Safety and Security Practitioner (SSP) Certification — Questions and Answers
Question 1: Which standard published by ASIS International provides guidance on the design, operation, and evaluation of security management systems?
- ISO 31000 (Risk Management)
- ANSI/ASIS PSC.1 (Management Systems for Quality of Private Security Operations)
- ASIS SPC.1-2009 (Organizational Resilience)
- ASIS/ANSI ASMS-2022 (Security Management Systems) (Correct answer)
Correct answer: ASIS/ANSI ASMS-2022 (Security Management Systems)
The ASIS/ANSI ASMS standard provides a management system framework for security programs, including planning, implementation, evaluation, and continual improvement aligned with ISO high-level structure.
Question 2: What does CPTED stand for in the context of physical security design?
- Controlled Perimeter Threat and Entry Detection
- Crime Prevention Through Environmental Design (Correct answer)
- Comprehensive Protection Through Exterior Deterrents
- Critical Physical Technology for Entry Defense
Correct answer: Crime Prevention Through Environmental Design
CPTED is a design philosophy that uses the built environment—lighting, landscaping, sightlines—to deter criminal behavior and reduce opportunities for crime.
Question 3: What is 'piggybacking' (also called 'tailgating') in physical security terms?
- Using another person's ID badge to swipe access
- An authorized person allowing an unauthorized person to enter behind them through a controlled door (Correct answer)
- Carrying equipment through a security checkpoint without declaring it
- Cloning an access card to duplicate its credentials
Correct answer: An authorized person allowing an unauthorized person to enter behind them through a controlled door
Tailgating exploits social courtesy to bypass access controls without triggering an alarm or authentication event.
Question 4: A security officer discovers a colleague falsifying incident reports. The ethical obligation is to:
- Confront the colleague privately and allow self-correction
- Ignore it unless directly asked by management
- Document it personally but take no further action
- Report the misconduct through proper channels immediately (Correct answer)
Correct answer: Report the misconduct through proper channels immediately
Ethical compliance requires reporting misconduct through proper channels to maintain integrity and organizational accountability.
Question 5: In the context of SSP certification, what is the most important consideration when implementing security technology & systems?
- Ensuring alignment with established standards, stakeholder needs, and best practices (Correct answer)
- Minimizing documentation to save time
- Delegating all responsibilities to junior staff
- Completing implementation as quickly as possible regardless of quality
Correct answer: Ensuring alignment with established standards, stakeholder needs, and best practices
When implementing security technology & systems, SSP professionals must ensure alignment with industry standards and stakeholder needs. Hasty implementation without proper planning often leads to compliance issues and suboptimal outcomes.
Question 6: What is the purpose of a 'hot zone' designation during a hazmat incident?
- To identify the safest staging area for responders
- To restrict access to the area of highest contamination risk (Correct answer)
- To mark where decontamination stations are located
- To designate the command post location
Correct answer: To restrict access to the area of highest contamination risk
The hot zone (exclusion zone) is the area of highest contamination where only properly equipped responders may enter.
Question 7: Why is documentation important after an emergency?
- Evaluate and improve response (Correct answer)
- Avoid accountability
- Punish responders
- Ignore incidents
Correct answer: Evaluate and improve response
Documentation after an emergency is crucial for creating a detailed record of events, actions taken, and outcomes. This comprehensive data allows organizations to conduct a thorough post-incident analysis, identifying what worked well and what needs improvement in their emergency response plans. By evaluating past responses, organizations can refine procedures, enhance training, and strengthen overall preparedness for future incidents.
Question 8: A risk matrix uses likelihood and consequence axes. A threat rated 'possible' (3/5) with 'major' consequences (4/5) produces a risk score of 12. The organization's risk appetite threshold is 10. What action is required?
- The risk must be treated because it exceeds the risk appetite threshold (Correct answer)
- The risk may be accepted because the likelihood is moderate
- The risk can be deferred until the next assessment cycle
- No action is needed unless the consequence rating rises to 5/5
Correct answer: The risk must be treated because it exceeds the risk appetite threshold
A risk score of 12 exceeds the threshold of 10, so the organization's risk appetite requires a treatment plan.
Question 9: What is the primary purpose of biological monitoring in occupational health?
- To measure airborne contaminant concentrations at breathing zone level
- To determine if PPE is functioning within manufacturer specifications
- To comply with OSHA injury and illness recordkeeping requirements
- To assess the total internal dose of a chemical absorbed by a worker from all routes of exposure (Correct answer)
Correct answer: To assess the total internal dose of a chemical absorbed by a worker from all routes of exposure
Biological monitoring measures chemical agents or their metabolites in biological specimens (blood, urine) to assess total absorbed dose from all exposure routes.
Question 10: Which act prohibits employers from using polygraph (lie detector) tests on most private-sector employees?
- Fair Credit Reporting Act
- Employee Polygraph Protection Act (EPPA) (Correct answer)
- National Labor Relations Act
- Privacy Act of 1974
Correct answer: Employee Polygraph Protection Act (EPPA)
The EPPA prohibits most private employers from requiring, requesting, suggesting, or causing employees or applicants to take polygraph tests.
Question 11: Which type of fire extinguisher is appropriate for a Class C (energized electrical equipment) fire?
- Water-based extinguisher
- CO2 or dry chemical extinguisher (Correct answer)
- Wet chemical extinguisher
- Foam extinguisher
Correct answer: CO2 or dry chemical extinguisher
Class C fires involving energized electrical equipment require non-conductive agents such as CO2 or dry chemical extinguishers.
Question 12: During a shelter-in-place order for an airborne chemical release, occupants should FIRST:
- Evacuate immediately via the nearest exit
- Open windows on the downwind side to ventilate the building
- Move to an interior room and seal gaps in doors and windows (Correct answer)
- Report to the building rooftop to avoid ground-level contamination
Correct answer: Move to an interior room and seal gaps in doors and windows
Sheltering in place requires moving to an interior room and sealing openings to minimize infiltration of outside contaminants.
Question 13: A Passive Infrared (PIR) motion detector is most likely to produce a false alarm when:
- Battery backup power activates
- A person walks across its field of view
- The protected area is completely dark
- An HVAC vent changes room temperature rapidly (Correct answer)
Correct answer: An HVAC vent changes room temperature rapidly
PIR sensors detect changes in infrared energy; sudden temperature shifts from HVAC vents can mimic a human body signature and trigger false alarms.
Question 14: In video surveillance, what does the term 'pan-tilt-zoom' (PTZ) describe?
- A camera that can rotate horizontally, vertically, and magnify the image (Correct answer)
- A compression standard for video footage
- A multi-lens camera array covering 360 degrees
- A recording mode that alternates between cameras
Correct answer: A camera that can rotate horizontally, vertically, and magnify the image
PTZ cameras can pan (rotate left/right), tilt (angle up/down), and zoom optically, allowing operators to track subjects and examine details remotely.
Question 15: Which type of barrier is designed to stop a vehicle weighing 15,000 lbs traveling at 50 mph and is rated K-12?
