โ† All CSC Flashcard Decks

Physical Security Operations Flashcards

7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Physical Security Operations flashcards as text
  1. A security consultant is designing an access control system for a data center. Which authentication factor combination provides the highest assurance for physical entry?

    Answer: Smart card plus biometric

    Smart card plus biometric combines something-you-have with something-you-are, providing two distinct factor types and the highest assurance for critical facilities.

  2. During a physical security assessment, you observe that a facility uses a mantrap at its main entrance. What is the PRIMARY security function of a mantrap?

    Answer: To prevent piggybacking and tailgating

    A mantrap (also called an airlock or sally port) prevents unauthorized individuals from following authorized personnel through a secured entrance by ensuring only one person passes through at a time.

  3. A company's badge access logs show that an employee's credential was used to enter the facility at 8:02 AM, yet the employee reported arriving at 9:15 AM. This anomaly MOST likely indicates:

    Answer: Credential sharing or a cloned badge

    A credential used before the legitimate holder arrives is a strong indicator of credential sharing or a cloned/stolen badge being used by an unauthorized person.

  4. Which ASIS International standard provides guidelines for the development and implementation of an organizational resilience management system, including physical security components?

    Answer: ASIS ORM.1

    ASIS ORM.1 (Organizational Resilience Management System) provides requirements and guidance for resilience, while ASIS SPC.1 focuses specifically on supply chain security.

  5. A security consultant recommends installing anti-passback controls on an access system. What vulnerability does this control PRIMARILY address?

    Answer: A valid credential being used to exit before it has been used to enter

    Anti-passback prevents a credential from being used to exit an area before it has registered an entry, stopping one card from being passed back through a door to let another person in.

  6. When assessing a facility's key control program, which finding represents the GREATEST security risk?

    Answer: Duplicate keys are stored in an unlocked drawer in the security office

    Storing duplicate (or master) keys in an unlocked location completely undermines key control, as anyone with access to the security office can obtain unrestricted keys without detection.

  7. A CSC candidate is evaluating a facility that uses proximity card readers for access control. Which attack technique specifically targets these systems by reading a card's RF signal from a distance without the cardholder's knowledge?

    Answer: Skimming/eavesdropping

    Skimming (or RFID eavesdropping) captures the RF signal from a proximity card at a distance, allowing duplication of the credential without the cardholder being aware.