All Practice Exams

100+ Free CISAW ES Practice Questions

Prepare for the CISAW Emergency Service Direction (信息安全保障人员认证-应急服务方向) exam with instant access — no signup required.

✓ No registration✓ No credit card✓ No hidden fees✓ Start practicing immediately
100+ Questions
100% Free

Loading practice questions...

2026 Statistics

Key Facts: CISAW ES Exam

120 points

Official mixed-paper full score (84 inclusive to pass)

CISAW Emergency Service Direction exam outline (基础级/专业级)

150 min

Official sitting length, including about 60 minutes of lab

CISAW Emergency Service Direction exam outline

RMB 1,080

Exam/certification fee in the official CISAW personnel system

CISAW personnel system / authorized training notices

3 levels

基础级 / 专业级 / 专业高级 after the 基础/专业 exam plus experience

ISCCC CISAW Emergency Service Direction certification page

Art. 25

Cybersecurity Law duty to plan, activate, remediate, and report incidents

Cybersecurity Law of the PRC

PDCERF

Prepare, Detect, Contain, Eradicate, Recover, Follow-up (准备到跟踪)

CISAW 应急服务 training model

GB/T 20985

Information-security incident management standard (ISO/IEC 27035 family)

SAC / SAMR national standard

CISAW 应急服务 (ES) certifies Chinese cybersecurity emergency-response practitioners through a 150-minute, 120-point mixed exam (84 to pass) that includes about 60 minutes of lab. The same 基础/专业 exam plus experience determines Foundation, Professional, or later Professional Advanced certification. Study Cybersecurity Law incident duties, National Cybersecurity Incident Emergency Plan grades, PDCERF, kill-chain artifacts, and host/network containment. These 100 questions are an English MCQ study adaptation, not the official Chinese paper.

Sample CISAW ES Practice Questions

Try these sample questions to test your CISAW ES exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.

