Questions with Correct Answers 2025-
2026.
What is physical security? - Answer Combination of people, processes, procedures and
equipment to protect resources
Has different set of vulnerabilities
Requiring practicing due diligence and due care
Protecting life is the first priority
Vulnerability - Answer Procedural weakness
Threat - Answer Potential danger to info, systems, personnel
Attack - Answer Attempted or successful exploitation of a vulnerability
Agent - Answer Entity capable of attacking a vulnerability
Physical Security program should address what goals? - Answer - Crime and disruptions
prevention through deterrence
ex. fences, security guards, warning signs, and so fourth
Reduction of damage through the use of delaying mechanisims
ex. locks, security personnel
Crime or disruption detection
ex. smoke/motion detectors, CCTV
Incident assesment
ex. response of security gurads to detected incidents and determination of damage
Response procedures
, ex. fire suppression mechanisms, emergency response processes, law enforcement
Requirements of physical securtiy program - Answer Joint participation of both the IT &
Management to define objectives, design program, develop metrics and evals to meet the
pretermined level of protection required for all assets.
Weighs the objectives of the program to available resources
Protection level determined by estimating organization risk posture, required laws and
regulations with which compnay must compy and predetermined threat profile
Threat profile determined by identifying who and what could damage business assets,
anticipating the attacks and crimes that could take place and understanding the business impact
of those threats.
Physical Security Program Performance Metrics - Answer Potential measures to estimate
effectiveness of program approach:
1. # of successful crimes
2. # of successful disruptions
3. # of unsuccessful crimes or disruptions
4. Time between detection, assessment, and recovery steps
5. Business impact of disruptions
6. Number of false-positive detection alerts
7. Time it took for a criminal to defeat a control
8. Time it took restore the operational environment
Steps to a Effective Physical Security Program - Answer 1. Identify a team
2. Conduct risk analysis
3. Define acceptable risk level
4. Performance baselines
5. Performance metrics
6. outlining the level of protection
7. Implement countermeasures
8. Continuously evaluate
CPTED - Answer Crime prevention through Environmental Design: