CERTIFIED PROTECTION
PROFESSIONAL CPP
PRACTICE EXAM
Question 1: A security director adopting Enterprise Security Risk Management
(ESRM) is deciding who should help evaluate a critical manufacturing process. Which approach BEST reects ESRM?
Choices:
1) Delegate the assessment entirely to the alarm-system vendor 2) Limit participation to security personnel to preserve condentiality 3) Let security independently set the risk tolerance for the process 4) Engage the business owner of the process to help identify assets, risks, and acceptable treatment Correct Answer: Engage the business owner of the process to help identify assets, risks, and acceptable treatment Explanation: ESRM aligns security risk decisions with enterprise objectives, so the business owner or asset owner should participate in identifying risk and deciding treatment.Page 1
Question 2: A security manager is preparing for a facility survey. What should be done FIRST to make the survey ecient and complete?
Choices:
1) Begin by testing every alarm without notifying stakeholders 2) Review existing plans, prior assessments, incident data, and relevant policies before the site visit 3) Replace existing controls before inspecting them 4) Interview only the security vendor Correct Answer: Review existing plans, prior assessments, incident data, and relevant policies before the site visit Explanation: Document review provides context and helps the survey team target onsite observations and interviews.Question 3: A security department budget shows actual overtime costs of $132,000 against a budget of $120,000. What is the unfavorable variance?
Choices:
1) $120,000
2) $252,000
3) $10,000
4) $12,000
Correct Answer: $12,000
Explanation: The unfavorable variance is actual cost minus budgeted cost: $132,000 - $120,000
= $12,000.
Page 2
Question 4: An information-security survey is beginning. What should the team
identify FIRST to make risk decisions meaningful?
Choices:
1) The brand of rewall currently installed 2) The color of employee ID cards 3) The information assets, business processes, owners, and their protection requirements 4) The number of help-desk tickets last year Correct Answer: The information assets, business processes, owners, and their protection requirements Explanation: Information security risk assessment starts with understanding what information and processes require protection and who owns them.Question 5: A crisis manager is ranking hazards for planning. Which factors should be considered together?
Choices:
1) Media interest only 2) Likelihood, potential consequences, and the organization's vulnerability or exposure 3) The cost of emergency uniforms 4) Whether the hazard occurred last year Correct Answer: Likelihood, potential consequences, and the organization's vulnerability or exposure Explanation: Prioritization should consider how likely a hazard is, how severe its consequences could be, and how exposed or vulnerable the organization is.Page 3