- A standard concrete jersey barrier
- A crash-rated bollard meeting ASTM F2656 K12 standard (Correct answer)
- A cable barrier rated for pedestrian control
- A chain-link fence with barbed wire topping
Correct answer: A crash-rated bollard meeting ASTM F2656 K12 standard
The ASTM F2656 (formerly DOS/SD-STD-02.01) K-12 rating certifies vehicle barriers to stop a 15,000 lb vehicle at 50 mph with minimal penetration.
Question 16: What is the primary function of a video analytics system integrated with CCTV?
- Synchronize camera timestamps across a network
- Compress video footage for long-term archival storage
- Convert analog camera signals to IP-based streams
- Automatically analyze video to detect specific events or behaviors without constant human monitoring (Correct answer)
Correct answer: Automatically analyze video to detect specific events or behaviors without constant human monitoring
Video analytics software processes camera feeds in real time to automatically detect defined events—loitering, perimeter breach, abandoned objects—reducing reliance on continuous human monitoring.
Question 17: A company's BCP identifies a critical vendor as a single point of failure. Which resilience strategy directly addresses this risk?
- Extending the Recovery Time Objective
- Dual-sourcing or qualifying an alternate supplier (Correct answer)
- Documenting the vendor's contact information in the plan
- Increasing the vendor's contract value
Correct answer: Dual-sourcing or qualifying an alternate supplier
Dual-sourcing eliminates the single point of failure by ensuring a qualified backup supplier can fulfill the same function.
Question 18: A security professional who witnesses evidence being destroyed during an ongoing investigation should:
- Document what was observed and immediately report to legal counsel (Correct answer)
- Dispose of any related records to avoid contamination
- Attempt to recover the evidence personally before reporting
- Wait to see if additional evidence surfaces before acting
Correct answer: Document what was observed and immediately report to legal counsel
Observing evidence destruction must be immediately documented and reported to legal counsel to preserve legal options and comply with spoliation rules.
Question 19: What does the term 'means of egress' include according to NFPA 101?
- The exit access and exit only
- Only the exit doors
- The exit access, exit, and exit discharge (Correct answer)
- Only the exit stairwells
Correct answer: The exit access, exit, and exit discharge
NFPA 101 defines means of egress as a continuous and unobstructed path consisting of three parts: exit access, exit, and exit discharge.
Question 20: A safety practitioner is developing a regulatory response strategy after receiving multiple citations. Which approach best balances legal exposure reduction with operational continuity?
- Seek an indefinite abatement extension for all citations simultaneously
- Contest all citations regardless of merit to maximize negotiating leverage
- Pay all penalties without contesting to avoid further regulatory scrutiny
- Prioritize abating the most serious violations immediately while evaluating merits of lesser citations for potential informal conference resolution (Correct answer)
Correct answer: Prioritize abating the most serious violations immediately while evaluating merits of lesser citations for potential informal conference resolution
Abating serious violations demonstrates good faith and reduces injury risk, while evaluating lesser citations for informal conference resolution preserves resources and maintains operational continuity.
Question 21: During an active threat response, the 'Hide' option should involve all of the following EXCEPT:
- Locking or barricading the door
- Sending a group text to warn others in the building
- Opening doors to allow fleeing coworkers to enter (Correct answer)
- Turning off lights and silencing phones
Correct answer: Opening doors to allow fleeing coworkers to enter
Opening doors during a hide response can compromise the secured space; individuals sheltering should keep doors locked and barricaded.
Question 22: What security principle does 'defense in depth' apply when designing physical security systems?
- Layering multiple independent security controls so that defeating one does not compromise the whole system (Correct answer)
- Prioritizing digital over physical security measures
- Placing all security resources at the outermost perimeter
- Using one highly reliable system instead of many redundant ones
Correct answer: Layering multiple independent security controls so that defeating one does not compromise the whole system
Defense in depth uses multiple, overlapping security layers (fencing, lighting, cameras, access control, guards) so an adversary must overcome each layer independently.
Question 23: A security professional discovers that a new company policy requires actions that conflict with the professional code of ethics. The best course of action is to:
- Immediately resign without attempting to address the issue internally
- Comply with company policy since employment obligations supersede professional ethics
- Anonymously report the policy to a regulatory body without internal discussion
- Raise the conflict with management and, if unresolved, consult legal or ethics guidance (Correct answer)
Correct answer: Raise the conflict with management and, if unresolved, consult legal or ethics guidance
Ethical conflicts should first be raised internally; if unresolved, consulting legal counsel or professional ethics boards ensures obligations are properly addressed.
Question 24: What is the importance of legal compliance in security?
- Ignore regulations
- Adhere to laws and reduce risks (Correct answer)
- Increase costs unnecessarily
- Avoid training
Correct answer: Adhere to laws and reduce risks
Legal compliance in security ensures that all operations, procedures, and personnel actions strictly adhere to relevant laws, regulations, and industry standards. Adhering to these legal frameworks protects the organization from significant financial penalties, lawsuits, and reputational damage. It also establishes a foundation of ethical and responsible conduct, thereby reducing overall legal and operational risks.
Question 25: A safety practitioner is evaluating noise levels in a manufacturing facility. Which instrument should be used to measure a worker's actual personal noise dose over a full shift?
- Noise dosimeter (Correct answer)
- Sound level meter
- Impact noise meter
- Octave band analyzer
Correct answer: Noise dosimeter
A noise dosimeter is worn by the worker and integrates exposure over the entire shift, providing an accurate personal dose measurement.
Question 26: In a regulatory enforcement context, what distinguishes a 'consent agreement and final order' (CAFO) from a traditional settlement?
- A CAFO eliminates all future regulatory oversight for the settling party
- A CAFO is a negotiated settlement that resolves violations without admitting liability and is executed by the agency head (Correct answer)
- A CAFO is only available for criminal violations
- A CAFO requires court approval while a traditional settlement does not
Correct answer: A CAFO is a negotiated settlement that resolves violations without admitting liability and is executed by the agency head
A CAFO is an EPA administrative enforcement tool that resolves civil violations through a negotiated agreement that does not require an admission of liability.
Question 27: What is the effect of non-compliance with laws?
- Ignore consequences
- Penalties and reputation loss (Correct answer)
- Reward
- Promotion
Correct answer: Penalties and reputation loss
Non-compliance with laws and regulations can lead to significant negative consequences for an organization. These can include substantial financial penalties, legal sanctions, and even criminal charges, which directly impact the organization's bottom line. Furthermore, non-compliance severely damages its reputation and public trust, affecting stakeholder relationships, business operations, and long-term viability.
Question 28: Which wiring topology provides the highest fault tolerance for a fire alarm system by allowing the system to continue operating if a single break occurs in the circuit?
- Class B (Style A/B) wiring
- Star topology
- Daisy-chain topology
- Class A (Style D/E) wiring (Correct answer)
Correct answer: Class A (Style D/E) wiring
Class A wiring loops back to the panel on both ends, so a single open circuit does not disable the devices; the panel can still communicate with all devices from the other direction.
Question 29: When interviewing a potential whistleblower during a regulatory investigation, investigators should prioritize which approach?
