Free ASIS CPP Exam Flashcards

Memorize 50 essential terms and definitions for the ASIS Certified Protection Professional (CPP). See the term, recall the definition, then flip to check yourself.

50 Flashcards
7 Topics
100% Free
TermClick to flip

What is the core management idea behind enterprise security risk management (ESRM)?

Tap to reveal definition
Card 1 of 50Security Principles and Practices

Filter by Topic

Jump to Card

About These ASIS CPP Flashcards

These 50 flashcards are designed to help you memorize key terms and definitions for the ASIS Certified Protection Professional (CPP). Each card shows a term on the front and its definition on the back—the classic flashcard format for vocabulary memorization. Use these alongside our practice questions to build both recall and comprehension.

Topics Covered

Security Principles and Practices11 cards
Business Principles and Practices8 cards
Investigations5 cards
Personnel Security5 cards
Physical Security8 cards
Information Security7 cards
Crisis Management6 cards

Complete Flashcard Reference

Review every term in this set. Open any term to reveal its definition.

What is the core management idea behind enterprise security risk management (ESRM)?

Security decisions should protect assets that enable the organization's mission. Asset owners own the risks, while security professionals facilitate risk decisions and align safeguards with business priorities.

Why should a security program define governance before choosing controls?

Governance assigns decision rights, accountability, escalation paths, and oversight. Without it, controls may exist but no one clearly owns risk acceptance, resources, or corrective action.

What should be evaluated before adopting an AI- or IoT-enabled security control?

Evaluate the business need, accuracy, bias or privacy exposure, cybersecurity, interoperability, failure modes, human oversight, and full lifecycle cost. New capability must not create unmanaged risk.

When is a qualitative risk assessment preferable to a quantitative one?

Use qualitative ratings when reliable loss data are limited or rapid prioritization is needed. Quantitative analysis is stronger when credible frequencies and financial impacts support numerical comparison.

How do threat, vulnerability, and consequence work together in risk analysis?

Threat describes a potential harmful actor or event, vulnerability is a weakness it could exploit, and consequence is the resulting impact. A defensible assessment considers all three rather than treating any one as risk by itself.

What is a consequential threat?

It is a secondary hazard created by an initial event, such as civil disorder after a prolonged outage. Planning should examine cascading effects, not only the initiating incident.

How do risk avoidance, acceptance, transfer, and mitigation differ?

Avoidance stops the risky activity; acceptance knowingly retains the risk; transfer shifts defined financial or operational consequences; mitigation reduces likelihood or impact. The residual risk still needs an owner.

What makes a security-program audit useful for continuous improvement?

It compares documented requirements with actual performance, records evidence and gaps, assigns corrective owners and dates, and verifies closure. A finding alone does not improve the program.

What distinguishes an outcome metric from an activity metric in security?

An activity metric counts work performed, such as training sessions. An outcome metric shows the effect, such as fewer reporting errors or faster response, and is more useful for judging program value.

What is the security manager's purpose in maintaining external liaison relationships?

Liaisons create trusted channels before an incident for information sharing, coordinated planning, resource access, and jurisdictional clarity. Contact lists alone are not working relationships.

How should a security-awareness program be evaluated?

Set observable objectives, measure knowledge and behavior, analyze incident or reporting trends, and adjust content for different roles. Attendance proves delivery, not effectiveness.

What does fiduciary responsibility require from a security manager who controls a budget?

Use funds for authorized purposes, maintain accurate records and approvals, protect assets, disclose conflicts, and support auditability. Good intentions do not replace financial controls.

How should budget variance be used during the security budget lifecycle?

Compare actual results with the approved plan, explain material differences, forecast their effect, and take or propose corrective action. Variance analysis is a management tool, not merely a year-end report.

What is the practical difference between a security policy and a procedure?

A policy states management intent, requirements, and accountability; a procedure gives the ordered steps for carrying it out. Procedures should trace to policy and remain workable at the operating level.

What makes a productivity KPI suitable for a security process?

It is tied to a defined objective, uses reliable data, has an owner and target, and encourages the intended behavior. A convenient count can be misleading if it rewards speed at the expense of quality or risk.

Why perform a job analysis before recruiting for a security position?

