EXIN AISP Study Plan: Threats, Controls and Evidence
Build an AISP preparation routine around EXIN’s weighted domains, the required OWASP reading, focused IT Mastery practice and careful review of mistakes.
Start with one mixed attempt
Use IT Mastery to answer a mixed set without opening explanations first. For a fixed paper-style attempt, use the 40-question free exam . Mark both mistakes and correct guesses. Record whether each gap concerns an unfamiliar concept, a misread exhibit or a control that does not address the stated threat.
Read the EXIN preparation guide before planning your sessions. Work from its required-reading list rather than trying to memorize every page of the changing live OWASP site.
Organize the next six sessions
| Session | Focus | Evidence that you can move on |
|---|---|---|
| 1 | Organization, GUARD and threat modeling | You can identify the responsible owner, sensitive asset, attacker capability and relevant trust boundary. |
| 2 | Input threats | You can distinguish direct/indirect injection, evasion, memorization, inversion, membership inference and extraction. |
| 3 | Development and runtime threats | You can tell whether the evidence concerns training examples, model artifacts, retrieval content or ordinary application authorization. |
| 4 | Security controls | You can explain what each control enforces, what it merely signals and which exposure remains. |
| 5 | Security testing, privacy and compliance | You can set safe test scope, interpret bounded results and identify the relevant data and organizational roles. |
| 6 | Mixed timed practice and review | You can justify the best answer and reject the closest alternative using facts in the scenario. |
These are sessions, not compulsory consecutive days. Give threats and controls most of your study time: together they account for 65% of the official outline. Adjust effort using your mistakes while still revisiting the smaller domains.
Review each missed or guessed answer
Write three short notes:
- Evidence: Which fact determines the answer?
- Boundary: Which tempting alternative confuses the asset, lifecycle stage, authority or scope?
- Next check: Which official reading section or fresh practice set will help you test the distinction?
For a code or log question, trace the inputs and identities before reading the choices. Do not assume a parameter is authorized merely because it is correctly formatted. For governance questions, distinguish an assigned owner, a signed acceptance and evidence that a control works.
Finish with a fresh timed attempt
Allow 90 minutes for 40 questions. Check your pace without using the official 65% threshold as a promise of readiness. Repeating the same static set immediately can measure answer memory. Use new app questions, revisit weak topics and practise explaining the rejected alternatives.
Keep the cheat sheet for a final recall pass, then confirm booking and candidate requirements through EXIN .