- Require the whistleblower to submit a sworn affidavit before any discussion occurs
- Immediately confirm the whistleblower's identity to the employer for verification
- Protect the whistleblower's identity to the extent permitted by law and document their account thoroughly (Correct answer)
- Discourage the whistleblower from legal representation to streamline the interview
Correct answer: Protect the whistleblower's identity to the extent permitted by law and document their account thoroughly
Whistleblower protection laws under OSH Act Section 11(c) and other statutes require investigators to protect the identity of reporting individuals to prevent retaliation.
Question 30: What is an ethical dilemma?
- Ignoring laws
- Conflicting moral principles (Correct answer)
- Following orders blindly
- Easy choice
Correct answer: Conflicting moral principles
An ethical dilemma arises when an individual or organization faces a situation where two or more moral principles or values are in conflict, making it difficult to determine the 'right' course of action. There is no clear-cut solution, and choosing one option often means compromising another deeply held value. Resolving such dilemmas requires careful consideration of ethical frameworks and potential consequences.
Question 31: An organization's risk appetite statement says it will 'accept risks up to $500,000 ALE without mandatory escalation.' A new risk is calculated at $650,000 ALE. Which action is REQUIRED?
- The risk must be escalated to senior leadership or the board for a treatment or acceptance decision (Correct answer)
- The risk must be immediately transferred to an insurer because it exceeds appetite
- The risk can be accepted by the security manager since it is only slightly above threshold
- The risk assessment must be recalculated using a different methodology to lower the ALE
Correct answer: The risk must be escalated to senior leadership or the board for a treatment or acceptance decision
The risk appetite statement defines the escalation trigger; a $650,000 ALE exceeds the $500,000 threshold and mandates senior leadership review.
Question 32: What is the most effective way to measure success in business continuity & resilience within SSP professional practice?
- Compare only with industry averages without considering context
- Count only the number of activities completed
- Use a combination of quantitative metrics, qualitative assessments, and stakeholder feedback aligned with defined objectives (Correct answer)
- Rely solely on supervisor opinion
Correct answer: Use a combination of quantitative metrics, qualitative assessments, and stakeholder feedback aligned with defined objectives
Effective measurement combines multiple data sources — quantitative metrics, qualitative assessments, and stakeholder feedback — all aligned with clearly defined objectives for a comprehensive evaluation.
Question 33: What is residual risk?
- Unidentified risk
- Eliminated risk
- Risk before controls
- Risk after controls (Correct answer)
Correct answer: Risk after controls
Residual risk refers to the level of risk that remains after all implemented risk mitigation controls and countermeasures have been put in place. It represents the inherent risk that an organization must accept, even after taking all reasonable steps to reduce it.
Question 34: What is the primary vulnerability addressed by installing anti-passback in an access control system?
- Preventing a credential from being used twice in a row at the same entry point without an exit (Correct answer)
- Encrypting card data during transmission
- Detecting cloned access credentials
- Blocking tailgating via door timing alerts
Correct answer: Preventing a credential from being used twice in a row at the same entry point without an exit
Anti-passback requires that a credential used to enter a zone must be used to exit before it can be used to enter again, preventing credential sharing and piggyback entry.
Question 35: A confined space is classified as 'permit-required' under OSHA 29 CFR 1910.146 if it:
- Requires a ladder for entry
- Contains or has the potential to contain a serious safety or health hazard (Correct answer)
- Has been entered by an employee in the last 12 months
- Has an opening larger than 18 inches in diameter
Correct answer: Contains or has the potential to contain a serious safety or health hazard
A permit-required confined space contains or has potential to contain a serious hazard such as a hazardous atmosphere, engulfment potential, converging walls, or other recognized serious safety or health hazard.
Question 36: Which term describes the process of redistributing risk to a third party, such as through insurance or contractual agreements?
- Risk acceptance
- Risk avoidance
- Risk transfer (Correct answer)
- Risk mitigation
Correct answer: Risk transfer
Risk transfer shifts the financial or operational burden of a risk to another party, commonly through insurance policies or vendor contracts.
Question 37: A security practitioner is asked by an executive to share confidential employee investigation records with HR without a formal request. The correct action is to:
- Refuse permanently regardless of circumstances
- Share the records since HR is an internal department
- Require a formal written request following established protocols (Correct answer)
- Share only a verbal summary to avoid documentation
Correct answer: Require a formal written request following established protocols
Confidential investigation records must be shared only through formal, documented requests to maintain chain of custody and legal defensibility.
Question 38: Which of the following best describes a key competency required for business continuity & resilience in SSP practice?
- Strong analytical skills combined with effective communication and ethical judgment (Correct answer)
- The ability to work independently without any oversight
- Memorization of all relevant regulations without understanding context
- Reliance on a single methodology for all situations
Correct answer: Strong analytical skills combined with effective communication and ethical judgment
SSP professionals working in business continuity & resilience need analytical skills to assess situations, communication skills to convey findings, and ethical judgment to make sound decisions.
Question 39: What does CCTV stand for?
- Common Camera Technology
- Controlled Circuit TV
- Central Control Television
- Closed Circuit Television (Correct answer)
Correct answer: Closed Circuit Television
CCTV stands for Closed Circuit Television, a system where video signals are transmitted to a limited set of monitors, unlike broadcast television. It is widely used in security operations for surveillance, monitoring, and recording activities in specific areas to enhance safety and deter crime.
Question 40: What is the key advantage of fiber optic cable over copper cable for perimeter intrusion detection?
- Immune to electromagnetic interference and very difficult to tap without detection (Correct answer)
- Lower cost and easier to install in wet environments
- Higher voltage capacity for powering sensors
- Better compatibility with legacy analog alarm systems
Correct answer: Immune to electromagnetic interference and very difficult to tap without detection
Fiber optic cables transmit light rather than electrical signals, making them immune to EMI, lightning, and virtually impossible to tap without causing a detectable signal disruption.
Question 41: When conducting a threat assessment, which factor is considered the MOST significant predictor of future violence?
- Lack of higher education
- Recent changes in job title
- Past history of violent behavior (Correct answer)
- Current financial difficulties
Correct answer: Past history of violent behavior
The single strongest predictor of future violent behavior is a documented history of past violence.
Question 42: Under TSA regulations, which document governs security requirements for surface transportation operators such as freight rail and mass transit?
- Transportation Security Plans (TSP)
- DHS Critical Infrastructure Protection Plans
- Security Directives issued under 49 CFR Part 1580 (Correct answer)
- FEMA National Response Framework
Correct answer: Security Directives issued under 49 CFR Part 1580
49 CFR Part 1580 governs rail transportation security and empowers TSA to issue Security Directives to surface transportation operators.
Question 43: What is the purpose of a Continuity of Government (COG) plan at the federal level?
- To maintain the constitutional authority and essential functions of government during a catastrophic emergency (Correct answer)
- To regulate private sector business continuity standards
- To ensure tax collection continues during a recession
- To coordinate international disaster relief efforts
Correct answer: To maintain the constitutional authority and essential functions of government during a catastrophic emergency
COG plans ensure that the executive, legislative, and judicial branches can continue to operate and exercise constitutional authority during a national emergency.