Job analysis identifies essential duties, competencies, authority, and working conditions. It supports defensible selection criteria, relevant screening, training plans, and performance measures.

How does succession planning reduce security-program risk?

It identifies critical roles, potential successors, competency gaps, and development actions before a vacancy. The goal is continuity of capability, not simply naming a backup.

What is management's role in creating an ethical security climate?

Leaders set clear conduct expectations, model them, protect confidential information, provide safe reporting channels, investigate consistently, and apply consequences without favoritism.

What should a security service-level agreement make measurable?

Define the service, performance standard, measurement method, reporting interval, escalation process, remedies, and responsibilities. Monitoring those terms turns a vendor promise into manageable performance.

What should an investigation plan establish before fact-finding begins?

Define the allegation, objectives, scope, authority, legal or policy constraints, resources, evidence sources, roles, milestones, and reporting path. The plan should also protect independence and confidentiality.

What information makes a chain-of-custody record defensible?

Identify the item, collector, date, time, location, condition, packaging, every transfer, purpose, and final disposition. Each handoff should show who controlled the evidence and when.

What must be resolved before using surveillance technology in an investigation?

Confirm lawful authority, necessity, proportionality, scope, privacy limits, data handling, operator competence, and approval. Capabilities such as drones or robotics do not remove legal and ethical constraints.

How should a manager choose resources for a specialized investigation?

Match the allegation and evidence to needed expertise, independence, legal authority, tools, and preservation methods. Cyber, financial, intellectual-property, and violent-crime matters may require different specialists.

What makes an investigative interview more reliable and defensible?

Use a planned, lawful, noncoercive approach; account for language and culture; ask open questions before specifics; document accurately; and preserve required rights. Seek counsel when legal exposure exceeds the investigator's authority.

How should preemployment screening be scoped?

Tie each check to job-related risk, obtain required consent, use reliable sources, protect the data, and apply criteria consistently. More intrusive screening is not automatically more defensible.

Why may personnel screening continue after hiring?

Promotion, retention, or assignment to a sensitive role can change the risk and required trust level. Any rescreening must follow law and policy, be job related, give notice where required, and protect confidentiality.

Why should workplace threat assessment focus on behavior rather than a profile?

No reliable demographic profile predicts violence. A multidisciplinary team should evaluate concerning behavior, context, capability, stressors, protective factors, and changes over time, then select proportionate interventions.

What should a travel-security plan provide beyond a destination risk rating?

Provide traveler briefing, tracking and contact methods, medical and evacuation options, escalation triggers, local support, and a response protocol. Risk intelligence is useful only when it drives decisions and assistance.

What should drive the design of an executive-protection program?

A current threat and vulnerability assessment should drive protective intelligence, advance work, transportation, staffing, communications, medical support, and liaison. The proprietary-versus-contract choice follows requirements and risk.

What evidence should a physical security survey gather?

Combine document review, site observation, interviews, system records, tests, and asset or threat data. A checklist organizes the work, but evidence and analysis support the findings.

Why compare facility drawings with actual site conditions during a survey?

Renovations, undocumented pathways, changed uses, and disabled devices can make drawings inaccurate. Field validation reveals dependencies and gaps that a desk review can miss.

What does a physical security gap analysis compare?

It compares current safeguards and performance with risk-based requirements or an approved target state. The resulting gaps should be prioritized by risk, feasibility, and dependency.

How should detection, delay, and response be related in a protection design?

Detection must provide enough reliable warning, and barriers must delay the adversary long enough for an effective response to arrive and intervene. A strong barrier alone may only postpone an unopposed loss.

How should physical countermeasures be selected from a risk assessment?

Choose a layered mix that addresses identified threats and vulnerabilities, meets legal and operational needs, integrates with existing systems, and produces acceptable residual risk at sustainable lifecycle cost.

How should a manager balance security personnel and technology?

Assign automation to consistent sensing, logging, and control while preserving trained people for judgment, communication, exception handling, and response. Staffing and technology must be designed as one operating system.

What should be defined before accepting a new physical security system from a vendor?

Define measurable requirements, interfaces, test cases, documentation, training, defect resolution, and acceptance authority in the procurement package. Factory, site, and commissioning tests should trace to those criteria.

How do predictive, preventive, and corrective maintenance differ?

Predictive maintenance uses condition data to anticipate failure; preventive maintenance follows planned intervals; corrective maintenance restores a failed or deficient asset. A resilient program deliberately combines them.

What makes an information security survey integrated rather than purely technical?

It examines physical, procedural, personnel, system, awareness, destruction, and recovery controls together, then traces data flows and dependencies across facility and network boundaries.

What do confidentiality, integrity, and availability each protect?

Confidentiality prevents unauthorized disclosure, integrity prevents unauthorized or undetected alteration, and availability keeps information and services accessible when needed. Controls may support more than one objective.

What effect should a legal hold have on normal records disposition?

It suspends routine destruction for information potentially relevant to a legal or regulatory matter. The organization should identify custodians and systems, preserve content and metadata, document actions, and release the hold only with authority.

Why does information classification come before choosing many safeguards?

Classification ties sensitivity, value, legal duties, and business impact to handling rules. It lets the organization apply proportionate access, storage, transmission, retention, and destruction controls.

What makes authentication truly multifactor?

It uses independent factor categories, such as something known, possessed, or inherent. Two passwords are two credentials of one factor type, so they do not provide true multifactor authentication.

How does data masking differ from encryption?

Encryption transforms data with a cryptographic key and can be reversed by an authorized holder. Masking obscures selected values for display or use; depending on the method, it may be irreversible.

What governance is needed before a penetration test?

Obtain written authorization and define scope, timing, methods, excluded assets, data handling, stop conditions, contacts, reporting, and remediation ownership. Testing without these rules can itself create an incident.

How should crisis threats be prioritized for planning?

Compare credible likelihood, consequences, vulnerabilities, dependencies, and existing capability, then consider the cost and effect of mitigation. Rare but catastrophic events may still demand preparation.

What decision does a business impact analysis support?

It identifies critical activities, dependencies, impacts over time, and acceptable disruption, helping leaders set recovery priorities and resource needs. It does not estimate how likely each threat is.

What is the value of an all-hazards crisis plan?

It builds common capabilities—command, communications, accountability, resource management, and recovery—that work across many events, while hazard-specific annexes address unique actions such as CBRNE controls.

What should a mutual-aid agreement establish before a crisis?

Define activation authority, resources, command relationships, communications, qualifications, cost and liability terms, logistics, and demobilization. A verbal expectation may fail when every party is under pressure.

How do an emergency operations center and incident command relate?

Incident command directs tactical operations at or near the incident. The EOC supports coordination, policy, information, and resource allocation across the organization; it should not create competing tactical command.

How should recovery reduce risk from the next crisis?

Restore priority operations, support affected people, document decisions, and use damage assessment and after-action findings to correct root causes. Rebuilding the same vulnerability only restores the prior risk.

Frequently Asked Questions

What is the current ASIS CPP exam format?

The CPP exam contains 200 scored multiple-choice questions and 25 unscored pretest questions. Candidates have four hours. Pretest questions are mixed into the exam and are not identified to candidates.

What score is required to pass the ASIS CPP exam?

ASIS requires a scaled score of at least 650. A scaled score is a standardized transformation of the raw number correct, not the number of correct answers and not a percentage.

What experience is required for CPP eligibility?

The handbook requires seven years of security experience with no higher-education degree, six with a bachelor's degree, or five with a master's degree. Each route includes at least three years in responsible charge. Holding the APP reduces the total experience requirement by one year. Experience must be full time or a primary duty, but current employment is not required.

What does responsible charge mean for CPP eligibility?

Responsible charge means authority to make independent decisions and take independent actions about operational methodology and execution of a security-related project or process. It does not require supervising employees.

What is the CPP retake policy after a failed attempt?

There must be at least 60 days between every exam date. A candidate may test no more than three times during the one-year eligibility period. After three failures, or when that eligibility period expires, the candidate must submit a new certification application before testing again.

How long does the CPP certification remain valid?

CPP certification operates on a three-year recertification cycle. A certificant must earn and report 60 qualifying Continuing Professional Education credits during the cycle under the current ASIS recertification rules.

Does ASIS publish the CPP exam pass rate?

No. ASIS does not publish a current official CPP pass rate. Percentages reported by training providers or other third parties should not be presented as an ASIS statistic.

Same family resources

Explore More ASIS International Certifications

Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.