfunctions to prevent recurrence rather than to assign criminal liability.
Industrial Security Professional (ISP) Certification Exam
The ISP certification validates an individual's expertise in industrial security practices, demonstrating a comprehensive understanding of security principles, regulations, and risk management within industrial environments.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds