ASIS International • CPP • Security Management C E R T I F I C A T I O N G U I D E CPP Certification Guide: ASIS Certified Protection Professional Syllabus, sample questions and a study plan for the ASIS CPP security management exam All seven domains with ASIS’s own percentages and every one of the thirty published task statements, the scaled-score rule that replaces the 80% figure still in circulation, what the 1 September 2026 testing changes mean for remote proctoring and extra time, the eligibility maths, a five-step route to exam day, and ten sample questions with a key. 225 QUESTIONS 4 HOURS TIME LIMIT 650 SCALED PASS $580 MEMBER FEE 7 DOMAINS Prepared by CertFun • www.certfun.com www.certfun.com ASIS International CPP ASIS Certified Protection Professional (CPP) 1 SECTION 01 Exam Overview The CPP is the senior credential in the ASIS International family, and ASIS itself calls it the “gold standard” for security management professionals. It is not an entry exam and it is not a technology exam: it certifies that someone who has already been running a security function can do it to a defined professional standard, across everything from budgets and vendor contracts to evidence handling and crisis response. Two hundred and twenty-five questions in four hours, at a Prometric test centre. The facts below come from CertFun’s CPP exam syllabus, the official ASIS CPP page and the ASIS International Board Certification Handbook. Certification ASIS Certified Protection Professional (CPP) Exam code CPP Awarding body ASIS International, through the ASIS Professional Certification Board Level Senior - the board certification in security management, ASIS’s top credential Number of questions 225 - 200 scored plus up to 25 unscored pretest items Time limit Four hours Question format Multiple choice, four options, one correct answer Scoring Scaled score; 650 or higher passes. It is not a percentage Languages English and Spanish; Spanish candidates also receive an English translation Exam fee ASIS members $580, nonmembers $910. Emerging Market bands: $480 / $460 for members, $720 / $680 for nonmembers. All include a nonrefundable $160 Retest fee $480 for members and nonmembers alike; $360 / $330 in the Emerging Market bands Eligibility Seven years of security experience, or six with a bachelor’s degree, or five with a master’s - and three of those years in responsible charge Delivery Prometric test centres worldwide; remote proctoring is accommodation-only from 1 September 2026 Domains Seven, weighted 22 / 16 / 15 / 14 / 13 / 11 / 9 Eligibility period One year, with up to three attempts and 60 days between them Validity Three years, recertified with Continuing Professional Education credits www.certfun.com ASIS International CPP ASIS Certified Protection Professional (CPP) 2 One line in that table is worth pausing on, because it is the single most commonly misreported fact about this exam. The pass mark is not 80%. ASIS scores every one of its exams on a scaled system, and the handbook is unambiguous: “A scaled score of at least 650 is required to pass ASIS examinations. A scaled score is neither the number of questions you answered correctly nor the percentage of questions you answered correctly.” Individual questions carry different weight according to how difficult they proved when they were pretested, and the scale exists so that a slightly harder form of the exam is not a harder exam to pass. The passing point itself was set by a standard-setting panel of ASIS-certified professionals working with Prometric’s exam development experts, and the handbook notes separately that it cannot be appealed. Plenty of study sites - CertFun’s own syllabus page among them - still print 80%. Treat 650 as the number that counts, and treat any percentage as a rough working target rather than a threshold. Two other details are worth knowing before you budget. The fee is not a single number : ASIS members pay $580 and nonmembers $910, but the ASIS Global Board has approved reduced fees for candidates living in countries the World Bank identifies as Emerging Markets, down to $460 for members and $680 for nonmembers. Because the member rate saves more than most memberships cost, the handbook is blunt about the sequence: join before you submit the application, because the discount is not applied retrospectively. And of every fee, $160 is nonrefundable - if your application is cancelled or denied, that is what you lose, and after 90 days from approval no refund is issued at all. SECTION 02 What Changed on 1 September 2026 If you are working from a study plan written before this summer, two testing policies have changed under you. Both were published in the handbook update of 4 August 2026 and took effect on 1 September 2026 , and both affect how and where you sit the exam rather than what is on it. The first is the bigger one. Remote proctoring is no longer broadly available. Until now, any candidate could choose to sit a CPP at home through Prometric’s ProProctor platform. From 1 September 2026, remote proctoring is available only through an approved accommodation from the Professional Certification Board’s Certificant Relations Committee, granted through ASIS’s established accommodation request process with supporting documentation. The handbook closes the obvious loophole in one sentence: “distance or geography are not sufficient justification for access to remote proctoring.” If you live a long way from a Prometric centre, plan the journey rather than the appeal. The second change goes the other way and is easy to miss. Candidates whose primary language is not English may now request 25% additional testing time - on a four-hour exam that is a full extra hour. You request it by emailing the certification team with your name as it appears in your ASIS record, your ASIS ID, your email address, the certification concerned and an attestation that English is not your primary language. The timing matters: the request has to be submitted and approved before you schedule the exam appointment, not after. One restriction - you may take the additional time or the Spanish-language form, but not both for the same appointment. www.certfun.com ASIS International CPP ASIS Certified Protection Professional (CPP) 3 What this means in practice Budget travel to a Prometric centre; home testing is now accommodation-only. Non-native English speaker? Ask for the extra hour before you book, not after. Extra time and the Spanish paper are mutually exclusive for one appointment. Download the handbook fresh - the version you saved in the spring is out of date. What has not changed is the exam content. The CPP Body of Knowledge still describes the same seven domains with the same percentages, and the domain list on the official page matches it. If your study materials cover those seven domains, they are current. SECTION 03 The Seven Domains by Weight ASIS publishes real percentages for the CPP, so the chart below is the exam’s own weighting rather than a proxy for it. Against 200 scored questions the arithmetic is easy to do in your head: 1% is two questions . Security Principles and Practices is worth about 44 questions, Physical Security about 32, Investigations about 18. The three biggest domains - Security Principles, Physical Security and Business Principles - are 53% of the exam between them. Security Principles and Practices 22% Physical Security 16% Business Principles and Practices 15% Information Security 14% Crisis Management 13% Personnel Security 11% Investigations 9% Official percentages from the ASIS CPP Body of Knowledge, cross-checked against the domain list on the official ASIS CPP page and against CertFun’s syllabus page, which reproduces the same seven domains with the same weights. The shape of that distribution is the first thing to understand about the CPP, because it is not the shape most candidates expect. People arrive from a specialism - physical security, or investigations, or corporate security management - and assume their own field will dominate. It does not. Investigations is the smallest domain at 9% , roughly eighteen questions, despite having six task statements to Physical Security’s three. Business Principles and Practices is 15% , and it is where experienced security managers most often lose marks: budgets, ROI, contract law, service level agreements, succession planning and ethical governance are management content, not security content, and they are examined as such. If you have never built a security budget or evaluated a bid package, that domain is where your study time should go, whatever your job title says. www.certfun.com ASIS International CPP ASIS Certified Protection Professional (CPP) 4 Domain One: Security Principles and Practices — 22% • Plan, develop, implement, and manage the organization’s security program to protect the organization’s assets. • Develop, manage, or conduct the security risk assessment process. • Evaluate methods to improve the security program on a continuous basis through the use of auditing, review, and assessment. • Develop and manage professional relationships with external organizations to achieve security objectives. • Develop, implement, and manage workforce security awareness programs to achieve organizational goals and objectives. Domain Two: Business Principles and Practices — 15% • Develop and manage budgets and financial controls to achieve fiscal responsibility. • Develop, implement, and manage policies, procedures, plans, and directives to achieve organizational objectives. • Develop procedures/techniques to measure and improve organizational productivity. • Develop, implement, and manage security staffing processes and personnel development programs in order to achieve organizational objectives. • Monitor and ensure an acceptable ethical climate in accordance with regulatory requirements and organizational culture. • Develop performance requirements and contractual terms for security vendors/suppliers. Domain Three: Investigations — 9% • Identify, develop, implement, and manage investigative operations. • Manage or conduct the collection, preservation, and disposition of evidence to support investigative actions. • Manage or conduct surveillance processes. • Manage and conduct investigations requiring specialized tools, techniques, and resources. • Manage or conduct investigative interviews. • Provide support to legal counsel in actual or potential criminal or civil proceedings. Domain Four: Personnel Security — 11% • Develop, implement, and manage background investigation processes for hiring, promotion, and retention of individuals. • Develop, implement, manage, and evaluate policies and procedures to protect individuals in the workplace against human threats (e.g., harassment, violence, active assailant). • Develop, implement, and manage executive protection programs. www.certfun.com ASIS International CPP ASIS Certified Protection Professional (CPP) 5 Domain Five: Physical Security — 16% • Conduct facility surveys