← All CSC Flashcard Decks

Physical Security Operations Flashcards

7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Physical Security Operations flashcards as text
  1. A security consultant is developing an emergency response plan for an active-shooter incident at a corporate campus. Which protocol framework is now the MOST widely taught in U.S. commercial facilities?

    Answer: Run-Hide-Fight (Avoid-Deny-Defend)

    Run-Hide-Fight (or Avoid-Deny-Defend per CISA/ALERRT) is the dominant framework taught in U.S. workplaces, giving individuals a tiered set of options based on their proximity to and nature of the threat.

  2. During a post-incident review, it is discovered that security officers were unaware of which areas of the facility were cleared during an evacuation. Which tool or practice would BEST prevent this gap in future incidents?

    Answer: Implementing a sweep-and-report protocol with floor warden assignments

    A sweep-and-report protocol assigns specific officers or trained floor wardens to clear and confirm evacuation of designated areas, ensuring command knows which zones are cleared in real time.

  3. A security guard force operates under a post order that specifies response times for alarm activations. The guard fails to respond within the required time on multiple occasions. The MOST appropriate corrective action is:

    Answer: Review post orders with the guard, document the deficiency, and implement a performance improvement plan

    Progressive discipline—reviewing requirements, documenting deficiencies, and providing a performance improvement plan—is the standard corrective approach before escalating to termination.

  4. A facility security director wants to test the effectiveness of the physical security program without alerting staff. This type of assessment is called a:

    Answer: Red team or penetration test

    A red team exercise or physical penetration test involves unannounced, real-world attempts to bypass security controls to identify gaps that staff and technology might otherwise miss.

  5. When a security incident report documents that an intruder was apprehended at 02:14 hours inside a restricted server room, the FIRST priority for the security consultant reviewing the incident is to determine:

    Answer: How the intruder bypassed each layer of the physical security system

    Understanding exactly how each security layer was defeated—access control, detection, surveillance, and response—identifies root causes and informs corrective measures to prevent recurrence.

  6. A visitor management system (VMS) that cross-references visitor identities against a government watch list is performing which security function?

    Answer: Threat screening

    Cross-referencing against government or corporate watch lists is a threat screening function, designed to prevent known threats, sanctioned individuals, or persons of concern from gaining facility access.

  7. According to standard physical security practice, a security post order should be reviewed and updated at a MINIMUM of:

    Answer: Annually or after any significant incident or operational change

    Post orders should be reviewed at least annually and immediately after any significant incident, organizational change, or shift in threat environment to ensure they remain accurate and effective.