ASIS APP Exam Prep Free practice test →

Free ASIS APP Practice Questions

10 free, exam-style ASIS Associate Protection Professional (ASIS APP) practice questions with answers and explanations. No signup required. Work through them below, then take the full free ASIS APP practice test to study every exam domain.

These 10 free ASIS APP questions are organized by exam domain, so you can see how each part of the ASIS Associate Protection Professional blueprint is tested. Reveal the answer and explanation under each question.

Domain 1: Security Fundamentals 35% of exam

Question 1

A CSO presents an ESRM assessment to the executive team, identifying a significant vulnerability in the warehouse access control system. The VP of Operations asks who is ultimately responsible for deciding whether to fund the remediation. According to the ESRM framework, the CSO should explain that this decision rests primarily with:

  1. The Chief Risk Officer, who is chartered to coordinate enterprise-wide risk management decisions
  2. The Chief Security Officer, since protecting organizational assets is the security department's core mandate
  3. The facilities department, as they manage the physical infrastructure that contains the vulnerability
  4. The VP of Operations, as the owner of the warehouse asset who must accept or fund treatment of the risk
Show answer & explanation

Correct answer: D - The VP of Operations, as the owner of the warehouse asset who must accept or fund treatment of the risk

Question 2

A corporate campus redesign includes replacing solid perimeter walls with ornamental fencing, trimming all shrubs to below three feet, positioning the security desk at the building entrance with a clear sightline to the parking area, and installing large windows along the ground floor. Which CPTED principle do these changes PRIMARILY demonstrate?

  1. Natural Surveillance
  2. Territorial Reinforcement
  3. Natural Access Control
  4. Target Hardening
Show answer & explanation

Correct answer: A - Natural Surveillance

Question 3

A hospital security officer receives a report that a floor nurse has been receiving repeated threatening phone calls at her workstation from her former domestic partner. The individual has no employment or patient relationship with the hospital but has appeared in the lobby on two occasions asking for the nurse. According to the ASIS WVPI Standard workplace violence classification, this situation BEST represents:

  1. Type I: Criminal Intent, because the former partner is trespassing and poses an intentional criminal threat
  2. Type II: Customer/Client, because the perpetrator is accessing the facility as a member of the public
  3. Type III: Worker-on-Worker, because the victim is a current hospital employee and the threatening behavior is occurring within the workplace environment
  4. Type IV: Personal Relationship, because the perpetrator has a personal tie to an employee but no organizational relationship
Show answer & explanation

Correct answer: D - Type IV: Personal Relationship, because the perpetrator has a personal tie to an employee but no organizational relationship

Question 4

A security assessment of a distribution facility reveals that the perimeter has concrete anti-ram vehicle barriers, reinforced gates, and high-security fencing. However, the assessment also finds there are no exterior lighting systems, no perimeter sensors, and no CCTV coverage of the outer grounds. Based on Physical Protection System (PPS) principles, which finding represents the GREATEST operational gap?

  1. The facility has no response force positioned to intercept a threat at the outer perimeter
  2. The vehicle barriers may be insufficient to stop a determined attacker using a heavy commercial truck
  3. Threats cannot be detected before reaching the delay layer, making the barriers operationally ineffective
  4. The absence of interior access controls means any adversary who breaches the perimeter has unrestricted movement toward the protected asset
Show answer & explanation

Correct answer: C - Threats cannot be detected before reaching the delay layer, making the barriers operationally ineffective

Domain 2: Business Operations 22% of exam

Question 5

A security department publishes a document titled 'Visitor Access Instructions' which states: 'Step 1 - Request the visitor's government-issued photo ID. Step 2 - Enter the visitor's name and purpose into the visitor management system. Step 3 - Issue a temporary badge and notify the employee host. Step 4 - Escort the visitor from the lobby to the destination.' Within the security policy hierarchy, this document is BEST classified as a:

  1. Procedure
  2. Security management policy
  3. Guideline
  4. Standard
Show answer & explanation

Correct answer: A - Procedure

Question 6

A security director presents the following four metrics to the executive team during a quarterly review: (1) total number of security incidents reported last quarter; (2) average time to close an investigation over the past year; (3) number of tailgating events detected by the access control system last month; (4) percentage of employees who completed the annual security awareness training program this cycle. Which metric is BEST described as a leading indicator of future security performance?

  1. Total number of security incidents reported to the security operations center during the previous quarter, broken down by category and location
  2. Average time to close an investigation over the past year
  3. Number of tailgating events detected by the access control system last month
  4. Percentage of employees who completed the annual security awareness training program
Show answer & explanation

Correct answer: D - Percentage of employees who completed the annual security awareness training program

Domain 3: Risk Management 25% of exam

Question 7

A security manager is evaluating a proposed $18,000-per-year server room access control upgrade. The server hardware is valued at $600,000. Based on historical incidents, a breach has a 30% exposure factor and is expected to occur approximately twice per year. What is the Annualized Loss Expectancy (ALE), and is the countermeasure financially justified?

  1. $90,000 ALE; not justified, because the countermeasure cost exceeds one year of expected loss
  2. $180,000 ALE; not justified, because insurance would be a more cost-effective risk treatment
  3. $360,000 ALE; justified, because the ALE far exceeds the annual countermeasure cost
  4. $600,000 ALE; justified, because the full asset value is at risk each year
Show answer & explanation

Correct answer: C - $360,000 ALE; justified, because the ALE far exceeds the annual countermeasure cost

Question 8

A security director identifies that aging water pipes above the primary data center pose a significant flooding risk. While a long-term relocation project is approved, she recommends immediately purchasing property damage and business interruption insurance. This recommendation BEST represents which risk treatment strategy?

  1. Risk avoidance, because the organization is protecting itself from absorbing the full financial loss
  2. Risk transfer, because the financial consequence of a loss event is shifted to the insurer
  3. Risk mitigation, because a proactive action is being taken to reduce the impact of the threat
  4. Risk acceptance, because no physical changes are being made to address the root cause
Show answer & explanation

Correct answer: B - Risk transfer, because the financial consequence of a loss event is shifted to the insurer

Question 9

Following a data center fire, a healthcare organization attempts to restore its electronic health records system. The most recent available backup was created 22 hours before the incident. The organization's documented Recovery Point Objective (RPO) for this system is 6 hours. Which statement BEST describes this situation?

  1. The organization met its RPO because backup data from the previous day is still available for restoration
  2. The organization failed to meet its RPO, as the potential data loss of up to 22 hours exceeds the 6-hour acceptable threshold
  3. The organization successfully met its RPO, because the backup captured the prior operational period and supports a complete system restoration to a known-good state
  4. The organization should update its Business Impact Analysis to revise the RPO to 24 hours to reflect operational reality
Show answer & explanation

Correct answer: B - The organization failed to meet its RPO, as the potential data loss of up to 22 hours exceeds the 6-hour acceptable threshold

Domain 4: Response Management 18% of exam

Question 10

During a major industrial fire response, the Incident Commander realizes that 12 individuals - section supervisors, agency liaisons, a safety officer, and logistics leads - are all reporting directly to her. According to ICS principles, what corrective action should she take FIRST?

  1. Designate a Public Information Officer to manage all external stakeholder communication, which will reduce the total number of individuals reporting directly to the Incident Commander
  2. Request activation of the Emergency Operations Center to shift strategic coordination off-site
  3. Establish additional supervisory positions to reduce each supervisor's span of control
  4. Transition to Unified Command so that command responsibilities are distributed across responding agencies
Show answer & explanation

Correct answer: C - Establish additional supervisory positions to reduce each supervisor's span of control

Ready for the real thing?

Practice hundreds more ASIS APP questions with instant scoring, weak-area drills, and full exam simulations.

Start the free practice test See pricing