to determine the current status of physical security. • Select, implement, and manage physical security strategies to mitigate security risks. • Assess the effectiveness of physical security measures by testing and monitoring. Domain Six: Information Security — 14% • Conduct surveys to evaluate current status of information security programs. • Develop policies and procedures to ensure information is evaluated and protected against vulnerabilities and threats. • Implement and manage an integrated information security program Domain Seven: Crisis Management — 13% • Assess and prioritize threats to mitigate potential consequences of incidents. • Prepare and plan how the organization respond to incidents. • Respond to and manage an incident. • Manage incident recovery and resumption of operations. All thirty task statements above are ASIS’s own wording from the CPP Body of Knowledge, cross-checked against the CertFun CPP syllabus page, which sets out the same tasks with the knowledge statements that sit beneath each one. Read the verbs. Nearly every task begins with develop , implement , manage , evaluate or conduct - and almost none begins with describe or list . That is deliberate. ASIS states plainly that its exams are experience-based and that you will need to apply your own experience to answer the questions correctly; it even asks candidates not to try to memorise the reference set. The questions put you in a situation and ask what a competent security manager would do about it. The reference set behind those questions is public, and it is worth knowing what it is: Protection of Assets (POA), plus seven ASIS standards and guidelines - the CSO, ORM.1, SRA-2024 and WVPI.1 standards, and the PAP, IAP and PBS guidelines. ASIS says its item writers and reviewers use these to determine the correct answers. SECTION 04 What the Credential Is Worth The CPP is unusual among the certifications CertFun covers in that it is not tied to a product, a vendor stack or a technology cycle. It is a professional board certification, closer in character to a chartered qualification than to a platform badge, and it has been the recognised mark of a senior security manager for more than forty years. That is what gives it staying power: the exam has no version number to go stale, and the domains have absorbed new content - artificial intelligence and IoT under security theory, unmanned aircraft under surveillance and facility survey, GDPR and biometric information under records management - without the credential itself being reissued. www.certfun.com ASIS International CPP ASIS Certified Protection Professional (CPP) 6 On pay, be careful which numbers you trust. ASIS’s own claim, on its Why Get Certified? page, is that “ASIS certificants earn an average of 20% higher salaries than those without an ASIS certification” - but the citation attached to it is the ASIS Certification Survey of April 2019 , so treat it as a claim of long-standing rather than a current measurement. Payscale, which tracks the CPP credential itself, reports an average base salary of $109,000 in the United States, updated 27 April 2026, from 151 individuals reporting. Job-board aggregates for CPP-requiring security roles run considerably higher, into six figures well above that average, which is what you would expect when the eligibility rules alone guarantee that every holder has at least five to seven years behind them. Take the range, not any single number, and read the eligibility bar as part of the salary story. Why this exam, specifically Vendor-neutral and versionless - no product cycle to make it obsolete. Recognised internationally as the senior security management credential. Covers the management content, not just the security content, of the job. The eligibility bar is itself a signal: nobody holds a CPP without the years. Be honest about the boundary too. The CPP is a management certification: it will not stand in for a technical credential in cyber security, and Information Security is only 14% of it, examined at the level of programme governance rather than implementation. Nor is it an entry point - if you are earlier in your career, ASIS’s own ladder starts with the APP at one year of experience, and the PSP and PCI sit alongside the CPP as specialist credentials in physical security and investigations respectively. The CertFun ASIS vendor page lists all four in one place, and the ASIS certification portal shows which is which if you are still choosing. SECTION 05 Getting Certified, Step by Step 1 Check the experience maths before anything else Seven years, or six with a bachelor’s, or five with a master’s. 2 Join ASIS, then apply - in that order The member rate saves $330; it is not applied after the fact. 3 Take the Self-Assessment and read the Body of Knowledge Score yourself domain by domain, and be honest about Business Principles. 4 Work the reference set and the practice exam Protection of Assets, seven standards and guidelines, retired real items. 5 Schedule with Prometric and sit the exam 225 questions, four hours, 650 scaled to pass; then start logging CPEs. Step one is not a formality. The CPP has the strictest eligibility rules of the four ASIS certifications, and applications are reviewed before you are authorised to test. Without a higher education degree you need seven years of security experience - six if you already hold the APP. A bachelor’s degree or www.certfun.com ASIS International CPP ASIS Certified Protection Professional (CPP) 7 international equivalent brings that down to six years, five with the APP; a master’s brings it to five, four with the APP. In every case, at least three of those years must be in responsible charge of a security function, and ASIS defines that term narrowly: authority to make independent decisions and take independent actions determining operational methodology and managing execution of a security-related project or process. It does not require you to supervise anyone, and it generally excludes patrol officer roles or their equivalent. Once your application is approved you receive an authorisation to test email, and only then can you schedule at Prometric through the ASIS application process. Exams run year-round. You then have a one-year eligibility period , within which you may sit the exam up to three times with at least 60 days between attempts; retests cost $480 and are nonrefundable. Fail three times or let the year lapse, and you start again with a new application. ASIS does not grant extensions for job demands, company budgets, employment status or personal finances - only for severe hardship such as a major medical emergency. On the day, bring a valid government-issued photo ID carrying your signature, with the identifying information printed in English. And afterwards, the clock starts again: every ASIS certification must be recertified every three years by earning Continuing Professional Education credits. Start logging them from the month you pass rather than discovering the requirement in year three. When you want timed practice under exam conditions before any of that, CertFun’s CPP practice exam rehearses the format so the four-hour clock stops being a surprise. SECTION 06 CPP Exam Sample Questions These ten come from CertFun’s CPP sample questions page, shown here in shuffled order. All ten are single-answer, matching the real format of four options with one correct answer. They are a fair sample of how the exam behaves: almost none of them asks you to recall a definition. Each one describes a situation and asks what the competent response is - and in most of them, more than one option is defensible. That is the exam. Q1. Two weeks after a violent incident at a facility, operations have resumed but absenteeism and resignations among the staff who were present are rising. Which resource does the recovery phase call for? a) Refresher training for the operational staff on duty b) A financial audit of the losses the incident caused c) Employee assistance and counseling support for affected staff d) Additional physical security measures at the affected facility www.certfun.com ASIS International CPP ASIS Certified Protection Professional (CPP) 8 Q2. A physical security upgrade is being designed for a building whose occupants include a research group with restricted areas and a public-facing reception. The project manager wants to run the design without involving them. Why should the occupants be engaged during design? a) Because consultation now removes the design review the project would otherwise have to schedule later. b) Because the design has to be aligned with how they actually work, or it will be defeated in daily use. c) Because their agreement recorded during design limits the changes they are able to request once work starts. d) Because their approval moves responsibility for the outcome of the upgrade to the departments affected. Q3. A distribution center’s continuity plan names a company-owned warehouse on the same industrial estate as the location operations will move to after a disruption. The security director is asked to endorse the arrangement before the plan goes to the board. What most weakens it? a) The proposed site is open to the same events as the one it would replace b) The proposed site holds no equipment reserved for the operation c) The proposed site has never been used for distribution work before d) The proposed site is company-owned rather than leased from a provider Q4. A hiring manager objects that background investigation is delaying recruitment for a role that handles cash and holds keys to the building. The security director has to state what the screening is for. What purpose should the director give? a) To apply the deepest checks available to every candidate, so that the standard cannot be called selective. b) To confirm the candidate meets the requirements this role and its governing regulations impose on the holder. c) To assess the personality characteristics that predict how a candidate will behave under pressure in the role. d) To reduce training cost by identifying the candidates who will need the least supervision once in post. www.certfun.com ASIS International CPP ASIS Certified Protection Professional (CPP) 9 Q5. An information security program holds a vulnerability scan of every system and has no basis for deciding which findings to fund first. The steering group asks how the threats to the organization’s information holdings should be evaluated. What has to be weighed? a) The controls each system lacks against the published baseline, weighed against the cost of closing them. b) The consequence of a holding being compromised, weighed against the likelihood a threat reaches it. c) The severity score the scanning tool assigns each finding, weighed against the effort needed to remediate it. d) The number of incidents the organization has recorded historically, weighed against the number its peers report. Q6. An investigator is preparing to interview an employee who was present when stock went missing. The manager who reported the loss has already named that employee as responsible. What is the objective of the interview? a) To obtain an objective account of what the employee observed b) To identify the countermeasures that would prevent the next loss of stock c) To record the chain of custody that the recovered property will follow d) To confirm the account the manager gave about the employee he named Q7. An organization that has handled incidents case by case is writing its first investigation policy. What is the first step in developing it? a) Training the workforce in the investigative techniques the unit must use b) Contracting an external firm to handle investigations the unit cannot c) Identifying the incident types the organization must investigate d) Publishing the policy so that all employees are on notice of it Q8. Ransomware is encrypting files on a production server. The organization intends both to resume operations and to preserve its ability to establish what happened. What should the response do first? a) Open communication with the actor to establish what recovery would cost b) Power the affected hosts down immediately in order to stop the encryption c) Restore the server from backup so operations resume without delay d) Isolate the affected hosts from the network while preserving their state www.certfun.com ASIS International CPP ASIS Certified Protection Professional (CPP) 10 Q9. A utility’s substation sits within several hundred acres of undeveloped land, and most of the boundary has neither power nor communications. The site owner wants periodic observation of the whole boundary rather than continuous coverage of a few points. Which surveillance method best fits those conditions, subject to the aviation and privacy rules where the site operates? a) A roving patrol driving the boundary on an irregular schedule b) Buried sensors along the sections with the highest recorded intrusion c) Scheduled unmanned aircraft flights over the full boundary d) Fixed cameras at the points where infrastructure already reaches Q10. A fire is burning in a warehouse on a manufacturing site. The fire service’s incident commander is directing crews at the scene, and the organization has activated its emergency operations center. What is the center’s role while the incident is running? a) To hold the organization’s data backups so that operations can be restored when the scene is released. b) To record the decisions taken at the scene so that the after-action review has an accurate account. c) To direct the tactical assignments of the crews at the scene from one consolidated position off site. d) To coordinate resources and information in support of the response at the scene. Answer key Q1 Q2 Q3 Q4 Q5 Q6 Q7 Q8 Q9 Q10 c b a b b a c d c d Read the pattern rather than the answers. Where two options both look reasonable, the CPP wants the one that serves the purpose of the activity rather than the convenience of the organisation: the interview gathers an account rather than confirming the accusation already made, the screening tests the requirements of the role rather than applying the deepest checks available to everyone, the emergency operations centre coordinates in support of the scene rather than commanding it, and the ransomware response preserves the evidence while it contains the incident. Options that are merely thorough, merely fast or merely defensive are the distractors. SECTION 07 Where to Go Next Before you apply, download the Board Certification Handbook fresh rather than working from a saved copy - it carries dated update notes throughout, and the testing changes described in Section 02 arrived in the August 2026 revision. Read the CPP Body of Knowledge next to your own CV and mark the tasks you could not sit down and do today; that list is your study plan. The official ASIS CPP page is where the Self-Assessment Guide, the practice exam of retired real items and the reference set all live. And when you want the part no document gives you - which domains people actually find hardest, how others structured six months of study around a full-time security job - ASIS Connects, the ASIS member community is where certificants and candidates compare notes, and where many local ASIS chapters run study groups. www.certfun.com ASIS International CPP ASIS Certified Protection Professional (CPP) 11 Quick reference Official CPP page, self-assessment and practice exam - asisonline.org/certification Board Certification Handbook - policies, fees, eligibility, scoring, testing rules CPP Body of Knowledge - the seven domains and all thirty task statements Syllabus, sample questions and practice test - certfun.com/asis Before you apply — the guide in one card Questions 225 (200 scored, 25 pretest) Time limit Four hours Scoring Scaled score, pass at 650 Not A flat 80% raw score Exam fee Member $580 / nonmember $910 Retest $480, nonrefundable Domains Seven: 22 / 16 / 15 / 14 / 13 / 11 / 9 Heaviest Security Principles, 22% Eligibility 7 years, or 6 with BA, or 5 with MA Of which 3 in responsible charge Delivery Prometric test centre Validity Three years, CPEs to recertify Good luck - and as you revise, keep asking one question of every scenario you meet: what would a security manager who is accountable for the outcome actually do here? The CPP is not testing whether you know the countermeasure. It is testing whether you would choose it, fund it, document it, and be able to explain it to a board afterwards.