Question 44: When conducting a pre-employment background investigation, failure to obtain written authorization from the applicant violates which federal law?
- Employee Polygraph Protection Act
- National Labor Relations Act
- Americans with Disabilities Act
- Fair Credit Reporting Act (FCRA) (Correct answer)
Correct answer: Fair Credit Reporting Act (FCRA)
The FCRA requires written disclosure and authorization before obtaining consumer reports (including background checks) for employment purposes.
Question 45: A security manager instructs staff to search employee personal vehicles in the parking lot without consent or policy authority. This most likely violates:
- Fourth Amendment protections against unreasonable searches (Correct answer)
- Fair Labor Standards Act
- National Labor Relations Act
- OSHA General Duty Clause
Correct answer: Fourth Amendment protections against unreasonable searches
Unauthorized searches of personal property can violate Fourth Amendment protections and expose the organization to significant civil liability.
Question 46: Which type of door lock is classified as 'fail-safe' in fire egress scenarios?
- Deadbolt with battery backup
- Delayed egress lock with 30-second timer
- Electric strike that locks when power is cut
- Electromagnetic lock that releases when power is cut (Correct answer)
Correct answer: Electromagnetic lock that releases when power is cut
Fail-safe locks (like mag-locks) default to the unlocked/open position when power is lost, ensuring egress during fire or power failure.
Question 47: A company stores its only BCP document copy in the primary headquarters building. Why is this problematic?
- It prevents external auditors from reviewing the plan
- It reduces response speed during incidents
- The plan may be inaccessible precisely when it is needed most — during a disaster affecting that building (Correct answer)
- It creates a regulatory compliance violation
Correct answer: The plan may be inaccessible precisely when it is needed most — during a disaster affecting that building
If the primary facility is the disaster site, storing the only copy there ensures the plan is unavailable when it is most critical.
Question 48: Which recovery strategy involves contracting with an external organization to perform specific business functions if an internal disruption occurs?
- Cold site activation
- Mutual aid agreement
- Manual fallback procedures
- Business Process Outsourcing (BPO) contingency arrangement (Correct answer)
Correct answer: Business Process Outsourcing (BPO) contingency arrangement
A BPO contingency arrangement pre-arranges for a third party to assume specific operational functions during a disruption, maintaining service continuity.
Question 49: A practitioner is reviewing a risk treatment plan and finds that the proposed control will reduce likelihood but NOT reduce consequence. What type of control is this?
- A preventive control that reduces the probability of the threat event occurring (Correct answer)
- A compensating control that replaces a failed primary control
- A corrective control that restores operations after an incident
- A detective control that identifies incidents after they occur
Correct answer: A preventive control that reduces the probability of the threat event occurring
Controls that reduce likelihood are preventive—they make a threat event less likely without changing the severity if it does occur.
Question 50: Which type of business impact analysis (BIA) output directly informs the selection of recovery strategies?
- Criticality rankings and recovery time/point objectives for each function (Correct answer)
- List of all organizational assets
- Budget allocation for the continuity program
- Staff contact directory for incident response
Correct answer: Criticality rankings and recovery time/point objectives for each function
Criticality rankings combined with RTO and RPO values tell planners which functions must be recovered first and how quickly, driving strategy selection.
Question 51: How should SSP professionals handle confidential information related to regulatory investigation & response?
- Store information without any security measures
- Share freely with all colleagues for transparency
- Delete all records after project completion
- Follow established protocols for data protection, access control, and disclosure in accordance with applicable regulations (Correct answer)
Correct answer: Follow established protocols for data protection, access control, and disclosure in accordance with applicable regulations
Confidential information must be handled according to established protocols, regulatory requirements, and professional ethics standards, including proper access control and disclosure procedures.
Question 52: The concept of 'span of control' in ICS recommends that each supervisor manage no more than how many individuals?
- 3 to 7 subordinates (Correct answer)
- 1 to 3 subordinates
- 8 to 12 subordinates
- 10 to 15 subordinates
Correct answer: 3 to 7 subordinates
ICS recommends a span of control between 3 and 7 (optimal: 5) to maintain effective supervision without overwhelming any single supervisor.
Question 53: How should conflicts of interest be handled?
- Ignore
- Disclose and avoid conflicts (Correct answer)
- Exploit
- Conceal
Correct answer: Disclose and avoid conflicts
Conflicts of interest arise when an individual's personal interests or relationships could potentially influence their professional judgment or actions in a way that benefits them personally or a third party, rather than the organization. The proper handling involves transparently disclosing any potential conflict to relevant parties and taking steps to avoid or mitigate the conflict, such as recusing oneself from decisions. This ensures impartiality, maintains trust, and upholds ethical standards.
Question 54: Which of the following best describes 'convergence' in modern security programs?
- The merger of fire safety and environmental systems under one manager
- The standardization of access card formats across all facilities
- The consolidation of all guard posts into a single control room
- The integration of physical security and cybersecurity into a unified risk management program (Correct answer)
Correct answer: The integration of physical security and cybersecurity into a unified risk management program
Security convergence unifies physical security (access control, surveillance) and information security (cyber) under a single governance framework, recognizing that threats often span both domains.
Question 55: Which of the following best describes the purpose of a Job Hazard Analysis (JHA)?
- Establish the minimum staffing ratio for a work crew
- Document worker compensation claims for a specific task
- Identify hazards associated with each step of a job and determine controls (Correct answer)
- Assess the ergonomic design of office workstations
Correct answer: Identify hazards associated with each step of a job and determine controls
A JHA breaks a job into individual steps, identifies potential hazards at each step, and recommends controls to eliminate or reduce risk.
Question 56: An OSHA compliance officer requests to conduct an inspection without advance notice. What authority does OSHA have in this situation?
- OSHA can only inspect during non-operational hours
- OSHA requires a court order for any workplace entry
- OSHA can conduct warrantless inspections of regulated workplaces with probable cause or voluntary consent (Correct answer)
- OSHA must provide 72 hours advance notice for all inspections
Correct answer: OSHA can conduct warrantless inspections of regulated workplaces with probable cause or voluntary consent
Under Marshall v. Barlow's Inc., OSHA must obtain a warrant if consent is refused, but consent-based or probable-cause warrantless inspections are permitted.
Question 57: Which document produced during a security design project defines the owner's security objectives, performance criteria, and basis of design decisions?
- Operational Requirements Document (ORD)
- Security Master Plan
- Commissioning Test Plan
- Basis of Design (BOD) / Security Narrative (Correct answer)
Correct answer: Basis of Design (BOD) / Security Narrative
The Basis of Design document records design intent, performance goals, and assumptions—serving as the foundational reference for all subsequent security design decisions.
Question 58: What is the role of risk assessment in emergency planning?
- Ignore risks
- Avoid responsibility
- Delay planning
- Identify hazards and prepare (Correct answer)
Correct answer: Identify hazards and prepare
Risk assessment is a fundamental component of emergency planning, involving the systematic identification of potential hazards, vulnerabilities, and the likelihood and impact of their occurrence. By understanding these specific risks, organizations can proactively develop targeted strategies, allocate resources, and implement preventative or mitigating measures. This process ensures that emergency plans are tailored to address the most probable and impactful threats, leading to more effective preparedness.
