CPP Study Guide — 2026 Edition cover

CPP — Certified Protection Professional · 2026 Edition

CPP Study Guide — 2026 Edition

The seven CPP domains taught from public primary sources: 326 original questions with worked explanations and a 225-question full-length practice exam.

  • 326 original CPP practice questions, each with a worked explanation, in one PDF + EPUB you keep

PDF + EPUB · English · 154 pages · $24.99 one-time

This book is written in English.

Instant download after payment — no account needed, no subscription.

14-day money-back guarantee: not satisfied for any reason? Email support@preppass.org within 14 days of purchase for a full refund. Refund policy

Read a free sample chapter first

Look inside the book

Three real pages, rendered straight from the PDF you download — a reference page, a teaching page, and a worked question, always in that order. Nothing here was redrawn to look better.

  • Quick reference
    Chapter 1 — Security Principles and Practices · PDF page 11

    A page you can turn back to: the numbers, deadlines or terms gathered in one place.

  • How it's taught
    Chapter 6 — Information Security · PDF page 56

    An explanation page: the material taught in prose, in the order the exam tests it.

  • A question, worked
    Chapter 4 — Personnel Security · PDF page 43

    A practice question with its answer and the reasoning behind it — not just a key.

About the CPP exam

Security managers and directors preparing for ASIS International's Certified Protection Professional exam. This independent guide teaches the seven published domains from public sources and includes chapter quizzes and a full-length practice exam. It is not produced or endorsed by ASIS and has no online practice component.

Certified Protection Professional — exam facts
Awarding bodyASIS International
QuestionsApproximately 225 multiple-choice questions: 200 scored and 25 unscored pretest; four answer choices each.
Time limitFour hours.
Passing ruleReported as a scaled score; ASIS does not publish a percentage or number-correct equivalent.
FeesASIS member $580; Emerging Market 1 $480; Emerging Market 2 $460; Nonmember $910 (updated 6 January 2025).
DeliveryAt Prometric test centers worldwide; from 1 September 2026, remote proctoring is available only as an approved accommodation.
EligibilityWithout a degree: seven years of security experience (six with the APP), including three years in responsible charge of a security function; shorter periods with a bachelor's or master's degree.
RetakesUp to three attempts during the one-year eligibility period; 60 days between testing dates; retest fee $480.
Content outlineCPP Body of Knowledge (domains, tasks and knowledge statements), As published with the CPP, PCI, PSP, and APP Certification Exams 2026 Handbook (updated 4 August 2026)
Domains and weights
  • Security Principles and Practices — 22%
  • Business Principles and Practices — 15%
  • Investigations — 9%
  • Personnel Security — 11%
  • Physical Security — 16%
  • Information Security — 14%
  • Crisis Management — 13%

Questions buyers ask

How many questions are on the CPP exam, and how long is it?
The CPP has approximately 225 multiple-choice questions — 200 scored and 25 unscored pretest items — and candidates have four hours.
What score do I need to pass the CPP?
ASIS reports results as scaled scores derived from raw scores so that different exam forms are comparable. ASIS does not publish a percentage or number-correct cutoff.
What are the CPP domains and their weights?
Security Principles and Practices 22%, Business Principles and Practices 15%, Investigations 9%, Personnel Security 11%, Physical Security 16%, Information Security 14%, and Crisis Management 13%.
Which edition of the CPP outline is current?
The current domains and tasks are those published with the 2026 certification handbook, updated 4 August 2026. ASIS states that a job analysis is routinely conducted but does not publish an effective date or a change summary for the outline.
Am I eligible for the CPP?
Without a degree, you need seven years of security experience (six if you hold the APP), including at least three years in responsible charge of a security function; shorter periods apply with a bachelor's or master's degree.
What does the CPP cost, and can I retake it?
The exam fee is $580 for ASIS members and $910 for nonmembers, with lower emerging-market rates. You may test up to three times in your one-year eligibility period, 60 days apart, with a $480 retest fee.
Can I take the CPP from home?
Not generally. ASIS exams are delivered at Prometric test centers, and from 1 September 2026 remote proctoring is available only through an approved accommodation.
How is this study guide organized?
Seven chapters follow the seven CPP domains, each ending with a quiz, followed by a 225-question practice exam weighted like the real exam; 326 questions in all, priced at $24.99.
Is a study guide enough for the CPP — Certified Protection Professional exam, or do I need a course?
Check eligibility first — per ASIS International: without a degree: seven years of security experience (six with the APP), including three years in responsible charge of a security function; shorter periods with a bachelor's or master's degree. A book does not replace those requirements. For the exam content itself, this 154-page guide teaches the material chapter by chapter with 326 practice questions and explanations inside. A prep course adds live instruction and a set schedule; whether you need one beyond any required education is your call.
Does the CPP — Certified Protection Professional study guide come as a PDF?
Yes — CPP Study Guide — 2026 Edition downloads as PDF and EPUB, 154 pages. The download link is emailed the moment payment clears and does not expire.
How much does the CPP — Certified Protection Professional study guide cost?
$24.99, once. There is no subscription and no account to create; the PDF and EPUB files are yours to keep.
Can I read part of the CPP — Certified Protection Professional study guide before buying?
Yes. A full chapter is free to read on this page — not a summary of one, the chapter itself.
Is this the official CPP — Certified Protection Professional study guide?
No. This is an independent study guide and is not affiliated with or endorsed by the exam's awarding body. It is written from ASIS International's CPP, PCI, PSP, and APP Certification Exams 2026 Handbook (updated 4 August 2026). Always confirm current requirements with the body that issues your licence.

