โ† All CSC Flashcard Decks

Access Control & Perimeter Security Flashcards

7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Access Control & Perimeter Security flashcards as text
  1. Which principle states that an access control system should default to denying access unless explicit permission has been granted?

    Answer: Default deny (fail-secure)

    The default deny or fail-secure principle ensures that access is blocked unless it has been explicitly authorized, minimizing unintended access.

  2. A security consultant is evaluating electronic access control readers. Which technology is MOST vulnerable to cloning attacks without additional protections?

    Answer: 125 kHz proximity (Prox) cards

    125 kHz proximity cards transmit their card number in cleartext and are easily cloned using inexpensive readers available online.

  3. What is the purpose of a 'crash-rated' vehicle barrier rating system such as ASTM F2656?

    Answer: Certifying barriers based on their ability to stop a defined vehicle at a specific speed

    ASTM F2656 (and its predecessor K-ratings) certifies vehicle barriers by the vehicle class and speed they can stop, and how far the vehicle penetrates.

  4. In access control terminology, what is 'dual control' (also called two-person integrity)?

    Answer: Requiring two authorized individuals to be present for high-risk actions

    Dual control requires two authorized individuals to jointly perform a sensitive action, preventing any single person from acting alone on critical tasks.

  5. A perimeter intrusion detection system (PIDS) uses fiber-optic sensing cables buried along a fence line. What type of intrusion detection technology is this?

    Answer: Distributed acoustic sensing (DAS)

    Distributed acoustic sensing (DAS) uses fiber-optic cables to detect vibrations caused by digging, cutting, or climbing along a perimeter.

  6. Which access control concept ensures that an employee who transfers to a new role does NOT retain permissions from their previous role?

    Answer: Privilege creep prevention / access revocation

    Preventing privilege creep requires revoking old permissions when a user changes roles so they only hold permissions relevant to their current duties.

  7. What is the primary advantage of using an 'anti-passback' feature in an electronic access control system?

    Answer: Preventing the same credential from being used to enter and exit in the wrong sequence

    Anti-passback prevents a credential from being used to re-enter an area before it has been used to exit, stopping card sharing and tailgating.