Question 59: What is an emergency operations plan (EOP)?
- Framework for emergency roles and procedures (Correct answer)
- Communication plan
- Financial plan
- Training manual
Correct answer: Framework for emergency roles and procedures
An Emergency Operations Plan (EOP) is a comprehensive document that outlines an organization's structured approach to managing emergencies. It defines roles and responsibilities, establishes clear procedures for various incident types, and coordinates resources to ensure an effective and unified response.
Question 60: When a SSP professional encounters an unfamiliar challenge in physical security design & implementation, what is the recommended first course of action?
- Proceed based on personal intuition alone
- Apply the solution used for the most recent similar problem without adaptation
- Postpone addressing the issue indefinitely
- Research applicable standards, consult with subject matter experts, and document the approach (Correct answer)
Correct answer: Research applicable standards, consult with subject matter experts, and document the approach
Professional practice requires a methodical approach to unfamiliar challenges: research the applicable standards, consult experts when needed, and document the reasoning for the chosen approach.
Question 61: An organization experiences a cyberattack during an ongoing natural disaster. This scenario is best described as a:
- Secondary incident
- Crisis amplification
- Cascading or compound disaster (Correct answer)
- Force majeure event
Correct answer: Cascading or compound disaster
A cascading or compound disaster occurs when multiple simultaneous or sequential events interact, complicating response and recovery efforts.
Question 62: In a criminal proceeding, the standard of proof required to obtain a conviction is:
- Clear and convincing evidence
- Beyond a reasonable doubt (Correct answer)
- Probable cause
- Preponderance of the evidence
Correct answer: Beyond a reasonable doubt
Criminal convictions require proof beyond a reasonable doubt, the highest standard in the legal system, to protect against wrongful convictions.
Question 63: Which suppression agent is most appropriate for protecting a server room containing sensitive electronics?
- Clean agent gaseous suppression (Correct answer)
- Deluge system
- Dry pipe sprinklers
- Wet pipe sprinklers
Correct answer: Clean agent gaseous suppression
Clean agent gaseous suppression systems extinguish fires without leaving residue or causing water damage to sensitive electronic equipment.
Question 64: In an integrated security system, the component that correlates alarms from multiple subsystems and presents a unified operational picture is called the:
- Physical Security Information Management (PSIM) platform (Correct answer)
- Intrusion Detection Panel (IDP)
- Access Control Management System (ACMS)
- Video Management System (VMS)
Correct answer: Physical Security Information Management (PSIM) platform
A PSIM integrates data from access control, video, intrusion, and other systems into one interface, enabling coordinated incident response.
Question 65: Why are patrols important in security operations?
- Deliver packages
- Manage visitor logs
- Monitor employee productivity
- Detect and deter threats (Correct answer)
Correct answer: Detect and deter threats
Security patrols are essential for maintaining a visible security presence, which acts as a deterrent to potential threats and criminal activity. Patrolling personnel can actively detect suspicious behavior, identify vulnerabilities, and respond quickly to incidents, enhancing overall safety and security.
Question 66: What is 'sterile area bypass,' and why is it a critical security concern?
- A fire evacuation route that circumvents normal exit procedures
- An approved procedure for diplomats with immunity
- Unauthorized access to the post-screening zone without passing through security, which defeats the integrity of screening (Correct answer)
- A maintenance shortcut through cargo areas, posing contamination risk
Correct answer: Unauthorized access to the post-screening zone without passing through security, which defeats the integrity of screening
Sterile area bypass allows an unscreened person to access the secure zone, potentially introducing prohibited items past the security checkpoint.
Question 67: Under the Americans with Disabilities Act (ADA), what must security personnel consider when detaining a person who appears impaired?
- Security personnel are exempt from ADA compliance
- Disabilities are not covered during security incidents
- The person may have a disability rather than be intoxicated (Correct answer)
- ADA exemptions apply when public safety is threatened
Correct answer: The person may have a disability rather than be intoxicated
Security personnel must consider that apparent impairment may be a disability such as epilepsy or diabetes, and act accordingly to avoid ADA violations.
Question 68: A security officer at a data center is asked by a visitor presenting a law enforcement badge to view server logs without a warrant or subpoena. The officer should:
- Verify the badge number online and then grant access
- Provide immediate access as law enforcement supersedes company policy
- Allow supervised viewing but not printing or copying
- Deny access and refer the request to legal counsel or management (Correct answer)
Correct answer: Deny access and refer the request to legal counsel or management
Private facilities generally require proper legal process (warrant/subpoena) before disclosing records; immediate compliance without legal review creates liability.
Question 69: Which standard provides guidance on security management systems for organizations in the supply chain?
- OSHA 29 CFR 1910
- ISO 9001
- ISO 28000 (Correct answer)
- NIST SP 800-53
Correct answer: ISO 28000
ISO 28000 specifies requirements for a security management system for the supply chain, including transportation.
Question 70: Which document type outlines the specific mission, objectives, and resource assignments for a single operational period during an incident?
- Incident Action Plan (IAP) (Correct answer)
- Emergency Operations Plan (EOP)
- Continuity of Operations Plan (COOP)
- Hazard Mitigation Plan (HMP)
Correct answer: Incident Action Plan (IAP)
An IAP is developed for each operational period and provides tactical direction, objectives, and resource assignments for that specific timeframe.
Question 71: Which access control topology stores credential data and makes access decisions at each individual reader rather than a central server?
- Peer-to-peer mesh architecture
- Distributed (edge-based) architecture (Correct answer)
- Hybrid cloud architecture
- Centralized architecture
Correct answer: Distributed (edge-based) architecture
Distributed or edge-based access control stores rules locally at the door controller, allowing access decisions even if the server is offline.
Question 72: Which component of an Emergency Operations Center (EOC) ensures that resource requests from the field are tracked and fulfilled?
- Public information officer function
- Finance and administration section
- Medical support unit
- Resource management and tracking function (Correct answer)
Correct answer: Resource management and tracking function
The resource management function within an EOC tracks requests, allocates resources, and monitors deployment status throughout the incident.
Question 73: Which standard governs the testing and rating of bullet-resistant glazing materials in the US?
- NIJ 0108.01
- UL 752 (Correct answer)
- ANSI Z97.1
- ASTM F1233
Correct answer: UL 752
UL 752 is the Underwriters Laboratories standard for bullet-resisting equipment, rating glazing into eight levels based on the ammunition type they resist.
Question 74: When conducting a post-incident analysis (After Action Review), which question is MOST important to address first?
- Which responders need additional training?
- How much did the incident cost the organization?
- Who made the first mistake during the response?
- What was supposed to happen according to the plan? (Correct answer)
Correct answer: What was supposed to happen according to the plan?
A post-incident review begins by establishing the intended plan as a baseline before comparing actual events to identify gaps.
Question 75: A security practitioner performing a business impact analysis (BIA) identifies that a payroll system has a Recovery Time Objective (RTO) of 4 hours. What does this mean for risk management?
