SAPPC
Certification
Study Guide
One hundred examination-style questions
with complete solutions covering threat and
risk management, information security,
personnel security, physical security,
industrial security, and program security
integration.
100 Questions | With Complete Solutions
Security Asset Protection Professional Certification · Aligned with the CDSE
SPeD SAPPC Exam Blueprint and DoD Security Policies
EDITION
,SAPPC Certification Study Guide | 100 Questions with Complete Solutions
Section 1: General Security & Threat/Risk Management
Questions 1 - 20
Q1. A security manager is establishing a protection program for a newly accredited research facility.
Following the DoD risk management framework, which action should be taken FIRST?
A. Conduct a vulnerability assessment of the facility perimeter
B. Identify and prioritize the assets that require protection [CORRECT]
C. Install layered countermeasures at all access points
D. Draft the installation security standard operating procedures
Correct Answer: B
Rationale: Risk management always begins with identifying and valuing assets, because asset value drives every
later decision under the DoDI 5200.08 risk framework. Threats, vulnerabilities, and risk are all assessed relative to
specific assets, and countermeasures are selected only after risk is understood. Installing controls first, as in option
C, may protect low-value items while leaving critical assets exposed, and procedures (option D) cannot be written
before the protection requirements are known.
Q2. Which expression correctly describes how overall risk is determined in the DoD risk management
model?
A. Risk = f(Asset Value x Threat x Vulnerability) [CORRECT]
B. Risk = Threat x Countermeasure Effectiveness
C. Risk = Vulnerability divided by Asset Value
D. Risk = Threat + Countermeasure Cost
Correct Answer: A
Rationale: Per the DoD security risk management model taught in CDSE SPeD curricula and reflected in DoDI
5200.08, risk is a function of asset value, threat, and vulnerability. Countermeasures are applied only after risk is
determined, so options involving countermeasures measure residual risk rather than define it. Dividing or adding
unrelated variables has no basis in the DoD model and produces meaningless results.
Q3. A defense contractor determines that a planned data-processing capability cannot be adequately
protected against a newly identified foreign intelligence technique, and leadership decides to discontinue that
capability entirely. Which risk management strategy is being applied?
A. Risk avoidance [CORRECT]
B. Risk transfer
C. Risk mitigation
D. Risk acceptance
Correct Answer: A
2026/2027 Edition · Aligned with CDSE SPeD SAPPC Exam Blueprint 1
,SAPPC Certification Study Guide | 100 Questions with Complete Solutions
Rationale: Risk avoidance means eliminating the activity, asset, or capability that generates the risk, which is
exactly what discontinuing the capability accomplishes. Risk acceptance (option D) would mean continuing the
activity while formally acknowledging residual risk, and mitigation (option C) would mean applying
countermeasures to reduce the risk. Transfer (option B) shifts consequences to another party, such as through
insurance, and does not eliminate the activity.
Q4. During a professional conference, an employee is approached by a foreign national who asks unusually
detailed questions about the company's radar program and later offers to pay consulting fees for 'general
technical opinions.' What should the employee do?
A. Continue the conversation to determine the visitor's intent before taking action
B. Decline to answer and mention the encounter only if the person makes contact again
C. Report the contact immediately to the security office or Facility Security Officer
[CORRECT]
D. Post a warning about the individual on the company intranet
Correct Answer: C
Rationale: Under SEAD-3 and NISPOM reporting requirements, cleared personnel must report suspicious
contacts or solicitations for protected information promptly to their security office or FSO, who forwards the
report through required channels. Waiting to see if contact recurs (option B) or probing intent (option A) delays
counterintelligence awareness and may allow targeting to succeed. Publicly posting about the encounter (option D)
is not an authorized reporting method and could itself expose program information.
Q5. Which combination of behaviors presents the most significant insider threat concern requiring
evaluation and possible reporting?
A. An employee who occasionally arrives early and reads approved industry newsletters at her desk
B. An employee with unexplained foreign travel, gambling-related debt, and requests for access
to files unrelated to his assigned duties [CORRECT]
C. An employee who asks a coworker to cover a shift and often eats lunch alone
D. An employee who occasionally complains about management in break-room conversations
Correct Answer: B
Rationale: CDSE insider threat guidance identifies unreported foreign travel and contacts, unexplained affluence
or financial distress, and requesting or accessing information beyond need-to-know as classic detectable warning
behaviors. Each item in option B is individually reportable under SEAD-3, and together they indicate potential
vulnerability to foreign intelligence targeting. The behaviors in options A, C, and D are ordinary workplace
activities without a security nexus and do not by themselves constitute insider threat indicators.
Q6. Under SEAD-3, the national reporting requirement obligates personnel with security clearances to do
what?
A. Report activities or contacts that could indicate a potential insider threat or risk to national
security [CORRECT]
B. Submit a new personnel security questionnaire once every five years
C. Obtain written approval before attending any professional conference
D. Report only confirmed acts of espionage witnessed firsthand
2026/2027 Edition · Aligned with CDSE SPeD SAPPC Exam Blueprint 2
, SAPPC Certification Study Guide | 100 Questions with Complete Solutions
Correct Answer: A
Rationale: SEAD-3 established uniform national reporting requirements obligating cleared personnel to
self-report and to report observed behaviors such as foreign contacts, unauthorized disclosure, security violations,
and other activities that raise insider threat concerns. Options B and C invent requirements that do not exist under
SEAD-3. Restricting reporting to confirmed espionage (option D) defeats the purpose of the requirement, which is
early warning based on observable indicators, not conclusive proof.
Q7. A facility threat assessment team is cataloging the events that could harm its program. Which of the
following is a NON-adversarial threat?
A. A foreign intelligence entity attempting to recruit a cleared employee
B. A insider deliberately copying controlled unclassified information to a personal device
C. An untrained employee accidentally mailing sensitive material to the wrong address
[CORRECT]
D. A hacker group conducting a targeted spear-phishing campaign against the program
Correct Answer: C
Rationale: Non-adversarial threats arise from human error, negligence, or natural events rather than hostile intent,
and accidental misdirected mail is the textbook example. The foreign intelligence entity in option A is the defining
adversarial threat discussed throughout CDSE materials, while deliberate insider actions (option B) and criminal
hackers (option D) are adversarial because intent to cause harm is present. Correctly separating adversarial from
non-adversarial threats is essential because the corresponding countermeasures differ, with training and procedures
addressing error and counterintelligence and cybersecurity addressing hostile actors.
Q8. During a vulnerability assessment, a security manager discovers that a side door to a classified storage
area can be opened without a badge or key during shift changes. In risk management terms, this finding is
best described as a(n):
A. Threat to the classified storage area
B. Vulnerability in the facility's protection system [CORRECT]
C. Overall risk level for the installation
D. Countermeasure requiring immediate funding
Correct Answer: B
Rationale: A vulnerability is a weakness or gap in protections that an adversary could exploit, and an uncontrolled
door is precisely such a gap identified through vulnerability assessment per the DoD risk management process. The
threat (option A) is the adversary who might exploit the door, not the door itself, and risk (option C) is the
calculated likelihood and impact of that exploitation. A discovered weakness becomes a countermeasure candidate
only after risk is evaluated, so option D skips required analytic steps.
2026/2027 Edition · Aligned with CDSE SPeD SAPPC Exam Blueprint 3