← All CPP Flashcard Decks

Mixed Deck — All CPP Topics Flashcards

99 cards from real CPP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 20 Mixed Deck — All CPP Topics flashcards as text
  1. Which of the following is considered a primary and essential study resource provided by ASIS International for CPP exam preparation?

    Answer: The "Protection of Assets" (POA) reference set.

    The "Protection of Assets" (POA) reference set is the foundational body of knowledge for the CPP certification, published by ASIS International. It is considered the primary and essential study resource because it comprehensively covers all the domains and principles tested on the exam. Candidates are expected to have a deep understanding of the information contained within the POA to succeed.

  2. What is the recommended sequence for applying the risk management process when planning physical security upgrades?

    Answer: Identify assets → Analyze threats → Assess vulnerabilities → Select countermeasures

    The standard risk management cycle begins with asset identification, then threat and vulnerability analysis before selecting proportionate countermeasures.

  3. Which of the following is a domain covered by the CPP exam?

    Answer: Operations and physical security management

    The CPP exam covers several key domains that reflect the breadth of security management responsibilities. Operations and physical security management is one of these core domains, encompassing topics like access control, surveillance, security personnel deployment, and emergency procedures. This domain is fundamental to protecting assets and personnel in various organizational settings, making it a critical area of expertise for CPPs.

  4. Under the Stored Communications Act (SCA), a company that wishes to access an employee's personal email account stored on a third-party server generally must:

    Answer: Obtain employee consent or a valid legal process (warrant/court order)

    The SCA restricts unauthorized access to stored electronic communications, requiring either voluntary consent or lawful legal process to access third-party-hosted accounts.

  5. How should professionals apply continuing education requirements in daily practice?

    Answer: Consistently integrate best practices into every aspect of professional work

    Consistent application of professional standards ensures quality outcomes and builds professional credibility.

  6. Which perimeter barrier is considered a passive anti-ram measure?

    Answer: Bollards

    Bollards are engineered posts designed to stop or deflect vehicles without active mechanical operation.

  7. Which of the following is a key benefit of attending a CPP review course?

    Answer: They provide targeted study and exam-taking strategies.

    CPP review courses are specifically designed to provide targeted study and exam-taking strategies, condensing vast amounts of information into a manageable format. Instructors often share insights into the ASIS body of knowledge, highlight key concepts, and offer tips for understanding question nuances. This focused approach helps candidates optimize their study efforts and improve their chances of success by understanding what to prioritize.

  8. Which document formally describes the security requirements and constraints that a new facility must meet during its design and construction phase?

    Answer: Basis of Design (BOD) / Security Design Criteria

    The Basis of Design or Security Design Criteria document captures all security performance requirements that architects and engineers must incorporate.

  9. How should applied methods and techniques knowledge be maintained and updated?

    Answer: Through continuous professional development, current literature review, and professional networking

    Professional competence requires ongoing development through education, literature review, and engagement with the professional community.

  10. A company wants to implement an access control system that provides the highest level of security and accountability. Which of the following technologies would be MOST appropriate?

    Answer: Biometric access with multi-factor authentication and detailed audit logs.

    For the highest level of security and accountability in an access control system, biometric access combined with multi-factor authentication (MFA) is superior. Biometrics provide unique personal identification, MFA adds an additional layer of verification, and detailed audit logs record every access attempt. This combination significantly reduces the risk of unauthorized access and provides a robust, verifiable trail for accountability and incident investigation.

  11. What ethical standard governs core concepts and principles practice?

    Answer: Adherence to the profession's code of ethics and applicable laws and regulations

    Professional ethics codes and applicable laws provide the framework for ethical practice in every professional field.

  12. What ethical standard governs applied methods and techniques practice?

    Answer: Adherence to the profession's code of ethics and applicable laws and regulations

    Professional ethics codes and applicable laws provide the framework for ethical practice in every professional field.

  13. The Incident Command System (ICS) was developed primarily to address which operational problem?

    Answer: Poor multi-agency coordination and communication during incidents

    ICS was designed to solve chronic problems of poor coordination, conflicting communication, and unclear command authority when multiple agencies respond to the same incident.

  14. Piggybacking (or tailgating) is a threat specifically addressed by which physical control?

    Answer: Mantraps or airlock vestibules

    A mantrap allows only one person to pass through a controlled entry at a time, preventing an unauthorized person from following an authorized one.

  15. A security vulnerability assessment (SVA) differs from a security risk assessment primarily because the SVA:

    Answer: Focuses on identifying weaknesses in existing countermeasures

    An SVA zeroes in on gaps in current protective measures, while a risk assessment also weighs threat likelihood and asset value.

  16. Which investigative technique involves placing an undercover operative within a suspect group to gather evidence of wrongdoing?

    Answer: Covert undercover operation

    A covert undercover operation inserts an investigator into a target environment to observe and document criminal or policy-violating behavior firsthand.

  17. In business continuity planning, what characterizes a 'warm site'?

    Answer: A site with basic infrastructure already in place requiring equipment installation and configuration before use

    A warm site has basic infrastructure such as power, network connectivity, and space pre-installed, but requires additional equipment setup before becoming operational, typically within 24 to 72 hours.

  18. A Closed-Circuit Television (CCTV) system is classified primarily as which type of security control?

    Answer: Deterrent and detective

    CCTV deters criminal activity through its visible presence and detects incidents by capturing video evidence.

  19. What quality assurance measure supports industry best practices?

    Answer: Regular self-assessment, peer review, and adherence to established standards

    Ongoing quality assurance through self-assessment, peer review, and standards adherence ensures continuous improvement.

  20. What does the Recovery Time Objective (RTO) define in business continuity planning?

    Answer: The maximum acceptable downtime before a business function must be restored

    RTO defines the maximum tolerable downtime for a critical business function, establishing the deadline by which that function must be restored after a disruption.