- The system has a 4-hour window before a disruption is reportable to regulators
- Payroll data must be backed up every 4 hours to prevent loss
- Any risk treatment must ensure the system can be restored within 4 hours of a disruption (Correct answer)
- Risk acceptance for this system is valid for up to 4 hours per incident
Correct answer: Any risk treatment must ensure the system can be restored within 4 hours of a disruption
An RTO of 4 hours means risk controls must support restoring the payroll system within that window to meet business continuity requirements.
Question 76: What is the purpose of an uninterruptible power supply (UPS) in a security system?
- Synchronize clocks on all security devices
- Regulate voltage spikes to prevent equipment damage only
- Encrypt power-line communications
- Provide continuous power to security equipment during utility outages (Correct answer)
Correct answer: Provide continuous power to security equipment during utility outages
A UPS maintains continuous electrical power to security equipment—cameras, access control panels, alarms—during power outages, ensuring system operation until backup generators start.
Question 77: Under OSHA's Bloodborne Pathogens Standard, which practice is the PRIMARY method for preventing occupational exposure to HIV and HBV?
- Annual hepatitis B vaccination
- Post-exposure prophylaxis
- Double-gloving for all tasks
- Universal Precautions (Correct answer)
Correct answer: Universal Precautions
Universal Precautions treat all human blood and certain body fluids as if infectious, forming the primary prevention strategy under 29 CFR 1910.1030.
Question 78: Under the Aviation and Transportation Security Act (ATSA), who is the primary federal authority responsible for civil aviation security?
- DHS Office of Intelligence
- FBI
- FAA
- TSA (Correct answer)
Correct answer: TSA
ATSA, enacted in 2001, created TSA and designated it as the primary federal authority for civil aviation security.
Question 79: An organization's risk committee reviews a risk treatment proposal that will reduce residual risk from 'High' to 'Medium' but requires a $2 million investment. The asset's total value is $500,000. What concern should the committee raise?
- The control cost exceeds the asset value, making the investment economically unjustifiable without additional justification (Correct answer)
- The residual risk of 'Medium' is unacceptable and the committee should demand 'Low' risk
- The committee should accept the proposal because reducing risk from High to Medium is always worth the cost
- The asset should be immediately decommissioned since it carries High risk
Correct answer: The control cost exceeds the asset value, making the investment economically unjustifiable without additional justification
Spending $2 million to protect a $500,000 asset violates the cost-benefit principle; the control cost should not exceed the protected value without compelling justification.
Question 80: Which type of smoke detector is most effective at detecting slow, smoldering fires?
- Photoelectric detector (Correct answer)
- Projected beam detector
- Ionization detector
- Heat detector
Correct answer: Photoelectric detector
Photoelectric detectors use a light beam and sensor that responds quickly to the large smoke particles produced by slow, smoldering fires.
Question 81: A corrective action plan submitted to a regulatory agency should include which core components?
- Root cause analysis, specific corrective measures, responsible parties, and target completion dates (Correct answer)
- Employee disciplinary actions taken and insurance claim documentation
- A denial of wrongdoing, legal arguments, and request for case dismissal
- Only the technical fix applied, with no documentation of root cause
Correct answer: Root cause analysis, specific corrective measures, responsible parties, and target completion dates
Effective corrective action plans must address root cause, define specific fixes, assign accountability, and set measurable timelines for completion.
Question 82: Under OSHA's Emergency Action Plan standard (29 CFR 1910.38), how many employees triggers the requirement for a written EAP?
- More than 10 employees (Correct answer)
- More than 25 employees
- More than 100 employees
- More than 50 employees
Correct answer: More than 10 employees
OSHA requires a written EAP when an employer has more than 10 employees; smaller organizations may communicate the plan orally.
Question 83: The Transportation Worker Identification Credential (TWIC) program primarily applies to which workforce?
- Truck drivers transporting household goods
- Maritime facility and vessel workers requiring unescorted access to secure areas (Correct answer)
- All federal transportation employees
- Commercial airline pilots only
Correct answer: Maritime facility and vessel workers requiring unescorted access to secure areas
TWIC provides a tamper-resistant biometric credential to maritime workers requiring unescorted access to secure areas of MTSA-regulated facilities.
Question 84: In the context of SSP certification, what is the most important consideration when implementing environmental health & safety?
- Delegating all responsibilities to junior staff
- Ensuring alignment with established standards, stakeholder needs, and best practices (Correct answer)
- Minimizing documentation to save time
- Completing implementation as quickly as possible regardless of quality
Correct answer: Ensuring alignment with established standards, stakeholder needs, and best practices
When implementing environmental health & safety, SSP professionals must ensure alignment with industry standards and stakeholder needs. Hasty implementation without proper planning often leads to compliance issues and suboptimal outcomes.
Question 85: What is the significance of whistleblower protection?
- Ignore reports
- Punish reporters
- Delay investigations
- Protect reporters from retaliation (Correct answer)
Correct answer: Protect reporters from retaliation
Whistleblower protection laws and policies are designed to safeguard individuals who report illegal, unethical, or harmful activities within an organization from adverse actions, such as demotion, termination, or harassment. This protection encourages transparency and accountability by empowering employees to come forward with critical information without fear of reprisal. It is vital for uncovering wrongdoing and maintaining organizational integrity.
Question 86: What is a risk mitigation strategy?
- Ignoring hazards
- Increasing risks
- Reporting accidents
- Reducing or eliminating risks (Correct answer)
Correct answer: Reducing or eliminating risks
A risk mitigation strategy involves implementing specific actions or controls designed to reduce the likelihood of a risk occurring or to lessen the severity of its impact if it does. The ultimate goal is to either diminish the risk to an acceptable level or, ideally, eliminate it entirely.
Question 87: Under OSHA's Process Safety Management (PSM) standard, which chemical triggers PSM coverage when stored at or above 10,000 pounds?
- Chlorine
- Anhydrous ammonia
- All of the above except chlorine
- Flammable liquids with a flash point below 100°F (Correct answer)
Correct answer: Flammable liquids with a flash point below 100°F
Under PSM (29 CFR 1910.119), flammable liquids and gases present in quantities of 10,000 lbs or more at or above their boiling point trigger coverage; individual highly hazardous chemicals have their own specific threshold quantities.
Question 88: During recovery operations, a team discovers the documented recovery procedures are outdated and incomplete. What is the root cause failure this exposes?
- Failure to maintain and regularly test the BCP (Correct answer)
- Poor communication with executive leadership
- Inadequate funding for recovery resources
- Insufficient staffing during the incident
Correct answer: Failure to maintain and regularly test the BCP
Outdated procedures indicate the BCP was not regularly reviewed, updated, and tested — a core maintenance failure in the continuity program lifecycle.
Question 89: What type of attack involves using a legitimate commercial vehicle as a weapon against a crowded transportation hub?
- Denial-of-service infrastructure attack
- Vehicle-borne improvised explosive device (VBIED) or vehicle ramming attack (Correct answer)
- Insider threat incident
- Cyber-physical attack
Correct answer: Vehicle-borne improvised explosive device (VBIED) or vehicle ramming attack
Vehicle ramming attacks and VBIEDs use commercial or personal vehicles as weapons against crowded areas, a recognized threat to transportation infrastructure.