1Under Article 23 of the Cybersecurity Law of the PRC (网络安全法, as amended effective 1 January 2026; formerly Article 21), which multi-level protection (等保) duty is explicitly stated for network operators regarding logs?
A.Retain relevant network logs for not less than six months
B.Forward all logs to a provincial public-security bureau within 24 hours
C.Publish raw logs on a public website after each audit
D.Keep logs only while an investigation is open
Explanation: Article 23 of the amended Cybersecurity Law (in force since 1 January 2026; this was Article 21 in the 2016 text) establishes the national cybersecurity multi-level protection scheme (网络安全等级保护制度 / 等保) and requires operators to monitor and record network operation status and cybersecurity events, retaining related network logs for not less than six months (留存相关的网络日志不少于六个月). That retention floor is a standing 等保 duty, not a temporary investigation hold.
2Article 27 of the Cybersecurity Law (网络安全法, as amended effective 1 January 2026; formerly Article 25) requires a network operator, when a cybersecurity-harming incident occurs, to do which of the following?
A.Wait for a court order before touching production systems
B.Immediately activate the emergency plan, take remedial measures, and report to competent authorities as required
C.Pay a fixed administrative deposit before any containment
D.Delete all logs first so attackers cannot reuse them
Explanation: Article 27 of the amended Cybersecurity Law (Article 25 before the 2025 amendment took effect on 1 January 2026) requires operators to formulate a cybersecurity-incident emergency plan, handle vulnerabilities, viruses, attacks, and intrusions in a timely way, and, when a harming incident occurs, immediately start the plan, take corresponding remedial measures, and report to the relevant competent authorities according to the rules. Immediate activation plus reporting is the statutory sequence.
3The National Cybersecurity Incident Emergency Plan (国家网络安全事件应急预案) divides cybersecurity incidents into which four grades?
A.Red, orange, yellow, and blue only
B.Especially major (特别重大), major (重大), relatively major (较大), and general (一般)
C.Confidential, secret, internal, and public
D.P0, P1, P2, and P3 as defined by ISO 27001
Explanation: The national plan classifies incidents as 特别重大, 重大, 较大, and 一般 according to harm to national security, social order, economic construction, and public interest. CISAW 应急服务 candidates must use those official grades, especially when distinguishing 重大 from 特别重大.
4In the National Cybersecurity Incident Emergency Plan, which impact language best matches a major (重大) incident that has not reached the especially major (特别重大) grade?
A.Important networks suffer particularly severe loss, large-area paralysis, and total loss of business-processing capability
B.A single unused test VM reboots with no user impact
C.Important networks suffer severe loss, causing prolonged interruption or local paralysis, with business-processing capability greatly affected
D.A phishing email is quarantined by the gateway before delivery
Explanation: A 重大 incident involves severe system loss with prolonged interruption or local paralysis and a great impact on business-processing capability, without meeting 特别重大 criteria. 特别重大 is reserved for large-area paralysis and loss of processing capability, or a particularly serious threat to national security and social stability.
5Besides log retention, which set of duties does Cybersecurity Law Article 23 (formerly Article 21) require of network operators under 等保?
A.Only encrypting marketing emails
B.Internal security rules and a responsible person; technical measures against viruses, attacks, and intrusion; data classification plus backup and encryption of important data
C.Outsourcing all security work so the operator has no remaining duties
D.Publishing source code of every business system
Explanation: Article 23 of the amended Cybersecurity Law lists operator 等保 duties: internal management systems and a designated cybersecurity responsible person; technical measures against viruses, attacks, and intrusion; monitoring/recording plus log retention; and data classification with backup and encryption of important data, plus other duties set by law. Those duties remain with the operator even if vendors assist.
6Under the National Cybersecurity Incident Reporting Measures (国家网络安全事件报告管理办法, 2025), when a cybersecurity incident involves critical information infrastructure (关键信息基础设施), the operator should report to the protection work department and public security:
A.Within one month after the annual audit
B.Immediately, and no later than one hour
C.Only if ransom is paid
D.Only after full eradication is complete
Explanation: The 2025 measures, which implement Cybersecurity Law reporting duties, require operators discovering an incident involving CII to report to the protection work department and public security at the first opportunity, no later than one hour. Waiting for eradication or an annual audit would miss the statutory window.
7What does GB/T 20985 primarily standardize for CISAW 应急服务 practice?
A.Password length only
B.Physical lock types for server cages
C.Information-security incident management principles and incident-response planning (ISO/IEC 27035 family)
D.The four national incident color badges used on police uniforms
Explanation: GB/T 20985 is the national incident-management standard aligned with ISO/IEC 27035. Part 1 covers principles and process stages (plan/prepare, detect/report, assess/decide, respond, lessons learned); Part 2 covers planning and preparing an incident-response capability, including IRT setup. It is not the incident-grading catalogue.
8A 等保-protected production system is under active ransomware encryption. Which statement best reflects the operator's Cybersecurity Law emergency duty?
A.The operator may delay the emergency plan until a press release is approved
B.The operator must immediately start the emergency plan, take remedial measures, and report as required while preserving evidence
C.The operator must first reclassify the system to 等保 level 1 so reporting is optional
D.The operator should wipe all disks before notifying anyone
Explanation: Article 27 of the amended Cybersecurity Law requires immediate emergency-plan activation, remedial measures, and required reporting. Article 23 still requires logs and related records to be retained, so containment and recovery must be done in a way that preserves evidence rather than wiping first.
9In a typical cyber kill chain, which stage comes first?
A.Actions on objectives such as data theft
B.Command and control (C2) beaconing
C.Reconnaissance against the target environment
D.Installation of a persistent backdoor
Explanation: The kill chain begins with reconnaissance: identifying targets, exposed services, people, and weaknesses. Weaponization, delivery, exploitation, installation, C2, and actions on objectives follow. 应急服务 analysts use that order to decide which artifacts belong to early versus late stages.
10After malware is installed on a host, which kill-chain stage is primarily shown by regular outbound beacons to a rare domain?
A.Reconnaissance of public WHOIS records
B.Command and control (C2)
C.Physical destruction of backup tapes
D.Password-policy design
Explanation: Periodic outbound connections to an unusual domain or IP are classic C2 beacons: the implant checks in for tasking. 应急服务 handlers use those artifacts to identify remaining infected hosts during containment.

About the CISAW ES Exam

CISAW Emergency Service Direction (信息安全保障人员认证-应急服务方向 / ES) is the CCRC/ISCCC personnel certification for practitioners who build and operate cybersecurity emergency-response capability. The official exam is administered in Chinese as a closed-book mixed paper with a lab. This OpenExamPrep bank is an English-language MCQ study adaptation covering 应急响应 laws (网络安全法, 等保 reporting, GB/T 20985), attack-process analysis, CSIRT and PDCERF system design, network- and host-layer emergency technology, and comprehensive 应急演练. It is not an official translation and does not simulate the official lab or short-answer format.

Assessment

Closed-book 150-minute mixed paper (笔试 + 上机实验): 60 single-choice (1 point), 10 practical single-choice (4 points), 2 short-answer (10 points). After the lab portion, candidates close the computer and continue the written items. Passing score is 84/120.

Time Limit

150 minutes (including about 60 minutes of lab)

Passing Score

84 out of 120 (70%)

Exam Fee

RMB 1,080 exam/certification fee via the official CISAW personnel system; authorized training commonly RMB 6,800 (China Cybersecurity Review Certification and Market Regulation Big Data Center (CCRC / ISCCC))

CISAW ES Exam Content Outline

8%

Emergency-response laws and regulations (应急响应法律法规)

Cybersecurity Law Article 23 MLPS (等保) duties and log retention, Article 27 emergency plans and reporting (Articles 21 and 25 before the 2025 amendment took effect on 1 January 2026), National Cybersecurity Incident Emergency Plan classification (particularly 重大 and 特别重大), GB/T 20985 incident management, and MLPS-related reporting.

25%

Cybercrime and attack-process analysis (网络犯罪与攻击过程分析)

Kill chain and intrusion stages, malware families, SQL injection / XSS / CSRF, and the log artifacts used to reconstruct attacker actions.

27%

Emergency-response system establishment (应急响应体系建立)

CSIRT roles, PDCERF (准备/检测/抑制/根除/恢复/跟踪), playbooks, escalation, communications, and drill programs.

12%

Network-layer emergency technology (网络层应急技术)

Packet and flow analysis, firewall/ACL isolation, DNS controls, and DDoS identification and mitigation.

20%

Host-layer emergency technology (主机层应急技术)

Windows 4624/4625 and Linux auth.log analysis, process and malware triage, persistence, and forensic preservation.

8%

Comprehensive emergency drills (综合应急演练)

Tabletop through full-scale 应急演练, inject design, after-action review, and corrective-action tracking.

How to Pass the CISAW ES Exam

What You Need to Know

  • Passing score: 84 out of 120 (70%)
  • Assessment: Closed-book 150-minute mixed paper (笔试 + 上机实验): 60 single-choice (1 point), 10 practical single-choice (4 points), 2 short-answer (10 points). After the lab portion, candidates close the computer and continue the written items. Passing score is 84/120.
  • Time limit: 150 minutes (including about 60 minutes of lab)
  • Exam fee: RMB 1,080 exam/certification fee via the official CISAW personnel system; authorized training commonly RMB 6,800

Keys to Passing

  • Work through all 100 available questions
  • Review every answer and explanation
  • Track weak areas and revisit them
  • Use our AI tutor for tough concepts

CISAW ES Study Tips from Top Performers

1Memorize Cybersecurity Law Article 23 (国家实行网络安全等级保护制度 / 等保) operator duties, especially log retention of not less than six months, and Article 27 (emergency plan, immediate activation, remedial measures, and reporting to competent authorities) — these were Articles 21 and 25 before the 2025 amendment took effect on 1 January 2026, so check which numbering your study materials use.
2Drill National Cybersecurity Incident Emergency Plan grades: 特别重大 (especially major: large-area paralysis and loss of business-processing capability), 重大 (major: prolonged interruption or local paralysis with severe business impact), 较大, and 一般. Classify from impact language, not from a guessed article number.
3Treat PDCERF as the CISAW 应急服务 handling model: 准备 (Prepare), 检测 (Detect), 抑制 (Contain), 根除 (Eradicate), 恢复 (Recover), 跟踪 (Follow-up). Containment stops spread; eradication removes the cause; recovery restores service; follow-up captures lessons and hardening.
4Do not confuse GB/T 20985 (information-security incident management, aligned with ISO/IEC 27035) with GB/T 20986 (incident classification and grading). 20985 is process/management; classification grades live in the national emergency plan and related grading guides.
5Practice log reading as if it were the lab: Windows 4624 (successful logon) vs 4625 (failed logon), Linux auth.log/secure failed-password bursts, web-access patterns for SQLi/XSS/webshells, and DNS or firewall artifacts for C2 and DDoS.
6In drills and playbooks, write measurable triggers (who declares the incident, when to isolate, when to notify leadership or public security) and force an after-action register with owners and due dates—CISAW 应急服务 weights system establishment and comprehensive drills together at 35%.

Frequently Asked Questions

What is CISAW Emergency Service Direction (信息安全保障人员认证-应急服务方向)?

It is the CISAW 应急服务 (ES) personnel certification administered by the China Cybersecurity Review Certification and Market Regulation Big Data Center (CCRC / ISCCC). It evaluates emergency-management system building, playbook and drill capability, incident analysis, and incident handling for network emergencies.

How does this OpenExamPrep question bank relate to the official Chinese exam?

The official exam is sat in Chinese as a closed-book mixed paper with single-choice items, practical lab single-choice items, and short-answer questions, including about 60 minutes of computer lab. This 100-question bank is an English-language MCQ study adaptation. It is not an official translation, not a past paper, and not a simulation of the lab or short-answer format.

What is the official format, time limit, and passing score?

Authorized CISAW Emergency Service outlines describe 150 minutes, 120 points, and a passing score of 84. The mix is 60 single-choice items (1 point), 10 practical single-choice items (4 points), and 2 short-answer items (10 points), with about 60 minutes of lab included in the sitting.

How do Foundation, Professional, and Professional Advanced levels work?

Candidates take the same 基础/专业 Emergency Service exam. After passing, ISCCC awards 基础级 or 专业级 based on education and 应急服务 experience. 专业高级 requires a Professional-level certificate plus a separate advanced assessment.

What does the exam cost, and where do I register?

The exam/certification fee is RMB 1,080 through https://ryrzcisaw.isccc.gov.cn/. Authorized training is commonly listed at RMB 6,800 in CACE-style notices. Confirm current fees, sitting dates, and any training expectations in the official system.

What Chinese terms should I keep while studying in English?

Keep 应急服务, 网络安全法, 等保, PDCERF (准备/检测/抑制/根除/恢复/跟踪), 特别重大/重大/较大/一般事件, CSIRT, and GB/T 20985. Official terminology is Chinese; English here is a study aid only.