1.3 Experience-Based Testing, References & Study Approach
Key Takeaways
- PSP items are experience-based: you apply professional judgment to scenarios rather than reciting a book as if it were the live item bank.
- Map study time to the three published domains and 13 tasks, giving the 35% design-and-integration domain slightly more hours than implementation.
- Use Protection of Assets — Physical Security, Implementing Physical Protection Systems (3rd Edition), the Physical Asset Protection Standard, and the Business Continuity Management Guideline as context that supports keyed answers—not as a secret question file.
- Independent OpenExamPrep practice covers published domains and tasks; it is separate from any ASIS retired practice exam and is not an official ASIS product.
- Common traps include treating 700 as the passing score, assuming Pearson VUE delivery, inventing a pass rate, and using outdated eligibility-year rules.
Experience-based testing is not a synonym for “skip the books”
Quick Answer: PSP is an experience-based exam. ASIS lists four official references that item writers use to key correct answers, but the form is not a recitation test of those books. Study the three published domains and 13 tasks, use the references as context, and practice applying judgment to workplace scenarios. This OpenExamPrep material is independent coverage of those domains and tasks—not an ASIS-approved course and not a substitute for any ASIS retired practice exam.
A pure recall test rewards the candidate who memorized a table: illuminance, cable types, lock functions, or a clause number. PSP can still require that you know what a technology does, but live items are written so two practitioners might argue in a project meeting—and only one option reflects defensible practice.
That is why ASIS tells candidates not to memorize the reference set as if it were the item bank. Item writers and reviewers use the references to determine the keyed answer. You still have to apply your own experience to the scenario. A hospital loading dock is not a data-center mantrap. A school visitor policy is not a refinery vehicle-access scheme. The right camera specification for detection is not automatically the right specification for identification after an assault.
What “experience-based” does not mean:
- You can skip studying because you have “been in security for years.”
- Vendor muscle memory always matches the keyed answer.
- Every site's compromise (“we never do acceptance testing”) is acceptable.
- The four references are optional decoration you can ignore.
It means you should study tasks, then ask “what would I do on a well-run project?” rather than “what sentence did I highlight on page 214?” Independent practice on OpenExamPrep is built for that rehearsal: scenario judgment across the published domains, not a claim that you have seen ASIS's live items.
Map a study plan to three domains and 13 tasks
ASIS publishes three domains. Inside them are 13 tasks—five in assessment, three in design/integration, five in implementation. Use the tasks as your outline. This independent guide covers those published domains and tasks; it does not invent a parallel syllabus.
Domain 1 — Physical Security Assessment (34%)
- Develop a physical security assessment plan. Scope, methods (qualitative versus quantitative), resources, and which parts of the site are in play.
- Identify assets and determine value, criticality, and loss impact. Not every asset is equally worth a six-figure delay system.
- Assess threats and hazards so the problem is sized correctly—crime, insider activity, natural hazards, neighboring occupancies.
- Conduct the assessment to identify and quantify vulnerabilities. Surveys, interviews, lighting and line-of-sight, procedures that exist only on paper.
- Perform a risk analysis so countermeasures are chosen against risk, not against a salesperson's catalog.
Domain 2 — Application, Design, and Integration of Physical Security Systems (35%)
- Establish performance requirements. Detection, delay, response, and operational constraints (life safety, aesthetics, budget, network).
- Apply physical security measures. CPTED, structural measures, electronic systems, supporting power and transmission, personnel measures—as an integrated set, not a pile of devices.
- Design systems and project documentation. Design phases, drawings, specifications, integration, and enough documentation that procurement is not a guessing game.
Domain 3 — Implementation of Physical Security Measures (31%)
- Outline criteria for the pre-bid meeting so bidders see the same scope, ethics, and technical compliance rules.
- Develop a procurement plan for goods and services—what will be bought, how vendors will be evaluated, and how the buy will be controlled before anyone mobilizes on site.
- Manage implementation of goods and services—installation, coordination, and making the purchased solution real. Do not collapse this task into procurement, and do not treat factory/site acceptance testing as a separate official task number.
- Develop requirements for personnel involved in support of the security program. Posts, training, and the human layer electronics cannot replace.
- Monitor and evaluate the program throughout the system life cycle. Maintenance, metrics, and whether residual risk stays acceptable after turnover.