Question 90: What does 'OSDP' stand for and what is its security relevance?
- On-Site Detection Protocol — a perimeter alarm standard
- Operational Security Defense Policy — a facility security framework
- Open Supervised Device Protocol — a secure, bidirectional communication standard for access control readers (Correct answer)
- Object Sensor Data Platform — an IoT security integration standard
Correct answer: Open Supervised Device Protocol — a secure, bidirectional communication standard for access control readers
OSDP (Open Supervised Device Protocol) is an access control communication standard that supports AES-128 encryption and bidirectional supervision between readers and controllers.
Question 91: An organization activates its BCP but recovery efforts are slowed because staff are unfamiliar with their assigned roles. Which program element failed?
- Executive sponsorship
- Risk assessment methodology
- Vendor management process
- Training and awareness program (Correct answer)
Correct answer: Training and awareness program
If personnel do not know their roles during activation, the training and awareness component of the BCP program has not been adequately implemented.
Question 92: What is the purpose of legal audits in security?
- Increase risks
- Ignore laws
- Ensure legal compliance (Correct answer)
- Reduce paperwork
Correct answer: Ensure legal compliance
The primary purpose of legal audits in security is to systematically review an organization's security policies, procedures, and practices to ensure they align with all applicable laws, regulations, and industry standards. These audits identify any gaps or deficiencies in compliance, allowing the organization to address them proactively. This helps mitigate legal risks, avoid penalties, and maintain a robust and legally sound security posture.
Question 93: What is the role of codes of conduct?
- Reduce training
- Create bureaucracy
- Guide behavior and ethics (Correct answer)
- Restrict employee freedom
Correct answer: Guide behavior and ethics
Codes of conduct are formal documents that outline the expected standards of behavior, ethical principles, and professional responsibilities for employees within an organization. They serve as a clear framework to guide decision-making, promote integrity, and ensure consistency in actions across the workforce. By setting clear expectations, codes of conduct help foster a culture of ethical conduct and accountability.
Question 94: A retail company's BCP includes a workaround for processing sales transactions manually when the POS system fails. This workaround is an example of:
- A compensating control for PCI-DSS compliance
- A risk acceptance strategy
- A manual fallback or degraded mode procedure (Correct answer)
- A cold site recovery option
Correct answer: A manual fallback or degraded mode procedure
Manual fallback procedures allow essential operations to continue in a degraded capacity when automated systems are unavailable.
Question 95: What is 'continuity of operations' (COOP) planning in the context of security operations?
- Pre-planning to maintain essential security functions during and after a disruptive event (Correct answer)
- Rotating security personnel to prevent complacency
- Ensuring security officers receive uninterrupted pay during incidents
- Maintaining a continuous video recording archive for evidentiary purposes
Correct answer: Pre-planning to maintain essential security functions during and after a disruptive event
COOP ensures that critical security functions continue without significant interruption even when normal operations are disrupted by emergencies.
Question 96: A security system sends an alarm signal even though no actual intrusion has occurred. This is called a:
- Nuisance alarm
- System fault
- False positive (Correct answer)
- Missed alarm
Correct answer: False positive
A false positive (false alarm) occurs when a security system triggers an alert without a real threat being present, often caused by environmental factors or equipment issues.
Question 97: What is the main goal of security operations?
- Increase profits
- Train employees only
- Protect people, property, information (Correct answer)
- Reduce paperwork
Correct answer: Protect people, property, information
The overarching goal of security operations is to safeguard an organization's most valuable assets: its people, physical property, and sensitive information. This comprehensive protection ensures business continuity, maintains a safe environment, and preserves the organization's integrity and reputation.
Question 98: Under NFPA 730 (Guide for Premises Security), what is the recommended minimum illumination level for parking facility security?
- 5 foot-candles
- 1 foot-candle (Correct answer)
- 0.5 foot-candles
- 10 foot-candles
Correct answer: 1 foot-candle
NFPA 730 recommends a minimum of 1 foot-candle of illumination in parking areas to support basic security and surveillance functions.
Question 99: A security professional overhears a conversation suggesting an imminent threat of workplace violence. Their primary obligation is to:
- Immediately report the threat to appropriate authorities (Correct answer)
- Keep it confidential as it was an overheard conversation
- Confront the individual directly to assess the threat personally
- Document the incident and review it at the next weekly meeting
Correct answer: Immediately report the threat to appropriate authorities
Imminent threats of violence must be immediately reported to appropriate authorities to fulfill the duty to warn and prevent harm.
Question 100: A security practitioner is developing a pandemic plan. Which continuity strategy is most critical to address in this scenario?
- Remote work capability and workforce redundancy (Correct answer)
- Supply chain diversification for hardware
- Alternate data center activation
- Physical security perimeter hardening
Correct answer: Remote work capability and workforce redundancy
Pandemics primarily affect personnel availability, making remote work capabilities and workforce redundancy the central continuity strategies.
Question 101: After restoring operations following a disaster, which activity formally closes out the incident response phase and transitions to normal operations?
- Reconstitution declaration (Correct answer)
- Business Impact Analysis update
- Risk register revision
- After-action review
Correct answer: Reconstitution declaration
A reconstitution declaration formally signals that primary systems are restored and the organization is transitioning back to normal operations.
Question 102: A safety practitioner is asked to prepare for a regulatory agency's programmed inspection. Which action best demonstrates proactive regulatory preparedness?
- Delaying the inspection by citing scheduling conflicts repeatedly
- Temporarily removing hazardous conditions only for the inspection period
- Conducting a pre-inspection internal audit against current regulatory standards (Correct answer)
- Coaching employees to decline interviews with inspectors
Correct answer: Conducting a pre-inspection internal audit against current regulatory standards
A pre-inspection internal audit identifies and corrects compliance gaps before the regulatory agency arrives, demonstrating genuine proactive compliance commitment.
Question 103: Under the Americans with Disabilities Act (ADA), an employer may discipline or terminate an employee who makes a credible threat of violence even if the behavior stems from a disability, because:
- The ADA does not cover employees with mental health conditions
- Federal law supersedes the ADA in all workplace violence cases
- Termination is automatically justified by any threatening statement
- Posing a direct threat to others is not a protected status under the ADA (Correct answer)
Correct answer: Posing a direct threat to others is not a protected status under the ADA
The ADA's 'direct threat' provision allows employers to take action when an individual poses a significant risk of harm that cannot be eliminated by reasonable accommodation.
Question 104: Under OSHA's Hazard Communication Standard (HazCom), Safety Data Sheets must include how many sections?
- 16 (Correct answer)
- 12
- 20
- 8
Correct answer: 16
OSHA's HazCom Standard (29 CFR 1910.1200) requires SDS documents to follow the GHS format with exactly 16 standardized sections.
Question 105: What is the function of security policies?
- Limit communication
- Create confusion
- Set rules and procedures (Correct answer)
- Ignore security risks
Correct answer: Set rules and procedures
Security policies serve as formal documents that establish clear rules, guidelines, and procedures for maintaining security within an organization. They define acceptable behavior, outline responsibilities, and provide a framework for consistent security practices, ensuring compliance and reducing vulnerabilities.
Question 106: Which document type formally authorizes continuity plan activation and identifies the conditions or thresholds that trigger plan execution?
- Risk Register
- After-Action Review report
- Plan Activation Criteria and Authority Matrix (Correct answer)
- Business Impact Analysis report
Correct answer: Plan Activation Criteria and Authority Matrix
The Plan Activation Criteria and Authority Matrix defines who has authority to activate the BCP and specifies the measurable thresholds that trigger activation.
Question 107: Under NFPA 101 Life Safety Code, what is the maximum travel distance to an exit in a business occupancy with sprinklers?
- 300 feet (Correct answer)
- 100 feet
- 400 feet
- 200 feet
Correct answer: 300 feet
NFPA 101 permits a 300-foot maximum travel distance to an exit in a sprinklered business occupancy, compared to 200 feet without sprinklers.
Question 108: Which international standard specifically provides guidance for Business Continuity Management Systems (BCMS)?
- ISO 22301 (Correct answer)
- ISO 31000
- ISO 27001
- NIST SP 800-53
Correct answer: ISO 22301
ISO 22301 is the international standard that specifies requirements for planning, implementing, maintaining, and improving a BCMS.
Question 109: Under OSHA's Hazard Communication Standard (HazCom), Safety Data Sheets must contain how many sections?
- 8
- 20
- 16 (Correct answer)
- 12
Correct answer: 16
OSHA's HazCom Standard (29 CFR 1910.1200) requires Safety Data Sheets to follow a standardized 16-section format aligned with the GHS.
Question 110: Which access control model grants permissions based on a user's role within an organization rather than individual identity?
- Attribute-Based Access Control (ABAC)
- Role-Based Access Control (RBAC) (Correct answer)
- Mandatory Access Control (MAC)
- Discretionary Access Control (DAC)
Correct answer: Role-Based Access Control (RBAC)
RBAC assigns permissions to roles (e.g., manager, guard, technician) and users inherit those permissions by being assigned to a role, simplifying large-scale permission management.
Question 111: When establishing a Joint Information Center (JIC) during a large-scale incident, the PRIMARY purpose is to:
- Provide medical triage services to injured responders
- Manage resource requests between field units and the EOC
- Coordinate and release consistent public information from all responding agencies (Correct answer)
- Serve as the operational base for hazmat response teams
Correct answer: Coordinate and release consistent public information from all responding agencies
A JIC consolidates public information functions across agencies to prevent conflicting messages and ensure coordinated communications to the public.
Question 112: What is the most effective way to measure success in workplace violence prevention within SSP professional practice?
- Compare only with industry averages without considering context
- Use a combination of quantitative metrics, qualitative assessments, and stakeholder feedback aligned with defined objectives (Correct answer)
- Rely solely on supervisor opinion
- Count only the number of activities completed
Correct answer: Use a combination of quantitative metrics, qualitative assessments, and stakeholder feedback aligned with defined objectives
Effective measurement combines multiple data sources — quantitative metrics, qualitative assessments, and stakeholder feedback — all aligned with clearly defined objectives for a comprehensive evaluation.
Question 113: Which investigative technique involves reviewing payroll, purchasing, and access records to establish a timeline of events?
- Witness credibility assessment
- Document trail reconstruction (Correct answer)
- Physical evidence mapping
- Behavioral analysis
Correct answer: Document trail reconstruction
Document trail reconstruction uses financial and administrative records to build a chronological sequence of events during an investigation.
Question 114: An organization is applying a Monte Carlo simulation to model financial losses from security incidents. What is the PRIMARY advantage of this technique over a single-point ALE estimate?
- It is the only method accepted by regulators for cybersecurity risk quantification
- It is faster and cheaper to execute than traditional annual loss expectancy calculations
- It produces a range of probable outcomes with associated probabilities, capturing uncertainty better than a single estimate (Correct answer)
- It eliminates the need for subject-matter expert input by relying entirely on statistical models
Correct answer: It produces a range of probable outcomes with associated probabilities, capturing uncertainty better than a single estimate
Monte Carlo simulation runs thousands of scenarios with variable inputs, producing a probability distribution of losses that reflects real-world uncertainty better than a deterministic ALE.
Question 115: A supply chain disruption prevents a manufacturer from obtaining critical components. Which BCP strategy specifically addresses this scenario?
- Pre-qualifying substitute suppliers and maintaining safety stock inventory (Correct answer)
- Activating the alternate data center
- Implementing a business interruption insurance claim
- Increasing cybersecurity controls on supplier portals
Correct answer: Pre-qualifying substitute suppliers and maintaining safety stock inventory
Pre-qualifying alternate suppliers and holding safety stock are supply chain resilience strategies that mitigate the impact of a single-source disruption.
Question 116: Which air pollutant is most commonly used as an indicator for overall air quality in the EPA's Air Quality Index (AQI)?
- Sulfur dioxide
- Hydrogen sulfide
- Ground-level ozone (Correct answer)
- Carbon monoxide
Correct answer: Ground-level ozone
Ground-level ozone is one of the six criteria pollutants tracked by the AQI and is among the most common indicators of poor urban air quality.
Question 117: What role does continuous improvement play in business continuity & resilience for SSP certified professionals?
- It focuses exclusively on cost reduction
- It drives ongoing enhancement of practices, processes, and outcomes through systematic evaluation (Correct answer)
- It is optional and only necessary during certification renewal
- It applies only to new professionals in their first year
Correct answer: It drives ongoing enhancement of practices, processes, and outcomes through systematic evaluation
Continuous improvement is fundamental to professional practice in business continuity & resilience, involving regular evaluation, feedback integration, and process enhancement to maintain high standards.
Question 118: An employer wishes to contest an OSHA citation. Within how many working days of receiving the citation must the employer file a Notice of Contest?
- 15 working days (Correct answer)
- 30 working days
- 5 working days
- 10 working days
Correct answer: 15 working days
Under the OSH Act, employers have 15 working days from receipt of a citation to file a Notice of Contest with the OSHA area director.
Question 119: In CCTV systems, what does 'resolution' expressed in TVL (TV lines) measure?
- The compression ratio of stored video footage
- The maximum distance at which a face can be identified
- The number of frames recorded per second
- The horizontal detail a camera can capture across the width of the image (Correct answer)
Correct answer: The horizontal detail a camera can capture across the width of the image
TVL measures horizontal resolution—the number of distinct vertical lines a camera can resolve across the full width of the image, indicating image detail quality.
Question 120: Which biometric technology measures the unique pattern of blood vessels in the human eye?
- Iris recognition
- Retinal scan (Correct answer)
- Facial recognition
- Vascular mapping
Correct answer: Retinal scan
Retinal scanning captures the unique pattern of blood vessels at the back of the eye, distinct from iris recognition which reads the colored ring around the pupil.
Safety and Security Practitioner (SSP) Certification
The SSP certification validates knowledge and skills in physical security, emergency planning, legal compliance, and security technology for safety and security practitioners in professional environments.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds