Physical Security Professional (PSP) Certification Exam — Questions and Answers
Question 1: For a CCTV system used as evidence in US criminal prosecution, which chain of custody practice is MOST critical?
- Storing footage on cloud servers only
- Using proprietary recording formats to prevent tampering
- Documenting all access to and handling of recorded media from capture to court (Correct answer)
- Deleting footage older than 30 days to prevent confusion
Correct answer: Documenting all access to and handling of recorded media from capture to court
Maintaining a documented chain of custody for video evidence — recording who accessed it, when, and for what purpose — is essential for its admissibility in US court proceedings.
Question 2: What documentation is essential for maintaining an integrated security system over its lifecycle?
- Marketing brochures from each subsystem vendor
- Only the original vendor proposals
- The original project budget spreadsheet
- As-built drawings, integration point maps, configuration databases, and standard operating procedures (Correct answer)
Correct answer: As-built drawings, integration point maps, configuration databases, and standard operating procedures
Comprehensive technical documentation enables effective troubleshooting, maintenance, and future modifications of integrated systems.
Question 3: What is the minimum recommended video retention period for a general commercial facility's CCTV system under most US security best-practice guidelines?
- 30 days (Correct answer)
- 72 hours to 7 days
- 24-48 hours
- 90 days
Correct answer: 30 days
ASIS and most US security guidelines recommend a minimum 30-day retention period for general commercial facilities, though specific industries (healthcare, financial) may have longer requirements.
Question 4: What role does Crime Prevention Through Environmental Design (CPTED) play in asset protection?
- It focuses exclusively on landscaping around facilities
- It replaces the need for security personnel
- It eliminates the need for electronic security systems
- It uses the built environment to reduce opportunities for crime against assets (Correct answer)
Correct answer: It uses the built environment to reduce opportunities for crime against assets
CPTED modifies the physical environment to naturally reduce criminal opportunity and enhance asset protection.
Question 5: For a camera monitoring a vehicle entry gate, what frame rate is the minimum recommended to reliably capture readable license plates on vehicles traveling at normal entry speeds?
- 25-30 frames per second (fps) (Correct answer)
- 15 frames per second (fps)
- 60 frames per second (fps)
- 5 frames per second (fps)
Correct answer: 25-30 frames per second (fps)
25-30 fps is the minimum recommended for license plate capture at vehicle entry gate speeds, as lower frame rates cause motion blur that makes plates unreadable.
Question 6: Which of the following is the first step in the risk management process?
- Risk Identification (Correct answer)
- Risk Assessment
- Risk Mitigation
- Risk Monitoring
Correct answer: Risk Identification
The risk management process begins with identifying potential risks. Before any other steps like assessment, mitigation, or monitoring can occur, an organization must first systematically discover and document what those potential threats and vulnerabilities are.
Question 7: What is the primary purpose of a 'clear zone' (also called a buffer zone) at a facility's perimeter?
- To store emergency equipment near the fence line
- To create a fire break around the facility
- To eliminate concealment and provide unobstructed surveillance of the perimeter (Correct answer)
- To provide parking for security personnel
Correct answer: To eliminate concealment and provide unobstructed surveillance of the perimeter
A clear zone eliminates vegetation and objects that could provide concealment for intruders, improving detection capability for security personnel and electronic sensors.
Question 8: When establishing an emergency communication plan, which factor is MOST important for reaching all employees?
- Using the highest-technology platform available
- Ensuring the plan accounts for employees who may be off-site or traveling (Correct answer)
- Limiting communication to on-site supervisors only
- Restricting notifications to business hours
Correct answer: Ensuring the plan accounts for employees who may be off-site or traveling
Effective emergency communication plans must account for all employees, including those off-site or traveling, to ensure no one is left without critical safety information.
Question 9: According to ASIS and IES (Illuminating Engineering Society) guidelines, what is the minimum recommended horizontal illuminance level (in foot-candles) for a security perimeter fence line?
- 0.1 foot-candles
- 0.5 foot-candles (Correct answer)
- 2 foot-candles
- 5 foot-candles
Correct answer: 0.5 foot-candles
IES RP-33 (Lighting for Exterior Environments) recommends a minimum of 0.5 foot-candles (5.4 lux) for perimeter fence lines to support security patrol and camera surveillance functions.
Question 10: What CPTED concept involves designing spaces so that legitimate users naturally observe and informally supervise the area through their normal activities?
- Activity programming
- Mechanical surveillance
- Natural surveillance (Correct answer)
- Natural access control
Correct answer: Natural surveillance
Natural surveillance positions windows, seating, and activity generators so that legitimate users — employees, residents, customers — naturally observe the space during routine use, deterring criminal activity.
Question 11: When presenting risk assessment findings to executive management, what format is most effective?
- Highly technical reports with detailed sensor specifications
- Risk-based business cases showing potential losses, countermeasure costs, and return on security investment (Correct answer)
- Compliance checklists with pass/fail ratings
- Verbal briefings with no written documentation
Correct answer: Risk-based business cases showing potential losses, countermeasure costs, and return on security investment
Business-oriented presentations that quantify risk in financial terms resonate most effectively with executive decision-makers.
Question 12: When a critical security system component fails, what should be the FIRST action taken?
- File a maintenance request with the facilities department
- Order a replacement part
- Implement compensating security measures while arranging repair (Correct answer)
- Document the failure for the annual report
Correct answer: Implement compensating security measures while arranging repair
Compensating measures must be implemented immediately to maintain security coverage while the failed component is repaired.
Question 13: What does 'Grade' mean in the context of EN 50131 intrusion detection system standards used as reference in US security specifications?
- The risk level classification (1-4) that determines required system performance and tamper resistance (Correct answer)
- The installation quality rating given by the alarm installer
- The number of communication paths from panel to monitoring center
- The UL listing category of the alarm control panel
Correct answer: The risk level classification (1-4) that determines required system performance and tamper resistance
EN 50131 Grades 1-4 define increasing levels of risk and required system performance: Grade 1 for low risk, Grade 4 for high risk requiring the highest tamper resistance and redundancy.
Question 14: Which IP camera compression standard provides the BEST image quality at the lowest bandwidth compared to older MPEG-4 and H.264 formats?
- H.264 AVC
- MPEG-2
- MJPEG
- H.265 (HEVC) (Correct answer)
Correct answer: H.265 (HEVC)
H.265 (HEVC) offers approximately 50% better compression efficiency than H.264, delivering the same image quality at half the bit rate or better quality at the same bit rate.
Question 15: Which card technology offers the highest level of security for access control credentials?
- Wiegand wire
- Magnetic stripe
- Proximity (125 kHz)
- Smart card (contact/contactless) (Correct answer)
Correct answer: Smart card (contact/contactless)
Smart cards use encrypted microprocessors that make them significantly more resistant to cloning and counterfeiting compared to magnetic stripe or proximity technologies.
Question 16: What is 'alarm fatigue' and how does it negatively impact physical security operations?
- Operators becoming resistant to alarm system upgrades
- Physical exhaustion of security personnel from responding to alarms at night
- System degradation caused by excessive alarm activations stressing the hardware
- Desensitization of operators to alarms due to high false alarm rates, causing genuine alarms to be ignored (Correct answer)
Correct answer: Desensitization of operators to alarms due to high false alarm rates, causing genuine alarms to be ignored
Alarm fatigue occurs when excessive false alarms cause security operators to become desensitized, leading to slower response or complete disregard of alarms — including genuine intrusion events.
Question 17: What should be done if a security alarm system repeatedly triggers false alarms?
- Disable the alarm system temporarily
- Increase the sensitivity of the sensors
- Schedule a maintenance check to diagnose and fix the issue (Correct answer)
- Ignore the alarms since they are false
Correct answer: Schedule a maintenance check to diagnose and fix the issue
Repeated false alarms indicate a malfunction or misconfiguration within the alarm system, which can lead to alarm fatigue and reduced response effectiveness. Scheduling a maintenance check is the appropriate action to diagnose the root cause of the false alarms and implement a permanent fix, restoring the system's reliability.
Question 18: In a CPTED second-generation (2nd Gen) assessment, what factor is evaluated in addition to the physical design elements assessed in 1st Gen CPTED?
- Social dynamics, community cohesion, and the human behavioral dimension of space use (Correct answer)
- Electronic security system effectiveness
- Emergency response capability of the nearest police station
- Building material strength and forced-entry resistance
Correct answer: Social dynamics, community cohesion, and the human behavioral dimension of space use
2nd Gen CPTED expands beyond physical design to include social dimensions — community programs, social cohesion, and behavioral norms that affect whether physical CPTED measures are effective.
Question 19: Which door-locking hardware is classified as an 'electrified mortise lock' in access control installations?
- A cylindrical lock with an electric strike
- A surface-mounted bolt with an electric solenoid
- A magnetic lock mounted on the door frame
- A full-function lock with an integral motorized latch bolt (Correct answer)
Correct answer: A full-function lock with an integral motorized latch bolt
An electrified mortise lock is a full-function mortise lock with a built-in motorized latch or deadbolt, offering high security and full egress capability in a single unit.
Question 20: What cybersecurity risk is MOST commonly exploited in IP surveillance camera systems in US critical infrastructure?
- PoE (Power over Ethernet) power source attacks
- Default or weak manufacturer passwords left unchanged after installation (Correct answer)
- Use of H.265 compression format
- Physical tampering with camera housings
Correct answer: Default or weak manufacturer passwords left unchanged after installation
Unchanged default credentials remain the most exploited vulnerability in IP camera systems, allowing attackers to access live feeds, disable recording, or use cameras as botnet nodes.
Question 21: What is the purpose of an 'anti-passback' feature in an access control system?
- To block entry from the rear of a facility
- To prevent credential sharing by requiring card-in and card-out sequences (Correct answer)
- To deny access to terminated employees retroactively
- To prevent cards from being used after expiration
Correct answer: To prevent credential sharing by requiring card-in and card-out sequences
Anti-passback prevents a credential from being used to enter an area again until it has been properly used to exit, stopping users from passing their cards back to others.
Question 22: What is residual risk in the context of physical security planning?
- The risk associated with terminated employees
- The risk of a security system malfunctioning
- The level of risk remaining after all planned security countermeasures have been applied (Correct answer)
- The risk that existed before any security measures were implemented
Correct answer: The level of risk remaining after all planned security countermeasures have been applied
Residual risk is what remains after countermeasures are applied and must be formally accepted by management or further reduced.
Question 23: In risk assessment methodology, what distinguishes a threat from a hazard?
- Threats are always more dangerous than hazards
- There is no difference; the terms are interchangeable
- Hazards only apply to environmental risks
- Threats involve intentional human action while hazards are typically natural or accidental events (Correct answer)
Correct answer: Threats involve intentional human action while hazards are typically natural or accidental events
Threats involve deliberate hostile intent while hazards encompass natural disasters, accidents, and other non-intentional events.
Question 24: In CPTED principles, what does 'territorial reinforcement' mean and how is it applied?
- Using design features to create a sense of ownership and legitimate use that deters potential offenders (Correct answer)
- Marking all facility boundaries with warning signs
- Installing fences and barriers to define territory boundaries
- Assigning security guards to enforce territorial boundaries
Correct answer: Using design features to create a sense of ownership and legitimate use that deters potential offenders
Territorial reinforcement uses design elements (landscaping, walkways, signage, lighting) to distinguish private from public space, creating a psychological sense that the area is owned and monitored.
Question 25: According to US Department of Defense standards, what is the minimum standoff distance from an unscreened vehicle to a critical building to mitigate blast effects from a vehicle-borne improvised explosive device (VBIED)?
- 25 feet (7.6m)
- 100 feet (30m) (Correct answer)
- 164 feet (50m)
- 50 feet (15m)
Correct answer: 100 feet (30m)
UFC 4-010-01 (DoD Minimum Antiterrorism Standards for Buildings) establishes 100 feet (30m) as the minimum standoff distance for unscreened vehicle parking near inhabited buildings.
Question 26: What is the most important consideration when integrating fire alarm systems with access control?
- Connecting fire alarms to external speakers only
- Ensuring access doors automatically unlock during fire alarms for safe egress (Correct answer)
- Eliminating manual fire alarm testing requirements
- Reducing the number of fire alarm pull stations needed
Correct answer: Ensuring access doors automatically unlock during fire alarms for safe egress
Life safety requires that access-controlled doors unlock automatically during fire alarms to allow unimpeded emergency egress.
Question 27: What is the primary security advantage of using a 'credential + PIN' (something you have + something you know) access control system?
- It eliminates the need for audit logs
- It is required by all US federal facilities
- It provides multi-factor authentication, reducing risk from stolen or cloned credentials (Correct answer)
- It is faster to process than single-factor authentication
Correct answer: It provides multi-factor authentication, reducing risk from stolen or cloned credentials
Combining a physical credential with a PIN provides two-factor authentication, so a stolen or cloned card alone is insufficient to gain access.
Question 28: During scheduled maintenance of an access control system, which procedure ensures continued security?
- Leaving all doors unlocked during maintenance
- Disabling all access points simultaneously to speed up maintenance
- Maintaining at least one operational entry point with manual monitoring while servicing others sequentially (Correct answer)
- Performing maintenance only at night when the building is empty
Correct answer: Maintaining at least one operational entry point with manual monitoring while servicing others sequentially
Sequential maintenance with manual monitoring ensures continuous access control coverage throughout the maintenance period.
Question 29: According to ASTM standards, what does an 'F2656 M50 P1' anti-ram barrier rating indicate?
- The rating indicates bollard spacing of 50 cm with P1 profile height
- The barrier stopped a 6,800 kg vehicle at 80 km/h with no penetration
- The barrier is rated for 50 mph with a P1 (positive) structural test result
- The barrier stopped a 5,000 kg vehicle at 80 km/h with less than 1 meter of penetration (Correct answer)
Correct answer: The barrier stopped a 5,000 kg vehicle at 80 km/h with less than 1 meter of penetration
ASTM F2656 M50 P1 means the barrier stopped a 5,000 kg (Class M) vehicle at 80 km/h (50 mph) with 1 meter or less penetration (P1 = Penetration Level 1).
Question 30: Which metric is most useful for measuring the effectiveness of an asset protection program?
- Number of security personnel employed
- Total number of security cameras installed
- Shrinkage rate or loss percentage over time (Correct answer)
- Annual security budget expenditure
Correct answer: Shrinkage rate or loss percentage over time
Shrinkage rate directly measures actual losses, making it the most meaningful indicator of program effectiveness.
Question 31: In asset classification for physical security purposes, what factor is LEAST important?
- Attractiveness to potential thieves
- Original purchase date of the asset (Correct answer)
- Criticality to business operations
- Replacement cost of the asset
Correct answer: Original purchase date of the asset
Original purchase date has minimal relevance to current security requirements compared to value, criticality, and theft attractiveness.
Question 32: Which type of fence topping provides the greatest deterrent against climbing while complying with most US local ordinances?
- Electric fence topping
- Razor ribbon (concertina) wire (Correct answer)
- Anti-climb paint
- Barbed wire (three-strand outrigger)
Correct answer: Razor ribbon (concertina) wire
Razor ribbon wire (concertina) provides superior anti-climb deterrence compared to barbed wire, though it must be installed in compliance with local ordinances and liability considerations.
Question 33: Which IDS sensor is specifically designed to detect an attempt to break through walls, floors, or ceilings rather than entering through doors or windows?
- Seismic/vibration sensor (Correct answer)
- Passive infrared motion detector
- Photoelectric beam sensor
- Glass break detector
Correct answer: Seismic/vibration sensor
Seismic/vibration sensors detect the physical vibrations caused by drilling, sawing, or hammering through walls and structural elements, providing 'structural penetration' detection.
Question 34: In a video surveillance system design, what is the '3-1-1 rule' or 'detect-observe-identify' methodology used for?
- Establishing alarm response times for security operators
- Calculating storage requirements for a 30-day retention system
- Determining the camera resolution and field of view needed to meet specific surveillance objectives (Correct answer)
- Setting minimum illumination levels for camera operation
Correct answer: Determining the camera resolution and field of view needed to meet specific surveillance objectives
The detect-observe-identify methodology sets pixel density requirements based on the surveillance objective: detect (lowest PPF), observe/monitor (medium PPF), or identify (highest PPF).
Question 35: In access control, what does the term 'two-person integrity rule' require?
- Two authorized individuals must be present to access a sensitive area (Correct answer)
- Two supervisors must approve access requests
- Two separate authentication factors must be used
- Two guards must patrol together at all times
Correct answer: Two authorized individuals must be present to access a sensitive area
The two-person integrity rule requires at least two authorized individuals to be present simultaneously when accessing sensitive areas or materials, reducing insider threat risk.
Question 36: What is the purpose of an NVR (Network Video Recorder) as compared to a DVR (Digital Video Recorder) in modern IP surveillance systems?
- NVRs process and record IP camera streams via the network without requiring direct connection to each camera (Correct answer)
- NVRs store video on tapes while DVRs use hard drives
- NVRs are only used in outdoor applications
- NVRs are analog while DVRs process IP camera streams
Correct answer: NVRs process and record IP camera streams via the network without requiring direct connection to each camera
An NVR receives pre-compressed IP video streams from cameras over the network, while a DVR connects directly to analog cameras and encodes the video itself, limiting scalability and placement flexibility.
Question 37: What is the purpose of 'alarm verification' in a modern intrusion detection system, and how does it reduce law enforcement response burden?
- It requires the alarm subscriber to physically verify the premise before police are called
- It allows police to remotely monitor the live alarm system feed
- It uses video, audio, or sequential sensor activation to confirm an intrusion before dispatching authorities, reducing false alarms (Correct answer)
- Alarm verification automatically dispatches police faster than unverified alarms
Correct answer: It uses video, audio, or sequential sensor activation to confirm an intrusion before dispatching authorities, reducing false alarms
Alarm verification (using video clips, audio, or two-sensor activation) reduces false dispatches — which constitute 94-98% of US police alarm responses — improving response efficiency and reducing fees.
Question 38: What is the recommended approach for managing firmware and software updates on networked security devices?
- Apply all updates immediately as they are released
- Never update firmware to avoid compatibility issues
- Only update when a device stops functioning
- Test updates in a staging environment before deploying to production security systems (Correct answer)
Correct answer: Test updates in a staging environment before deploying to production security systems
Testing in a staging environment prevents updates from causing unexpected failures or compatibility issues in the live security system.
Question 39: What is the primary advantage of Wide Dynamic Range (WDR) cameras in physical security applications?
- They are less expensive than standard IP cameras
- They have a wider horizontal field of view than standard cameras
- They capture usable images in scenes with extreme contrast between bright and dark areas (Correct answer)
- They operate in complete darkness without supplemental lighting
Correct answer: They capture usable images in scenes with extreme contrast between bright and dark areas
WDR cameras use multiple exposures or sensor technology to capture detail in both very bright (e.g., exterior windows) and very dark areas simultaneously within the same frame.
Question 40: A security manager wants to detect unauthorized digging under the perimeter fence. Which sensor technology is MOST appropriate?
- Buried geophone or seismic sensor cable along the fence line (Correct answer)
- Vibration sensor attached to the fence fabric
- Passive infrared motion detector aimed at the fence base
- Microwave beam sensor at ankle height
Correct answer: Buried geophone or seismic sensor cable along the fence line
Buried geophone or seismic sensor cables detect the ground vibrations produced by digging, tunneling, or heavy footsteps underground, specifically designed for this type of sub-surface intrusion detection.
Question 41: According to FEMA and DoD perimeter security standards, what is the recommended minimum clear zone width on BOTH sides of an outer perimeter fence?
- 50 feet (15m) inside, 20 feet (6m) outside
- 10 feet (3m) inside, 10 feet (3m) outside
- 20 feet (6m) inside, 20 feet (6m) outside (Correct answer)
- No specific requirement — determined by risk assessment
Correct answer: 20 feet (6m) inside, 20 feet (6m) outside
A 20-foot clear zone on both sides of the perimeter fence provides unobstructed surveillance and eliminates concealment cover for approaching intruders.
Question 42: According to ASIS Physical Security Principles, what is the recommended approach when camera placement must balance surveillance effectiveness with employee privacy concerns?
- Install cameras only in exterior locations to avoid privacy issues
- Always prioritize surveillance effectiveness over privacy
- Post visible notices that surveillance is in use and focus cameras on work areas rather than personal spaces (Correct answer)
- Require written employee consent for all surveillance
Correct answer: Post visible notices that surveillance is in use and focus cameras on work areas rather than personal spaces
Posting conspicuous notices of surveillance and focusing cameras on work processes and assets rather than personal spaces balances security needs with employee privacy expectations and legal requirements.
Question 43: Which security lighting type activates only when a sensor detects movement, and what is its PRIMARY limitation in a high-security application?
- Continuous lighting; it uses too much energy
- Standby lighting; it requires manual activation by guards
- Motion-activated (standby) lighting; an intruder can observe the detection zone boundary and avoid it (Correct answer)
- Emergency lighting; it only functions during power outages
Correct answer: Motion-activated (standby) lighting; an intruder can observe the detection zone boundary and avoid it
Motion-activated standby lighting reveals the exact boundaries of the sensor's detection zone to a patient observer, allowing intruders to map and avoid triggering the lights.
Question 44: What is the purpose of access control systems in asset protection?
- To record video footage
- To monitor traffic flow
- To detect fires
- To ensure only authorized personnel can enter certain areas (Correct answer)
Correct answer: To ensure only authorized personnel can enter certain areas
Access control systems are designed to regulate who can enter specific areas, when they can enter, and under what conditions. Their primary purpose is to restrict entry to authorized individuals, thereby protecting sensitive areas, assets, and personnel from unauthorized access.
Question 45: A passive infrared (PIR) detector is installed near an exterior glass wall. What is the MOST likely source of false alarms in this installation?
- Radio frequency interference from nearby equipment
- Direct sunlight or headlights shining through the glass, causing rapid temperature changes in the detection zone (Correct answer)
- High humidity condensation on the detector lens
- Nearby smoke detectors interfering with the PIR signal
Correct answer: Direct sunlight or headlights shining through the glass, causing rapid temperature changes in the detection zone
PIR detectors sense changes in infrared (heat) energy — sunlight or vehicle headlights shining through glass can rapidly heat objects in the detection zone, mimicking a human body and triggering false alarms.
Question 46: Which of the following is a deterrent to theft in a retail environment?
- Emergency exits
- Inventory management software
- Visible surveillance cameras (Correct answer)
- Employee training programs
Correct answer: Visible surveillance cameras
A deterrent is something that discourages or prevents an action. Visible surveillance cameras act as a strong deterrent to theft in a retail environment because potential thieves are less likely to commit a crime if they believe they are being watched and recorded, increasing their risk of being caught.
Question 47: How should a physical security professional prioritize risks when multiple threats have been identified?
- Address the most recently identified threat first
- Rank risks by their combined likelihood and potential impact, addressing the highest-rated risks first (Correct answer)
- Allocate equal resources to all identified risks
- Focus only on threats that have occurred previously
Correct answer: Rank risks by their combined likelihood and potential impact, addressing the highest-rated risks first
Risk prioritization based on likelihood and impact ensures resources are directed toward the most significant threats first.
Question 48: Which factor is MOST critical when selecting a network infrastructure for integrated security systems?
- Using the cheapest available network switches
- Using wireless connections for all security devices
- Sharing the corporate network without any modifications
- Ensuring dedicated bandwidth, network segmentation, and Quality of Service (QoS) for security traffic (Correct answer)
Correct answer: Ensuring dedicated bandwidth, network segmentation, and Quality of Service (QoS) for security traffic
Security systems require guaranteed bandwidth, network isolation, and traffic prioritization to ensure reliable operation.
Question 49: According to ASIS International standards, how often should emergency response plans be formally reviewed and updated?
- Only following an actual emergency
- At least annually or whenever significant changes occur (Correct answer)
- Every three to five years as part of strategic planning
- Only when required by a government audit
Correct answer: At least annually or whenever significant changes occur
ASIS standards recommend emergency plans be reviewed at least annually and updated whenever significant organizational, operational, or environmental changes occur.
Question 50: What is the MOST important outcome of a comprehensive risk management program?
- Reduced headcount in the security department
- Informed decision-making about security investments that align with organizational risk tolerance (Correct answer)
- Complete elimination of all identified risks
- Zero security incidents
Correct answer: Informed decision-making about security investments that align with organizational risk tolerance
Risk management enables evidence-based security decisions aligned with organizational priorities and acceptable risk levels.
Question 51: What is the primary benefit of maintaining a security system asset inventory with lifecycle tracking?
- It satisfies tax depreciation requirements
- It reduces the number of maintenance staff needed
- It helps negotiate bulk purchasing discounts
- It enables proactive replacement planning before end-of-life failures create security gaps (Correct answer)
Correct answer: It enables proactive replacement planning before end-of-life failures create security gaps
Lifecycle tracking allows planned replacement of aging equipment before it fails and creates security vulnerabilities.
Question 52: Which document should be the foundation of any organizational asset protection program?
- The building floor plan
- A comprehensive asset protection policy approved by senior management (Correct answer)
- The annual budget report
- The employee handbook
Correct answer: A comprehensive asset protection policy approved by senior management
A formal policy approved by senior management establishes authority, scope, and accountability for the asset protection program.
Question 53: When performing an access control audit, which activity BEST identifies 'ghost accounts' (credentials belonging to former employees)?
- Inspecting cable terminations in the access control panels
- Reviewing physical damage to card readers
- Reconciling the active credential list against current HR employee records (Correct answer)
- Testing door hardware for forced-entry resistance
Correct answer: Reconciling the active credential list against current HR employee records
Reconciling active credentials against current HR records identifies credentials that belong to terminated, transferred, or otherwise ineligible individuals.
Question 54: Which US federal regulation mandates specific access control requirements for facilities handling classified national security information?
- HIPAA Security Rule
- NIST SP 800-116
- NFPA 101 Life Safety Code
- ICD 705 (Intelligence Community Directive 705) (Correct answer)
Correct answer: ICD 705 (Intelligence Community Directive 705)
ICD 705 establishes the physical and technical security standards for Sensitive Compartmented Information Facilities (SCIFs), including strict access control requirements.
Question 55: What does OSDP (Open Supervised Device Protocol) provide that legacy Wiegand does NOT?
- Higher card read speed
- Encrypted, bidirectional communication between reader and controller (Correct answer)
- Compatibility with magnetic stripe cards
- Longer cable runs without signal loss
Correct answer: Encrypted, bidirectional communication between reader and controller
OSDP provides AES-128 encrypted, bidirectional communication that enables mutual authentication between reader and controller, eliminating eavesdropping and relay attacks possible with Wiegand.
Question 56: When conducting a risk assessment for a new facility, what should be evaluated FIRST?
- The architectural design of the building
- The threat environment including crime data, natural hazards, and geopolitical factors for the location (Correct answer)
- The cost of security equipment
- The number of employees who will work there
Correct answer: The threat environment including crime data, natural hazards, and geopolitical factors for the location
Understanding the threat environment establishes the context for all subsequent vulnerability and countermeasure assessments.
Question 57: How does the Open Supervised Device Protocol (OSDP) improve access control system integration?
- It is exclusively used for elevator control integration
- It eliminates the need for access control cards
- It provides encrypted bidirectional communication between readers and controllers, replacing legacy Wiegand protocol (Correct answer)
- It only works with a single manufacturer's products
Correct answer: It provides encrypted bidirectional communication between readers and controllers, replacing legacy Wiegand protocol
OSDP enables encrypted, bidirectional communication between access control readers and panels, overcoming Wiegand's security and functional limitations.
Question 58: What is the most important consideration when selecting a maintenance contractor for security systems?
- The contractor's general reputation in the community
- Proximity of the contractor's office to the facility
- Lowest bid price
- Background verification and security clearance of technicians who will access the systems (Correct answer)
Correct answer: Background verification and security clearance of technicians who will access the systems
Maintenance technicians have intimate knowledge of and access to security systems, making their trustworthiness paramount.
Question 59: What is the recommended minimum door thickness for a high-security access-controlled door to resist forced entry?
- 1-3/8 inches (35mm)
- 2-1/4 inches (57mm)
- 1 inch (25mm)
- 1-3/4 inches (44mm) (Correct answer)
Correct answer: 1-3/4 inches (44mm)
ANSI/SDI standards recommend a minimum 1-3/4 inch (44mm) solid-core door for high-security applications to provide adequate forced-entry resistance.
Question 60: What is the minimum recommended fence height according to ASIS guidelines for a standard industrial security perimeter?
- 4 feet (1.2m)
- 7 feet (2.1m) (Correct answer)
- 6 feet (1.8m)
- 8 feet (2.4m)
Correct answer: 7 feet (2.1m)
ASIS guidelines recommend a minimum 7-foot (2.1m) fence height for industrial security perimeters, with additional topping for higher-security applications.
Question 61: What role does threat intelligence play in an ongoing risk management program?
- It is only relevant during the initial risk assessment
- It replaces the need for physical security measures
- It continuously updates threat information to ensure risk assessments reflect current conditions (Correct answer)
- It is only useful for government facilities
Correct answer: It continuously updates threat information to ensure risk assessments reflect current conditions
Threat intelligence provides current information that keeps risk assessments relevant as the threat landscape evolves.
Question 62: Which access control model grants permissions based on a subject's clearance level and the sensitivity classification of the object?
- Role-Based Access Control (RBAC)
- Attribute-Based Access Control (ABAC)
- Discretionary Access Control (DAC)
- Mandatory Access Control (MAC) (Correct answer)
Correct answer: Mandatory Access Control (MAC)
Mandatory Access Control (MAC) enforces access based on security labels assigned to subjects and objects, commonly used in government and military environments.
Question 63: What does 'IPVM pixel density calculator' methodology account for that simple megapixel ratings do NOT?
- Infrared illumination range of the camera
- Camera mounting height and angle
- Network bandwidth consumed by the camera stream
- The actual scene width covered by the camera, which determines how many pixels cover each foot of the scene (Correct answer)
Correct answer: The actual scene width covered by the camera, which determines how many pixels cover each foot of the scene
Scene width (field of view) is the critical variable — the same 4MP camera provides dramatically different pixel density depending on whether it covers 10 feet or 100 feet of scene width.
Question 64: Which detection technology is MOST appropriate for detecting an intruder who has defeated the outer perimeter but is moving very slowly to avoid triggering motion sensors?
- Passive infrared (PIR) motion detector
- Microwave Doppler motion detector
- Thermal imaging camera with video analytics (Correct answer)
- Vibration sensor on the floor
Correct answer: Thermal imaging camera with video analytics
Thermal cameras detect the heat signature of the human body regardless of movement speed — unlike Doppler (requires motion) or PIR (requires movement across detection zones), thermal imaging detects stationary or slow-moving intruders.
Question 65: What is the role of a central management system (CMS) in security system integration?
- To monitor and control integrated security systems from a single interface (Correct answer)
- To increase the number of security cameras
- To physically connect all security devices
- To replace the need for on-site security guards
Correct answer: To monitor and control integrated security systems from a single interface
A Central Management System (CMS) serves as the unified control center for all integrated security systems. It provides a single, intuitive interface through which security personnel can monitor alerts, manage access points, control cameras, and respond to incidents across the entire security infrastructure. This centralization streamlines operations, improves situational awareness, and enhances the efficiency of security management.
Question 66: A perimeter fence line must pass through a low-lying area prone to flooding. What is the BEST security solution to maintain perimeter integrity during flood events?
- Use underwater ground sensors connected to the alarm system
- Install a concrete barrier instead of fence in the flood zone
- Install a flood gate or flap gate designed to allow water flow while deterring human intrusion (Correct answer)
- Raise the fence height to 12 feet in the flood-prone section
Correct answer: Install a flood gate or flap gate designed to allow water flow while deterring human intrusion
Flood gates or anti-intrusion flap gates are designed to allow water to pass freely while physical barriers and sensors prevent human intrusion through drainage openings.
Question 67: What is the purpose of a vulnerability assessment in risk management?
- To monitor ongoing security risks
- To identify weaknesses that could be exploited by threats (Correct answer)
- To document security incidents
- To measure the effectiveness of security controls
Correct answer: To identify weaknesses that could be exploited by threats
A vulnerability assessment specifically focuses on identifying weaknesses or flaws within a system, process, or environment. These vulnerabilities, if exploited by a threat, could lead to a security incident, making their identification crucial for understanding potential attack vectors and improving defenses.
Question 68: What is a 'video analytics' false positive in the context of a security surveillance system?
- The system incorrectly records footage at the wrong frame rate
- The system fails to detect an actual intrusion event
- The recorded video has compression artifacts that obscure faces
- The system generates an alarm for a non-threatening event such as an animal or blowing debris (Correct answer)
Correct answer: The system generates an alarm for a non-threatening event such as an animal or blowing debris
A false positive (nuisance alarm) occurs when the analytics system triggers an alert for a benign event, such as a shadow, animal, or environmental condition, wasting operator attention.
Question 69: Which environmental factor most commonly degrades outdoor security camera performance over time?
- Gravity pulling on the mounting bracket
- Radio frequency interference from nearby buildings
- Fluctuations in internet bandwidth
- Accumulated dirt, moisture, and UV exposure on lenses and housings (Correct answer)
Correct answer: Accumulated dirt, moisture, and UV exposure on lenses and housings
Environmental exposure to dirt, moisture, and UV radiation is the primary cause of degraded outdoor camera image quality.
Question 70: According to ASIS PSP guidelines, what is the recommended action when a lost or stolen access card is reported?
- Change all facility access codes within 24 hours
- Issue a new card and deactivate the old one within 30 days
- Notify law enforcement before taking any system action
- Immediately deactivate the reported credential in the access control system (Correct answer)
Correct answer: Immediately deactivate the reported credential in the access control system
Immediate deactivation of a lost or stolen credential is the first priority to prevent unauthorized use, regardless of whether the loss was accidental or malicious.
Question 71: In alarm system design, what is the 'defense in depth' approach to intrusion detection?
- Placing all sensors deep inside the facility near the most valuable assets
- Hiring additional security guards to supplement electronic detection
- Using only the most expensive sensors available
- Installing multiple sensor types and layers so that an intruder must defeat several independent systems to reach the target undetected (Correct answer)
Correct answer: Installing multiple sensor types and layers so that an intruder must defeat several independent systems to reach the target undetected
Defense in depth layers perimeter, exterior, interior, and point protection so that bypassing one detection layer still leaves additional layers that must be defeated, increasing detection probability.
Question 72: Under UL 2050 standards for central station alarm monitoring, what is the maximum response time for a central station to call the subscriber after receiving an intrusion alarm signal?
- 10 minutes
- 5 minutes
- 30 seconds
- 90 seconds (Correct answer)
Correct answer: 90 seconds
UL 2050 requires central stations to attempt to contact the subscriber within 90 seconds of receiving an intrusion alarm signal to verify the event.
Question 73: What alarm transmission technology offers the MOST reliable path from premises to monitoring center against communication sabotage?
- Dual-path: cellular + broadband IP with automatic failover (Correct answer)
- Broadband IP-only communication
- Cellular-only communication
- Standard PSTN (phone line) with dial-up communicator
Correct answer: Dual-path: cellular + broadband IP with automatic failover
Dual-path communication using both cellular and broadband IP with automatic failover is most resistant to sabotage because cutting one path (phone/cable line) still leaves the cellular path active.
Question 74: Which risk treatment strategy involves accepting the risk without taking any action to reduce its impact?
- Risk Mitigation
- Risk Transfer
- Risk Avoidance
- Risk Acceptance (Correct answer)
Correct answer: Risk Acceptance
Risk acceptance is a deliberate decision to acknowledge a risk and take no action to reduce its likelihood or impact. This strategy is typically chosen when the cost of mitigating the risk outweighs the potential cost of the risk occurring, or when the risk is deemed to be very low.
Question 75: What is the primary purpose of a preventive maintenance schedule for security systems?
- To provide work for maintenance technicians
- To comply with manufacturer warranty requirements only
- To reduce the security department's budget
- To ensure systems operate reliably and detect failures before they create security gaps (Correct answer)
Correct answer: To ensure systems operate reliably and detect failures before they create security gaps
Preventive maintenance identifies and corrects potential failures before they result in security system downtime.
Question 76: A physical security professional is updating the facility's emergency plan. Which step should be performed FIRST?
- Conduct a risk and hazard assessment of the facility (Correct answer)
- Schedule training for all security staff
- Draft new evacuation procedures
- Purchase new emergency communications equipment
Correct answer: Conduct a risk and hazard assessment of the facility
A risk and hazard assessment must be conducted first to identify the specific threats and vulnerabilities that the emergency plan must address.
Question 77: What is the primary security concern with open-plan office environments regarding asset protection?
- Reduced ability to control access to sensitive assets and information (Correct answer)
- Increased noise levels affecting productivity
- Higher heating and cooling costs
- Difficulty installing security cameras
Correct answer: Reduced ability to control access to sensitive assets and information
Open-plan designs inherently reduce the ability to restrict physical access to sensitive materials and equipment.
Question 78: In layered physical security design, what term describes the space between the outer perimeter fence and an inner security fence around the most sensitive areas?
- No-man's land / controlled zone (Correct answer)
- Dead zone
- Annular space
- Buffer zone
Correct answer: No-man's land / controlled zone
The controlled zone (sometimes called no-man's land) between the outer and inner perimeters is a sterile area where any presence is considered unauthorized, triggering alarm response.