What's included — and what isn't

Included

  • All seven CPP domains, with every published task under its own heading
  • A quiz closing each of the 7 chapters, with worked explanations
  • A 225-question practice exam at the published domain weights
  • 326 original questions, each explained and cited to its source
  • Taught from public sources: NIST, FEMA, DHS, OSHA
  • PDF + EPUB you keep

Not included

  • No printed copy is shipped — this is a file you download and can print yourself
  • No video course, instructor, tutoring or online question bank comes with the book — everything is in the file
  • Not your exam registration or the testing centre's fee, which you still pay to the official body

Contents

See 9 sections and the page each one starts on
  1. Chapter 1 — Security Principles and Practicesp. 7
  2. Answer key & explanationsp. 17
  3. Chapter 2 — Business Principles and Practicesp. 21
  4. Chapter 3 — Investigationsp. 31
  5. Chapter 4 — Personnel Securityp. 38
  6. Chapter 5 — Physical Securityp. 46
  7. Chapter 6 — Information Securityp. 55
  8. Chapter 7 — Crisis Managementp. 64
  9. Appendix A — Precise Termsp. 144

Taken from the PDF you download, with the page each one starts on — not typed here.

Read a chapter free, in full

One complete chapter, exactly as it ships in the eBook. Scroll the window to read it right here; no download, no email.

Read chapter 1 here, without leaving the page
FREE SAMPLE — READ IT RIGHT HERE
Chapter 1 · 22% of the exam · ≈14 min read
Security Principles and Practices
scroll ↓

This is the largest domain on the exam, and it is the one that frames everything else. The CPP treats security as a management discipline: a program is planned, risks are assessed with a repeatable method, the program is improved continuously, relationships outside the organization are managed deliberately, and the workforce is trained. Nearly every question in this chapter tests whether you think like a program manager or like a guard supervisor — the exam rewards the program manager.

Task 1 — Plan, develop, implement and manage the security program (ESRM)

The Body of Knowledge opens with the task to plan, develop, implement, and manage the organization's security program to protect the organization's assets. ASIS's published model for this work is Enterprise Security Risk Management (ESRM): a strategic approach to security management that ties an organization's security practice to its overall strategy using globally established and accepted risk management principles. The single most testable idea in ESRM is the shift in who owns risk. ESRM places the responsibility for security risk management decision making with the asset owners — in other words, whoever owns the asset owns the risk — while the security professional adopts the role of advisor rather than enforcer. On the exam, the wrong answers will cast the security manager as the person who decides what risk is acceptable; the right answer puts that decision with the asset owner and keeps security in the advisory seat.

ESRM runs as a four-step cycle. The first step is to identify and prioritize assets: understand what the assets are, where they are, and why they matter to the organization's mission, then prioritize by the impact each asset has on the organization's ability to execute that mission. The second step is to identify and prioritize risks to those assets. The third step is to mitigate the prioritized risks, choosing strategies that balance costs with acceptable risk levels. The fourth step is ongoing continuous improvement — the program is never declared finished. Underpinning the cycle are four pillars: holistic risk management (consider all types of security risk), partnership with stakeholders (security as trusted partner, not unilateral enforcer), transparency (be open with stakeholders about identified risks and the process used to prioritize and mitigate them), and governance (a governing body or committee leads the risk-tolerance discussion and makes top-level decisions).

How this is tested: a scenario describes a disagreement about a security spend or a residual risk, and asks who decides or what security's role is. The trap answers sound responsible — "the security director accepts the risk" — but in ESRM the director advises and the asset owner decides. Another favorite: asking which step of the cycle comes next. Remember the order — assets first, then risks, then mitigation, then continuous improvement — because the exam will offer "mitigate risks" as a tempting answer to a question whose scenario is still at the asset-identification stage.

Task 2 — The security risk assessment process

Task 2 asks you to develop, manage, or conduct the security risk assessment process. NIST SP 800-30 defines risk as a measure of the extent to which an entity is threatened by a potential circumstance or event — typically a function of the adverse impacts if the event occurs and the likelihood of occurrence. That two-factor structure (likelihood × impact) is the spine of every risk assessment method the exam touches.

Assessments come in three flavors. Qualitative assessments use nonnumerical categories or levels — very low, low, moderate, high, very high — and they are best at communicating risk results to decision makers. Quantitative assessments use numbers whose meanings and proportionality hold inside and outside the assessment — dollars, frequencies, probabilities — and they most effectively support cost-benefit analyses of alternative risk responses. Semiquantitative assessments sit between: they use bins, scales, or representative numbers (like a 1–5 matrix) whose values do not carry real-world meaning outside the assessment. The exam loves to ask which method fits a situation: a board presentation asking "how bad is it" wants qualitative; a budget decision comparing two countermeasures wants quantitative.

Quantitative analysis has its own vocabulary, and the exam expects you to compute. Single Loss Expectancy is the loss from one occurrence: SLE = asset value × exposure factor (EF), where EF is the fraction of the asset's value lost to the threat. Annualized Loss Expectancy spreads that over a year: ALE = SLE × ARO, where ARO is the annualized rate of occurrence. A countermeasure is worth buying when its value — the ALE it removes, i.e., ALE before minus ALE after — exceeds its cost; one common formulation is ROI = countermeasure value ÷ countermeasure cost, and a value above 1.0 means the control pays for itself. Watch the trap that confuses SLE with ALE: the question gives an ARO and asks for the annual figure, and one option is the single-loss number.

Finally, once risks are assessed, NIST names five families of risk response: acceptance, avoidance, mitigation, sharing, and transfer. Acceptance means living with the risk; avoidance means eliminating the activity that creates it; mitigation means reducing likelihood or impact; sharing spreads the risk (for example across partners); transfer shifts the financial consequence to a third party, classically through insurance. The exam tests the distinctions: buying insurance is transfer, not mitigation; discontinuing a product line is avoidance, not acceptance.

Task 3 — Continuous improvement through auditing, review and assessment

Task 3 — evaluate methods to improve the security program on a continuous basis through auditing, review, and assessment — is the ESRM fourth step wearing operational clothes. Audits test conformance against a standard or policy; reviews are management-level examinations of whether the program still fits the organization's needs; assessments measure current performance against objectives. Incidents and investigations feed this loop: ESRM explicitly notes that operational tasks like incident response offer the ancillary benefit of fueling continuous improvement. The trap here is treating improvement as a one-time project with an end date — the exam's right answers always describe a recurring cycle, and the wrong ones describe a single certification or a finished overhaul.

Task 4 — Relationships with external organizations

Task 4 asks you to develop and manage professional relationships with external organizations to achieve security objectives. This is the liaison portfolio: law enforcement agencies, emergency services, regulators, industry groups, and neighboring organizations. The tested principles are practical — know your contacts before the crisis, establish information-sharing channels in advance, understand jurisdictional boundaries, and coordinate rather than freelance. Questions here are usually scenario-based: a facility faces a threat that crosses property lines, and the correct answer involves engaging the appropriate external agency or mutual-aid partner rather than handling it entirely in-house. The wrong answers either ignore the external party or suggest the security team assume powers it does not have.

Task 5 — Workforce security awareness programs

Task 5 — develop, implement, and manage workforce security awareness programs — treats the workforce as a control. A program needs defined objectives tied to organizational goals, content matched to roles and risk (executives, travelers, new hires, contractors), delivery methods that fit the audience, and measurement: completion rates, phishing-test click rates, incident-reporting rates. The exam tests two things repeatedly: that awareness is an ongoing program rather than a one-time briefing, and that it is measured. A tempting wrong answer describes a single annual video with no follow-up; the right answer describes recurring training with metrics and reinforcement.

Key numbers & deadlines

FigureValueSource
Risk (NIST SP 800-30)Function of adverse impact × likelihood of occurrence[1]
SLEAsset value × exposure factor[2]
ALESLE × annualized rate of occurrence[2]
Countermeasure ROICountermeasure value ÷ countermeasure cost[2]
Risk responsesAcceptance, avoidance, mitigation, sharing, transfer[1]
ESRM cycleAssets → risks → mitigation → continuous improvement[3]

Key takeaways

  • In ESRM, asset owners own risk decisions; security advises. The exam punishes answers that make the security manager the decider.
  • Assess in order: identify and prioritize assets first, then risks, then mitigate, then improve continuously.
  • Qualitative communicates to decision makers; quantitative supports cost-benefit decisions; semiquantitative uses bins and scales.
  • SLE is per-occurrence loss; ALE is per-year loss (SLE × ARO). A countermeasure pays when its ALE reduction exceeds its cost.
  • Insurance is risk transfer; dropping the activity is avoidance; reducing likelihood or impact is mitigation.
  • Improvement is a recurring cycle fed by audits, reviews, assessments, and lessons from incidents — never a one-time project.
  • Awareness programs are ongoing and measured, not one-time briefings.

Chapter 1 quiz — 22 questions

1. A security analyst must compare two proposed countermeasures for the board and show which one returns more value per dollar spent. Which assessment type most effectively supports that cost-benefit analysis?

  • A. A qualitative assessment
  • B. A semiquantitative assessment
  • C. A quantitative assessment
  • D. A descriptive assessment

2. A new security manager is building the company's first formal security program. According to the ESRM cycle, what should she do first?

  • A. Buy countermeasures for the highest risks
  • B. Write the incident response procedures
  • C. Benchmark against peer company programs
  • D. Identify and prioritize the organization's assets

3. A manufacturing firm's operations VP refuses to fund a recommended upgrade to the plant's intrusion alarms, saying the current risk is acceptable to her. Under the ESRM model, whose decision is that to make?

  • A. The security director, as the program owner
  • B. The operations VP, as the asset owner
  • C. The finance director, as the budget holder
  • D. The alarm vendor, as the technical expert

4. A company discontinues its cash-handling service at retail sites after a string of robberies. Which risk response does this represent?

  • A. Risk avoidance
  • B. Risk acceptance
  • C. Risk mitigation
  • D. Risk transfer

5. A security manager wants to know whether the phishing awareness program is working. Which metric best measures its effectiveness?

  • A. The number of training slides used
  • B. The total hours of training delivered
  • C. The trainer's satisfaction survey score
  • D. The phishing-test click rate over time

6. A CEO asks why the security budget funds both guards and cybersecurity tools instead of focusing on one. Which ESRM pillar best justifies the answer?

  • A. Holistic risk management
  • B. Governance by committee
  • C. Transparency with stakeholders
  • D. Continuous improvement cycles

7. A hospital buys an insurance policy covering losses from equipment theft. Which risk response does the purchase represent?

  • A. Risk mitigation
  • B. Risk sharing
  • C. Risk transfer
  • D. Risk acceptance

8. Under ESRM, a security professional who tells business units which risks they must accept and enforces the decision is violating which pillar?

  • A. Stakeholder partnership
  • B. Holistic risk management
  • C. Transparency of process
  • D. Governance structure

9. During a regional flood, a plant's security team considers directing traffic on public roads around the site. What is the correct approach to external coordination?

  • A. Take over traffic control immediately
  • B. Hire contractors to block the roads
  • C. Coordinate with local law enforcement
  • D. Close the roads without notice

10. A company installs sprinklers that cut a fire's expected damage from 70% of a warehouse's value to 20%. If the warehouse is worth $1,000,000, what is the single loss expectancy after the control?

  • A. $700,000
  • B. $500,000
  • C. $200,000
  • D. $300,000

11. A facility borders a rail yard where trespassers regularly cut through the property. The security manager wants a coordinated response. Which external relationship is most appropriate to develop first?

  • A. The rail operator's security team
  • B. A private investigation firm
  • C. An executive protection provider
  • D. A cybersecurity consultant

12. A server worth $200,000 faces a ransomware threat expected to destroy 40% of its value per incident, occurring on average once every four years. What is the annualized loss expectancy?

  • A. $80,000
  • B. $20,000
  • C. $50,000
  • D. $32,000

13. A company rolls out security awareness training as a single 20-minute video shown once at new-hire orientation, with no follow-up. What is the principal weakness of this program?

  • A. The video format is outdated
  • B. It is not ongoing or measured
  • C. New hires are the wrong audience
  • D. Orientation is too early for training

14. An organization shares threat intelligence with peer companies through an industry group so all members benefit. Which risk response does this best illustrate?

  • A. Risk transfer
  • B. Risk sharing
  • C. Risk avoidance
  • D. Risk acceptance

15. An assessment scores threats on a 1-to-5 scale where the numbers rank severity but do not represent dollars or real frequencies. Which type is it?

  • A. Semiquantitative
  • B. Quantitative
  • C. Qualitative
  • D. Deterministic

16. A security director presents risk findings to the executive team using plain-language categories because the audience needs a clear picture fast. Which assessment strength is she relying on?

  • A. Quantitative precision in dollar terms
  • B. Statistical modeling of rare events
  • C. Automated scoring of vulnerabilities
  • D. Clear communication to decision makers

17. A security program's annual review finds that the threat landscape changed but the policies did not. Which improvement activity most directly addresses that gap?

  • A. A compliance audit against the old policy
  • B. A guard force headcount increase
  • C. A vendor contract renewal
  • D. A management review of program fit

18. A countermeasure costs $15,000 per year and reduces a threat's ALE from $60,000 to $30,000. What is the countermeasure's ROI under the value-over-cost formulation?

  • A. 0.5
  • B. 1.0
  • C. 4.0
  • D. 2.0

19. During a risk workshop, stakeholders disagree about how much risk the company should tolerate. Under the ESRM pillars, which body should lead that discussion and make the top-level decision?

  • A. The security department alone
  • B. A governing committee
  • C. The external audit firm
  • D. The insurance broker

20. A risk assessment report states that a data-center flood has "high" impact and "low" likelihood, using labeled categories rather than dollar figures. Which assessment type does this describe?

  • A. A qualitative assessment
  • B. A quantitative assessment
  • C. A semiquantitative assessment
  • D. A probabilistic assessment

21. After a theft investigation reveals a guard tour was skipped for weeks, the security manager revises the patrol policy and adds supervisor spot-checks. Which ESRM step does this illustrate?

  • A. Identifying and prioritizing assets
  • B. Ongoing continuous improvement
  • C. Mitigating prioritized risks
  • D. Establishing governance pillars

22. A risk register lists a threat with an annualized rate of occurrence of 0.25. What does that figure mean?

  • A. The threat occurs every four months
  • B. The threat has a 25% chance each month
  • C. The threat is expected once every four years
  • D. The threat already occurred 25 times

Answer key & explanations

1. C. Quantitative assessments use numbers whose meanings and proportionality hold inside and outside the assessment, and they most effectively support cost-benefit analyses of alternative risk responses. Comparing value per dollar is exactly that analysis, so the quantitative approach fits and the qualitative one does not.[1]

2. D. The ESRM cycle begins by identifying and prioritizing assets — understanding what they are, where they are, and why they matter to the mission — before risks are identified, mitigated, or improved upon. Buying countermeasures first skips the foundation the whole cycle rests on, which is why it is the trap.[3]

3. B. ESRM places security risk management decision making with the asset owners — whoever owns the asset owns the risk — and the security professional serves as advisor rather than enforcer. The operations VP, as asset owner, decides whether the residual risk is acceptable; the security director's role is to frame the risk and recommend, not to overrule. The tempting wrong answer is the security director, which describes the old enforcer model ESRM replaces.[3]

4. A. Avoidance eliminates the activity that creates the risk — here, the cash-handling service itself. Mitigation would reduce the robbery risk while keeping the service; acceptance would keep the service and live with the risk. Discontinuing the activity is the textbook avoidance move.[1]

5. D. Effectiveness is shown by outcomes: NIST treats the number of people who report a phishing test appropriately[4] and the share who change a behavior[4] as measures of whether the program works. Slides, hours and trainer satisfaction measure activity.

6. A. Holistic risk management means ESRM considers all types of security risk, so the budget properly spans physical and cyber rather than betting on one. Governance describes who decides, not what the program covers, which is why it is the trap.[3]

7. C. Transfer shifts the financial consequence of a risk to a third party, classically through insurance. The theft risk itself is unchanged — the cameras and locks that would reduce it would be mitigation — but the dollar consequence now sits with the insurer.[1]

8. A. The partnership pillar positions security professionals as trusted partners who advise asset owners, not as authoritarians who unilaterally define and enforce policy. Dictating risk acceptance to business units is the enforcer model ESRM explicitly replaces.[3]

9. C. Directing traffic on public roads is a job for the agency with authority, and NIMS expects government and the private sector to work together in response[5]. A private security team has no authority on public roads, so coordinating with local law enforcement is correct.

10. C. SLE after the control equals asset value times the new exposure factor: $1,000,000 × 0.20 = $200,000. The $700,000 figure is the pre-control loss, the trap for readers who compute the reduction but forget the question asks for the after-control figure.[2]

11. A. Security risks that cross property lines are managed through partnerships: NIMS describes government, NGOs and the private sector working together to prevent, protect against and respond to incidents[5]. The rail operator controls the adjacent risk, so it is the relationship to build first; the other providers do not address the trespass path.

12. B. SLE equals asset value times exposure factor: $200,000 × 0.40 = $80,000 per incident. ALE equals SLE times the annualized rate of occurrence: $80,000 × 0.25 = $20,000. The trap is stopping at the $80,000 single-loss figure and forgetting to annualize.[2]

Sources cited in this excerpt

  1. NIST SP 800-30 Rev. 1, Guide for Conducting Risk Assessments (2012). https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf
  2. Quantitative Security (CS 559 lecture slides, Colorado State University, Yashwant K. Malaiya; slide dated September 3, 2025). https://www.cs.colostate.edu/~cs559/slides/L4.pdf
  3. ASIS International, A Brief Guide to ESRM Implementation (2022). https://www.asisonline.org/globalassets/publications-and-resources/documents/a-brief-guide-to-esrm-implementation.pdf
  4. NIST SP 800-50 Rev. 1, Building a Cybersecurity and Privacy Learning Program (2024). https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-50r1.pdf
  5. FEMA, National Incident Management System, 3rd ed. (2017). https://www.fema.gov/sites/default/files/2020-07/fema_nims_doctrine-2017.pdf
Open the free chapter →

Before you buy

How do I get it?
Pay, and the download appears on this page straight away. The links are also emailed to you. No account is required.
What if it isn't for me?
Email us within 14 days for a full refund, no questions asked.
Is there online practice for this exam too?
No. PrepPass has no online question bank for this exam; the book is self-contained. Its chapter quizzes and full-length practice exam, each question with a worked explanation, are all in the PDF and EPUB.
Can I read it on my phone?
Yes — the EPUB is for phones and e-readers, the PDF is for printing and tabbing. You get both.

Full refund policy

The details

The seven CPP domains taught from public primary sources: 326 original questions with worked explanations and a 225-question full-length practice exam.

PrepPass team · Verified against ASIS International's CPP, PCI, PSP, and APP Certification Exams 2026 Handbook (updated 4 August 2026) · How we review
  • Format: PDF + EPUB download · 154 pages
  • 326 practice questions in the book, with a full answer key
  • $24.99 one-time — no subscription
  • 14-day money-back guarantee · refund policy
  • Cross-referenced against: ASIS International's CPP, PCI, PSP, and APP Certification Exams 2026 Handbook (updated 4 August 2026)
  • Last updated: September 2026
  • Verified from the official source(ASIS International's CPP, PCI, PSP, and APP Certification Exams 2026 Handbook (updated 4 August 2026))
  • Instant download, yours for life

What the book gives you

PrepPass has no online question bank for this exam, so the $24.99 book is complete in itself: the material taught in order, a quiz closing each chapter and a full-length practice exam, in a file you own.

  • Systematic teaching — every exam section explained chapter by chapter, start to finish, not just questions
  • Print it & tab it — a paper-ready PDF you can highlight, mark up, and bring to your study table
  • Study anywhere, offline — EPUB on your phone or e-reader; no wifi, no browser tabs
  • Everything in one place — the chapters and the practice questions in one file
  • Yours for life — one-time $24.99, instant download, no subscription

And it's risk-free: 14-day money-back guarantee — not satisfied? Email us for a full refund, no questions asked. See the refund policy.

Get the eBook — $24.99 (PDF + EPUB) ↑

14-day money-back guarantee · full refund, no questions asked.

One-time purchase, lifetime access to the download. The eBook is the full CPP — Certified Protection Professional study guide in PDF and EPUB. Educational summary, not professional or legal advice — always confirm the current rules with the official source. Last updated: September 2026.

Report