A practical split for a 100–160 hour plan (about 8–14 weeks for many candidates) overweights the 35% domain without starving the others:
| Block | Domain / purpose | Suggested hours | Why |
|---|---|---|---|
| 1 | Assessment (34%) | about 35 | Build the survey-to-risk chain before you specify hardware |
| 2 | Design and integration (35%) | about 45 | Largest weight; densest technology and documentation |
| 3 | Implementation (31%) | about 35 | Procurement, testing, personnel, lifecycle |
| 4 | Mixed timed practice | about 25 | 2.5-hour stamina and weak-task repair |
Adjust if your job is lopsided. A designer who has never walked a bid meeting should overweight Domain 3. A retired officer who never produced drawings should overweight Domain 2. Weekly rhythm that works: one task cluster deep (readings plus notes from real projects), then a short mixed quiz. End each week with a 20–40 item drill under time pressure. In the final two weeks, sit at least one full 140-item / 2.5-hour simulation and review every miss by task, not by a vague “I am bad at cameras.”
The bar chart below is a planning aid for independent study—not an ASIS-required hour quota.
How to use the official references without treating them as the exam
ASIS lists four references for PSP. Use them by role; do not try to reproduce their text:
- Protection of Assets — Physical Security (POA). The broad physical-security sourcebook: concepts you will meet across assessment and measures.
- Implementing Physical Protection Systems — A Practical Guide, 3rd Edition (IPPS). Field-oriented guidance on making protection systems real—requirements through implementation.
- Physical Asset Protection Standard. The ASIS standard that frames a protection program as a managed system, not a shopping list of devices.
- Business Continuity Management Guideline. Continuity context so physical measures still make sense when operations are disrupted.
A method that respects experience-based testing:
- Read for definitions and decision logic (what a survey includes, what a drawing set must communicate, what acceptance testing is for).
- After each chapter, write a workplace example from a site you know. If you cannot, the reading has not become experience yet.
- When a practice item disagrees with “how we do it here,” check whether your site is the outlier. The keyed answer will follow defensible practice as supported by the references, not a local shortcut.
- Do not build flashcards of random page numbers. Do not assume a quiz at the back of a book is a live PSP item.
Independent OpenExamPrep practice versus an ASIS retired practice exam
ASIS has offered a retired practice exam as an official familiarization product. That product is ASIS's. It can help you see item style. It is still not the live bank, and a high score on a retired form is not a scaled 650.
Use both kinds of practice if you have them. Never launder either one into “I have seen the real questions.” Sharing live exam content would violate the ASIS Certification Code of Professional Responsibility you already agreed to.
Common traps: folklore that fails expensive seats
| Trap | Current fact |
|---|---|
| “Passing is 700” or “70%” | Passing is a scaled score of at least 650, not a raw percentage. |
| “The ASIS pass rate is X%” | ASIS does not publish a PSP pass rate. Ignore invented percentages. |
| “I schedule at Pearson VUE” or “I can just pick ProProctor from home” | Default delivery is a Prometric test center. Pearson VUE is the wrong vendor. Remote ProProctor is accommodation-only (PCB Certificant Relations Committee); distance or geography is not enough. Some handbook pages still describe an older center-or-ProProctor choice—use the live Prepare for Test Day rule. |
| “Everyone needs seven years” or “APP always knocks off two years” | Years are 5 / 4 / 3 by education; APP reduces the first two paths by one year; master's stays 3. |
| “Unanswered questions are skipped” | Unanswered = incorrect. |
| “I can use my work laptop at home because I live far from a center” | Distance is not enough for remote testing. If the Committee does approve ProProctor, do not use a company computer; failed hardware or room can forfeit the fee. |
| “Grace period lets me finish CPEs” | You have 3 months to apply; CPE credits cannot be earned in grace. |
| “Memorize the four books and you are done” | Experience-based items require application; references support keys, they are not the form. |
| “Pretest items are marked” | They are not identified. Treat all 140 as live. |
A study approach you can start this week
- Print the domain/task list above and rate yourself 1–5 on each task from real work, not from confidence.
- Start the application/ATT chores in parallel so eligibility is not the long pole.
- Study Domain 2 with extra hours, but do not skip assessment fundamentals—design without risk analysis is catalog shopping.
- Pair every technology topic (video, intrusion, access control, barriers, power, transmission) with an implementation question: how would you bid, install, test, and maintain it?
- Drill mixed questions under time. Then read explanations that cite the principle, not an option letter.
- In the last 10 days, stop harvesting new topics. Rehearse the 2.5-hour clock, ID and logistics, and your flag-and-return method.
PSP rewards the practitioner who can walk from a threat statement to a tested system. Study that walk, using the published tasks as waypoints and the references as context. The remaining chapters of this independent OpenExamPrep guide go domain by domain through that same path.
What does it mean that PSP is an experience-based exam?
Which statement about PSP scoring, delivery, and published statistics is accurate?
How should a candidate use the ASIS-listed PSP references during independent prep?