Question 79: Why is cybersecurity a critical consideration in integrated physical security system design?
- Cybersecurity adds unnecessary cost with no security benefit
- Cybersecurity only affects computer networks, not physical security
- It is only important for government installations
- Networked security devices are potential entry points for cyberattacks that could disable physical security systems (Correct answer)
Correct answer: Networked security devices are potential entry points for cyberattacks that could disable physical security systems
Integrated networked security systems can be compromised through cyberattacks, potentially disabling physical protection measures.
Question 80: What is the purpose of the 'exit delay' and 'entry delay' in an intrusion alarm system?
- Exit delay allows the last person to leave and disarm the system; entry delay allows an authorized user time to disarm before the alarm activates (Correct answer)
- Both delays are required by UL for all commercial alarm installations
- Exit delay silences external sounders while entry delay silences internal sounders
- Entry and exit delays reduce power consumption during non-business hours
Correct answer: Exit delay allows the last person to leave and disarm the system; entry delay allows an authorized user time to disarm before the alarm activates
Exit delay gives the last authorized person time to leave after arming, while entry delay gives an authorized person time to reach the keypad and disarm after entering through a designated entry point.
Question 81: The Incident Command System (ICS) recommends that no supervisor have more than how many personnel reporting directly to them?
- 10 to 12
- 3 to 5
- 5 to 7 (Correct answer)
- 7 to 10
Correct answer: 5 to 7
ICS recommends a span of control of 5 to 7 subordinates per supervisor, with 5 being optimal, to maintain effective management during incidents.
Question 82: Which document formally establishes the authority, scope, and responsibilities for an organization's emergency response program?
- Incident Action Plan
- Business Continuity Plan (BCP)
- Emergency Operations Plan (EOP) (Correct answer)
- Standard Operating Procedure (SOP)
Correct answer: Emergency Operations Plan (EOP)
An Emergency Operations Plan (EOP) is the foundational document that defines authority, scope, roles, and responsibilities for an organization's emergency response.
Question 83: During an emergency evacuation, which group should receive priority assistance according to standard life-safety protocols?
- Persons with mobility impairments or disabilities (Correct answer)
- Employees nearest to exits
- Senior executives
- IT personnel protecting critical data
Correct answer: Persons with mobility impairments or disabilities
Standard life-safety protocols prioritize persons with disabilities or mobility impairments who may need assistance evacuating safely.
Question 84: During an emergency, the Unified Command structure is BEST used when:
- A single agency has complete jurisdiction over the incident
- Multiple agencies or jurisdictions share responsibility for an incident (Correct answer)
- The incident involves only internal security personnel
- Command must be transferred from day to night shift
Correct answer: Multiple agencies or jurisdictions share responsibility for an incident
Unified Command is used when multiple agencies or jurisdictions have shared authority over an incident, allowing them to coordinate while maintaining individual accountability.
Question 85: For a parking garage security lighting design, what is the recommended minimum maintained horizontal illuminance at pavement level according to IES RP-20?
- 10 foot-candles (108 lux)
- 0.5 foot-candles (5 lux)
- 1.0 foot-candle (11 lux)
- 5.0 foot-candles (54 lux) (Correct answer)
Correct answer: 5.0 foot-candles (54 lux)
IES RP-20 recommends a minimum 5.0 foot-candles maintained horizontal illuminance at pavement level in parking garages to support both personal safety and camera surveillance effectiveness.
Question 86: Which approach best addresses the protection of intellectual property in a physical security context?
- Hiring additional security guards
- Encrypting all digital files
- Installing bollards around the building
- Controlling physical access to areas where sensitive information is processed and stored (Correct answer)
Correct answer: Controlling physical access to areas where sensitive information is processed and stored
Physical access control to sensitive areas prevents unauthorized individuals from viewing, copying, or stealing proprietary information.
Question 87: According to ASIS standards, what is the recommended maximum 'fail-safe' vs 'fail-secure' configuration for fire exit doors?
- Fail-secure for all doors when connected to fire alarm systems
- Fail-safe for egress doors, fail-secure for high-security entry doors (Correct answer)
- Fail-secure (remains locked on power loss) for all exit doors
- Fail-safe (unlocks on power loss) for all exit doors
Correct answer: Fail-safe for egress doors, fail-secure for high-security entry doors
Egress doors must be fail-safe to comply with life-safety codes (unlocking during fire/power loss), while high-security entry doors may be fail-secure to maintain asset protection.
Question 88: A Business Continuity Plan (BCP) differs from an Emergency Response Plan (ERP) primarily in that a BCP:
- Focuses on immediate life-safety actions
- Defines roles for first responders on scene
- Establishes evacuation routes and assembly points
- Addresses restoration of critical business functions after a disruption (Correct answer)
Correct answer: Addresses restoration of critical business functions after a disruption
A BCP focuses on maintaining or restoring essential business functions during and after a disruption, whereas an ERP addresses immediate life-safety and incident response.
Question 89: What is the significance of establishing risk tolerance levels before conducting a risk assessment?
- It eliminates the need for quantitative analysis
- It provides clear criteria for determining which risks require treatment and which can be accepted (Correct answer)
- It satisfies insurance company requirements
- It reduces the cost of the assessment
Correct answer: It provides clear criteria for determining which risks require treatment and which can be accepted
Predefined risk tolerance levels provide objective criteria for determining acceptable versus unacceptable risk levels.
Question 90: Which vehicle barrier is classified as a 'passive' anti-ram barrier?
- Concrete jersey barriers (Correct answer)
- Hydraulic rising bollard
- Swing arm gate with vehicle stop
- Electric gate with vehicle sensors
Correct answer: Concrete jersey barriers
Concrete jersey barriers (K-rails) are passive barriers because they are fixed in place and do not require power, activation, or operator intervention to function.
Question 91: What is the primary benefit of integrating different security systems?
- Reduced maintenance costs
- Enhanced overall security by enabling systems to work together (Correct answer)
- Decreased need for security personnel
- Improved aesthetics of the security setup
Correct answer: Enhanced overall security by enabling systems to work together
Integrating different security systems allows them to communicate and share information, creating a unified and more effective security posture. This synergy enables systems like CCTV, access control, and alarms to work together, leading to enhanced threat detection, faster response times, and a more comprehensive security solution than isolated systems could provide.
Question 92: What testing methodology should be used to validate integrated security system performance?
- Manufacturer bench testing before installation
- Only testing during the annual maintenance visit
- End-to-end scenario testing that verifies cross-system event correlation, notification, and response workflows (Correct answer)
- Testing individual components separately is sufficient
Correct answer: End-to-end scenario testing that verifies cross-system event correlation, notification, and response workflows
End-to-end scenario testing validates that integrated systems work together correctly under realistic conditions.
Question 93: What is the primary difference between a 'point' intrusion detection sensor and a 'line' or 'volumetric' sensor?
- Point sensors are more expensive than volumetric sensors
- Point sensors protect a single specific location (door/window), while volumetric sensors cover an entire area or zone (Correct answer)
- Point sensors require a wired connection while volumetric sensors are wireless
- Point sensors detect motion only while volumetric sensors detect heat
Correct answer: Point sensors protect a single specific location (door/window), while volumetric sensors cover an entire area or zone
Point sensors (magnetic door contacts, glass break detectors) protect a single discrete location, while volumetric sensors (PIR, microwave) detect intrusion throughout an entire protected volume or zone.
Question 94: What is the most significant advantage of using an asset tracking system integrated with access control?
- Real-time knowledge of asset location and who accessed it (Correct answer)
- Lower insurance premiums
- Reduced staffing requirements
- Simplified audit procedures
Correct answer: Real-time knowledge of asset location and who accessed it
Integration provides real-time visibility into both asset location and the identity of individuals who interacted with it.
Question 95: What is the key difference between qualitative and quantitative risk assessment methods?
- Qualitative uses descriptive scales while quantitative assigns numerical values and calculates expected losses (Correct answer)
- Quantitative can only be performed by external consultants
- Qualitative is always more accurate than quantitative
- There is no meaningful difference between the two methods
Correct answer: Qualitative uses descriptive scales while quantitative assigns numerical values and calculates expected losses
Qualitative assessment uses categories like high/medium/low while quantitative assigns numerical probabilities and dollar values.
Question 96: Which of the following is an example of a physical barrier used in asset protection?
- Security guard
- Alarm system
- Surveillance camera
- Fence (Correct answer)
Correct answer: Fence
A physical barrier is a tangible structure designed to impede or prevent unauthorized access. A fence serves as a clear physical impediment, establishing a perimeter and deterring entry, unlike surveillance cameras (detection), security guards (personnel), or alarm systems (detection/response).
Question 97: What is the primary security benefit of constructing a facility with a 'setback' from the property line in addition to a perimeter fence?
- It provides depth-of-defense by creating multiple security layers with detection time between them (Correct answer)
- It reduces property taxes for the facility owner
- It satisfies local building code requirements for fire access lanes
- It reduces the cost of perimeter lighting installation
Correct answer: It provides depth-of-defense by creating multiple security layers with detection time between them
Physical setback between the property line and the building creates detection time — the distance an attacker must travel after breaching the outer perimeter gives security personnel time to respond.
Question 98: Which of the following is a best practice when maintaining CCTV systems?
- Replacing cameras every year
- Turning off cameras when not in use
- Cleaning camera lenses monthly (Correct answer)
- Adjusting camera angles daily
Correct answer: Cleaning camera lenses monthly
Cleaning camera lenses monthly is a best practice for CCTV systems because dust, dirt, and smudges can significantly degrade image quality and obscure critical details. Regular cleaning ensures clear, high-quality footage, which is essential for effective surveillance and incident investigation.
Question 99: What is the primary purpose of a mantrap (access control vestibule) in a physical security system?
- To house security personnel
- To store access control credentials
- To provide emergency egress
- To prevent tailgating and piggybacking (Correct answer)
Correct answer: To prevent tailgating and piggybacking
A mantrap uses two interlocking doors to ensure only one person passes through at a time, preventing unauthorized tailgating or piggybacking.
Question 100: Which lighting technology offers the BEST combination of energy efficiency, long lifespan, and instant-on capability for security applications, replacing older HID and fluorescent systems?
- LED (Light Emitting Diode) lighting (Correct answer)
- High-pressure sodium (HPS) lighting
- Metal halide (MH) lighting
- Fluorescent T8 lighting
Correct answer: LED (Light Emitting Diode) lighting
LED lighting offers 50,000-100,000+ hour lifespan, 60-80% energy savings over HID, instant full-brightness activation, and superior color rendering for camera performance.
Question 101: When should an organization conduct a full-scale emergency exercise?
- At least annually or as required by regulation, involving real resources and personnel (Correct answer)
- Only after an actual emergency has occurred
- Only when mandated by external regulatory auditors
- Every five years as part of long-term planning cycles
Correct answer: At least annually or as required by regulation, involving real resources and personnel
Full-scale exercises should be conducted at least annually (or per regulatory requirement) to validate plans and train personnel using actual resources and realistic scenarios.
Question 102: What is the primary purpose of establishing a common command and control center for integrated security systems?
- To provide centralized monitoring, correlation, and coordinated response across all security subsystems (Correct answer)
- To eliminate the need for field security officers
- To reduce the number of security monitors needed
- To satisfy building code requirements
Correct answer: To provide centralized monitoring, correlation, and coordinated response across all security subsystems
A centralized command center enables operators to monitor all systems, correlate events, and coordinate responses from a single location.
Question 103: Which of the following security systems is typically integrated with access control systems?
- Public address systems
- HVAC systems
- Fire alarms
- CCTV surveillance cameras (Correct answer)
Correct answer: CCTV surveillance cameras
CCTV surveillance cameras are frequently integrated with access control systems to provide visual verification of entry and exit events. When an access card is used or a door is opened, the CCTV system can automatically record or display the corresponding camera feed. This integration enhances security by linking physical access records with visual evidence, allowing for better incident investigation and deterrence.
Question 104: Which access control system architecture processes authentication decisions at the door-level hardware rather than a central server?
- Cloud-based access control
- Analog access control
- Distributed (edge) access control (Correct answer)
- Centralized access control
Correct answer: Distributed (edge) access control
Distributed or edge access control systems store access rules locally at the door controller, allowing continued operation even when network connectivity to the central server is lost.
Question 105: In CPTED (Crime Prevention Through Environmental Design), what principle is applied when using low-height landscaping near building windows and entrances?
- Natural access control
- Natural surveillance (Correct answer)
- Target hardening
- Territorial reinforcement
Correct answer: Natural surveillance
Using low-height landscaping near windows and entrances applies the natural surveillance principle by maintaining sightlines for occupants and passersby to observe criminal activity.
Question 106: In developing an asset protection strategy, what does the term 'target hardening' refer to?
- Increasing the effort required for an adversary to compromise a specific asset (Correct answer)
- Moving assets to an underground vault
- Insuring assets against all possible losses
- Making assets physically indestructible
Correct answer: Increasing the effort required for an adversary to compromise a specific asset
Target hardening increases the difficulty, time, and risk an adversary faces when attempting to compromise a specific asset.
Question 107: Which perimeter intrusion detection system (PIDS) technology is MOST susceptible to nuisance alarms caused by wind, animals, and debris?
- Microwave beam sensor
- Taut-wire fence sensor
- Ported coaxial leaky cable
- Buried seismic/vibration sensor cable (Correct answer)
Correct answer: Buried seismic/vibration sensor cable
Buried seismic/vibration sensors are highly sensitive to ground vibrations from any source, making them susceptible to nuisance alarms from wind-driven debris, animals, and nearby traffic.
Question 108: Which security measure is most effective for protecting high-value assets stored in a warehouse environment?
- Layered security with access control, surveillance, and alarm systems (Correct answer)
- Motion-activated exterior lighting
- Perimeter fencing alone
- Security guard patrols only
Correct answer: Layered security with access control, surveillance, and alarm systems
Layered security (defense in depth) combines multiple countermeasures to create overlapping protection zones.
Question 109: Which of the following is a common challenge when integrating security systems?
- Increased system speed
- Simplified user interface
- Reduction in system costs
- Compatibility issues between different systems (Correct answer)
Correct answer: Compatibility issues between different systems
A significant hurdle in integrating security systems is the inherent compatibility issues between different manufacturers' products. These systems often use varying communication protocols, hardware, and software, making it challenging to achieve seamless interoperability. Overcoming these differences typically requires specialized interfaces, middleware, or custom programming, adding complexity and cost to the integration project.
Question 110: How often should access control systems be tested for functionality?
- Every six months
- Weekly
- Annually
- Monthly (Correct answer)
Correct answer: Monthly
Access control systems are critical for security, and regular testing ensures they function correctly and securely. Monthly testing is a recommended best practice to verify that all components, such as card readers, locks, and software, are operating as intended and that no unauthorized access is possible.
Question 111: Which of the following is an example of risk transfer?
