PSP Access Control Systems 2 — Questions and Answers
Question 1: Which access control system architecture processes authentication decisions at the door-level hardware rather than a central server?
- Centralized access control
- Distributed (edge) access control (Correct answer)
- Cloud-based access control
- Analog access control
Correct answer: Distributed (edge) access control
Distributed or edge access control systems store access rules locally at the door controller, allowing continued operation even when network connectivity to the central server is lost.
Question 2: What is 'credential harvesting' in the context of physical access control attacks?
- Collecting expired access cards for disposal
- Capturing credential data from cards using a concealed reader (Correct answer)
- Gathering biometric data from enrolled users
- Auditing all access logs for anomalies
Correct answer: Capturing credential data from cards using a concealed reader
Credential harvesting involves using a covert RFID/NFC reader to skim and copy card data from unsuspecting cardholders, enabling later cloning of the credential.
Question 3: According to ASIS standards, what is the recommended maximum 'fail-safe' vs 'fail-secure' configuration for fire exit doors?
- Fail-safe (unlocks on power loss) for all exit doors
- Fail-secure (remains locked on power loss) for all exit doors
- Fail-safe for egress doors, fail-secure for high-security entry doors (Correct answer)
- Fail-secure for all doors when connected to fire alarm systems
Correct answer: Fail-safe for egress doors, fail-secure for high-security entry doors
Egress doors must be fail-safe to comply with life-safety codes (unlocking during fire/power loss), while high-security entry doors may be fail-secure to maintain asset protection.
Question 4: What is the purpose of an 'anti-passback' feature in an access control system?
- To prevent credential sharing by requiring card-in and card-out sequences (Correct answer)
- To block entry from the rear of a facility
- To deny access to terminated employees retroactively
- To prevent cards from being used after expiration
Correct answer: To prevent credential sharing by requiring card-in and card-out sequences
Anti-passback prevents a credential from being used to enter an area again until it has been properly used to exit, stopping users from passing their cards back to others.
Question 5: Which door-locking hardware is classified as an 'electrified mortise lock' in access control installations?
- A magnetic lock mounted on the door frame
- A cylindrical lock with an electric strike
- A full-function lock with an integral motorized latch bolt (Correct answer)
- A surface-mounted bolt with an electric solenoid
Correct answer: A full-function lock with an integral motorized latch bolt
An electrified mortise lock is a full-function mortise lock with a built-in motorized latch or deadbolt, offering high security and full egress capability in a single unit.
Question 6: In Wiegand access control protocol, which data format is most commonly used in North American installations?
- 26-bit Wiegand (Correct answer)
- 64-bit Wiegand
- ABA Track II
- OSDP v2
Correct answer: 26-bit Wiegand
The 26-bit Wiegand format is the de facto standard in North American access control installations, though its limited address space has prompted migration to longer formats.
Which access control system architecture processes authentication decisions at the door-level hardware rather than a central server?