ASIS APP Exam Guide: Associate Protection Professional Eligibility, Domains and Preparation

The Associate Protection Professional (APP) is ASIS International's entry-level board certification for security management. ASIS created it for people who are new to the security field or moving into it from another career. It is a first step, before the more senior Certified Protection Professional (CPP).

Who is eligible

According to ASIS, APP candidates need at least one year of related, compensated security experience. That drops to six months if you already hold a related, approved certification. Candidates also need to be employed full-time in a security-related role and agree to the ASIS Certification Code of Conduct. Check the current requirements on the ASIS website before applying.

Exam format

The APP exam has 100 scored multiple-choice questions plus 25 unscored pre-test questions, 125 in total. The unscored questions are mixed in and not identified, so answer every question as if it counts. ASIS offers the exam at test centers and through remote proctoring.

What the exam covers

The APP Body of Knowledge is organised into four domains:

  • Security Fundamentals — core security principles, programmes and practices.
  • Business Operations — how security fits into, and supports, the wider organisation.
  • Risk Management — identifying, assessing and treating security risks.
  • Response Management — preparing for and responding to incidents and emergencies.

The domains are weighted by how important they are to the job, based on ASIS's analysis of what early-career security professionals actually do. The official Body of Knowledge lists the tasks and knowledge statements under each domain. Use it as your study checklist.

How to prepare

Build the business view early. Candidates with purely operational experience, such as guarding, patrol or monitoring, often find business operations and risk management the least familiar areas. Put extra time there.

Think in terms of process. APP questions often ask for the most appropriate next step or the best overall approach. Knowing the logical sequence of risk assessment and incident response helps you rule out answers that are reasonable but premature.

Study against the Body of Knowledge. Work through the official BoK and note which knowledge statements you can't yet explain in your own words.

Practise at full length. 125 questions is a long sitting. Timed practice builds the focus you need and shows which domain is holding your score back.

Study resources from CertCraft

Planning ahead? See our guides to the senior Certified Protection Professional (CPP) and the Professional Certified Investigator (PCI), or browse our Security Management collection.

Always confirm current eligibility requirements, exam specifications and fees with ASIS International before applying. CertCraft Institute is an independent study resource and is not affiliated with, endorsed by, or sponsored by ASIS International.