- Implementing stronger access controls
- Purchasing insurance (Correct answer)
- Performing regular security audits
- Discontinuing a risky operation
Correct answer: Purchasing insurance
Risk transfer involves shifting the financial consequences of a risk to a third party. Purchasing insurance is a classic example, as it transfers the financial burden of potential losses (e.g., property damage, liability) from the organization to the insurance company in exchange for premiums.
Question 112: Which CPTED strategy is applied when a facility uses visible security measures — cameras, lighting, guard booths — to signal to potential offenders that detection is likely?
- Activity support
- Image maintenance / management
- Target hardening (Correct answer)
- Natural surveillance
Correct answer: Target hardening
Target hardening makes the potential target more difficult and risky to attack through visible security measures that increase perceived detection and apprehension risk for potential offenders.
Question 113: What is the recommended maximum spacing between fence posts for a standard 7-foot chain-link security fence to maintain structural integrity under attack?
- 6 feet (1.8m)
- 16 feet (4.8m)
- 12 feet (3.6m)
- 10 feet (3m) (Correct answer)
Correct answer: 10 feet (3m)
ASIS and DoD perimeter security guidelines recommend a maximum 10-foot (3m) post spacing to ensure the fence maintains structural integrity and cannot easily be pushed down.
Question 114: The US Department of State's K-rating system for anti-ram barriers tests a vehicle at 50 mph. What does a K12 rating indicate?
- The barrier withstands 12,000 foot-pounds of impact force
- The barrier stops a 65,000 lb vehicle traveling at 50 mph
- The barrier is 12 inches thick at the base
- The barrier stops a 15,000 lb vehicle traveling at 50 mph (Correct answer)
Correct answer: The barrier stops a 15,000 lb vehicle traveling at 50 mph
A K12 rating means the barrier successfully stopped a 15,000 lb vehicle (medium-duty truck) traveling at 50 mph with no more than 3.3 feet of penetration beyond the face.
Question 115: In the context of physical security risk assessment, what does the formula R = T x V x C represent?
- Rating equals testing multiplied by verification multiplied by compliance
- Reliability equals throughput multiplied by variance multiplied by capacity
- Risk equals threat multiplied by vulnerability multiplied by consequence (Correct answer)
- Revenue equals time multiplied by volume multiplied by cost
Correct answer: Risk equals threat multiplied by vulnerability multiplied by consequence
The standard risk formula calculates risk as the product of threat likelihood, vulnerability level, and potential consequence or impact.
Question 116: Which biometric identifier is considered the MOST unique and stable over time for access control purposes?
- Hand geometry
- Voice recognition
- Iris pattern (Correct answer)
- Fingerprint
Correct answer: Iris pattern
The iris pattern is considered the most unique and stable biometric identifier because it is protected inside the eye and does not change significantly with age.
Question 117: What is 'glare projection' (or controlled lighting) in perimeter security lighting design?
- Using motion-activated lights to surprise and disorient intruders
- Positioning lights to cast shadows into the facility to hide security activities
- Using floodlights aimed outward to blind potential intruders approaching the perimeter (Correct answer)
- Installing lights inside the facility to illuminate windows for surveillance
Correct answer: Using floodlights aimed outward to blind potential intruders approaching the perimeter
Glare projection lighting aims bright lights outward from the perimeter to temporarily blind approaching intruders while keeping guards in relative darkness, giving defenders a tactical advantage.
Question 118: What is the primary security risk associated with allowing trees to grow tall near security lighting fixtures at a facility perimeter?
- Trees attract wildlife that triggers perimeter detection sensors
- Tree branches can fall and damage lighting fixtures
- Tall trees can provide climbing access over perimeter fences and block security lighting coverage (Correct answer)
- Tree roots can damage underground cable conduits
Correct answer: Tall trees can provide climbing access over perimeter fences and block security lighting coverage
Tall trees near the perimeter can be used as climbing aids to scale fences, and their canopies can block security lighting, creating dark zones that benefit intruders.
Question 119: What monitoring standard requires that a central station maintain a backup facility capable of taking over operations within a specified time if the primary station is incapacitated?
- NFPA 72 Chapter 26
- ANSI/SIA CP-01
- UL 827 (Central Station Alarm Services) (Correct answer)
- IEC 60839-11-1
Correct answer: UL 827 (Central Station Alarm Services)
UL 827 (Standard for Central Station Alarm Services) requires listed central stations to maintain backup facilities with the capability to assume full monitoring operations to ensure uninterrupted service.
Question 120: What is the best practice for handling security system maintenance during a facility's high-security events?
- Allow maintenance only in non-security areas
- Perform all routine maintenance to ensure systems are fresh for the event
- Freeze all non-emergency maintenance before and during the event, with all systems verified operational beforehand (Correct answer)
- Cancel all maintenance contracts during event periods
Correct answer: Freeze all non-emergency maintenance before and during the event, with all systems verified operational beforehand
Maintenance freezes during high-security events prevent disruptions while pre-event verification ensures all systems are fully operational.
Question 121: Under the Americans with Disabilities Act (ADA) and US privacy law, which area is generally PROHIBITED for video surveillance installation in a workplace?
- Restrooms and changing rooms (Correct answer)
- Break rooms and kitchens
- Parking lots and driveways
- Loading docks and shipping areas
Correct answer: Restrooms and changing rooms
Video surveillance in restrooms and changing rooms is prohibited under US federal and state privacy laws because individuals have a reasonable expectation of privacy in these locations.
Question 122: What camera resolution is generally recommended for reliable facial identification in a video surveillance system according to ASIS and IPVM guidelines?
- 20 pixels per foot (PPF)
- 40 pixels per foot (PPF)
- 80 pixels per foot (PPF)
- 100 pixels per foot (PPF) or higher (Correct answer)
Correct answer: 100 pixels per foot (PPF) or higher
Facial identification (recognizing a specific individual from a database) typically requires 100 PPF or higher, while facial detection requires approximately 40 PPF.
Question 123: What is the primary goal of asset protection in physical security?
- To increase operational efficiency
- To safeguard people, property, and information from threats (Correct answer)
- To enhance customer satisfaction
- To monitor employee behavior
Correct answer: To safeguard people, property, and information from threats
Asset protection in physical security is fundamentally about protecting an organization's valuable assets. This encompasses not only tangible property but also the people within the environment and critical information, by implementing measures to prevent unauthorized access, damage, or theft.
Question 124: Which fence type is recommended by ASIS for high-security applications due to its rigidity and resistance to cut-through attacks?
- Welded wire mesh panel fence (Correct answer)
- Wooden privacy fence
- Woven wire fence
- Chain-link fence (11-gauge)
Correct answer: Welded wire mesh panel fence
Welded wire mesh panel fences (such as 358 anti-cut mesh) offer superior resistance to cutting and climbing compared to chain-link due to their rigid construction and small aperture size.
Question 125: Which type of motion detector is MOST resistant to false alarms caused by HVAC air currents, heat vents, and changes in ambient temperature?
- Dual-technology (PIR + microwave) detector (Correct answer)
- Passive infrared (PIR) detector
- Ultrasonic detector
- Microwave (Doppler) detector
Correct answer: Dual-technology (PIR + microwave) detector
Dual-technology detectors require BOTH PIR and microwave to simultaneously trigger before generating an alarm, dramatically reducing false alarms caused by environmental factors that typically affect only one technology.
Physical Security Professional (PSP) Certification Exam
The Physical Security Professional (PSP) certification exam is administered by ASIS International and is designed for security practitioners responsible for conducting threat surveys, designing physical security systems, and implementing security measures. The exam covers physical security assessment, application of physical security measures, and implementation of security measures. Candidates must demonstrate expertise in risk management, access control, video surveillance, intrusion detection, perimeter security, CPTED principles, and security system integration.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds