100+ Free CISAW-LPT Practice Questions
Prepare for the CISAW Penetration Testing Direction — LPT (信息安全保障人员认证-渗透测试方向) exam with instant access — no signup required.
Loading practice questions...
Explore More China CISAW Information Security Assurance Workforce Certifications (信息安全保障人员认证)
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
Key Facts: CISAW-LPT Exam
84/120
Official passing score
CISAW 120-point paper (CCRC/ISCCC)
150 min
Typical CISAW written sitting
CISAW sitting logistics
RMB 1,080
Exam/certification fee
CACE 19 March 2025 CISAW-LPT notice; ryrzcisaw.isccc.gov.cn
RMB 8,800
Authorized training fee
CACE 19 March 2025 CISAW-LPT notice
3 years
Typical certificate validity
CISAW personnel certification practice
CISAW-LPT is CCRC/ISCCC’s penetration-testing personnel credential. The official sitting is mixed written and practical, 120 points, 84 to pass, typically 150 minutes for the written CISAW paper plus practical tasks. CACE’s 2025 notice lists RMB 8,800 training and RMB 1,080 exam/certification via ryrzcisaw.isccc.gov.cn. This free 2026 English MCQ bank trains recognition, sequencing, legal scope, and mitigation — never exploit payloads.
Sample CISAW-LPT Practice Questions
Try these sample questions to test your CISAW-LPT exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.
1A web application builds SQL statements by concatenating unsanitized user input into the query string. Which control most reliably prevents SQL injection?
2A comment field stores visitor input and later renders it in every user's browser without encoding. Which XSS class is this?
3Which control best prevents CSRF on a cookie-authenticated form that changes account email?
4User A changes the account-id parameter in a profile URL and receives User B's personal data. What access-control failure is this?
5An application fetches a user-supplied URL on the server to generate a link preview. Which mitigation best reduces SSRF risk?
6A feature accepts a URL, the server retrieves it, and the HTTP response body is shown only to the requesting user. Testers observe that supplying an internal hostname returns an internal error page. Which issue is indicated?
7Which file-upload design most reduces the chance that an uploaded file is later executed as code?
8A session cookie is sent over HTTPS. Which cookie flag tells the browser not to include that cookie on cleartext HTTP requests?
9Why should an authentication cookie set the HttpOnly flag?
10Which SameSite cookie setting most strictly prevents the browser from sending the cookie on cross-site requests?
About the CISAW-LPT Exam
CISAW Penetration Testing Direction (CISAW-LPT, 信息安全保障人员认证-渗透测试方向) is a CCRC/ISCCC personnel certification under ISO/IEC 17024. It evaluates whether a practitioner can plan and perform authorized tests of networks and applications, recognize common web, middleware, and OS weaknesses, and report remediation without causing unlawful intrusion. The official exam is a Chinese mixed written and practical assessment on a 120-point paper with a passing score of 84; typical written time is 150 minutes. Authorized CACE training in the 19 March 2025 notice is RMB 8,800 plus RMB 1,080 exam/certification paid at ryrzcisaw.isccc.gov.cn. This question bank is a free English-language MCQ study adaptation for 2026. It is not an official CCRC translation, not a dump of exam items, and not permission to test any system.
Assessment
Mixed written paper (objective and constructed-response items in Chinese) plus practical/performance tasks covering authorized reconnaissance, vulnerability recognition, safe validation, and reporting. CCRC published an updated CISAW penetration-testing outline effective 1 September 2026; always follow the current notice in the personnel system.
Time Limit
150 minutes typical CISAW sitting, with an additional practical/performance component for LPT as published in the exam notice
Passing Score
84 out of 120
Exam Fee
RMB 1,080 exam/certification fee via ryrzcisaw.isccc.gov.cn (CACE 2025 notice); authorized training RMB 8,800 (China Cybersecurity Review, Certification and Market Regulation Big Data Center (CCRC / ISCCC / 中国网络安全审查认证和市场监管大数据中心))
CISAW-LPT Exam Content Outline
Web Application Security
SQL injection, XSS, CSRF, SSRF, file upload and include, access control, session management, HTTP semantics, and cookie flags, with emphasis on detection cues and mitigations rather than exploits.
Methodology, Reporting, Ethics and Law
PTES-like stages, rules of engagement, written authorization, report structure, CVSS v3.1 qualitative ratings, evidence handling, and PRC Cybersecurity Law limits on unauthorized intrusion and hacking tools.
Reconnaissance and Scanning
Passive OSINT, DNS and WHOIS, host discovery, Nmap scan-type recognition, CIDR host-count calculations, and service fingerprinting on authorized targets only.
Operating Systems and Middleware
Linux and Windows least-privilege hardening, Apache, Nginx, IIS, Tomcat, and WebLogic exposure, default credentials, and patching of management consoles.
Exploitation Concepts and Post-Exploitation Safety
In-scope confirmation, safe validation, no out-of-scope pivoting, production-impact limits, cleanup, and stopping when unexpected personal data appears.
How to Pass the CISAW-LPT Exam
What You Need to Know
- Passing score: 84 out of 120
- Assessment: Mixed written paper (objective and constructed-response items in Chinese) plus practical/performance tasks covering authorized reconnaissance, vulnerability recognition, safe validation, and reporting. CCRC published an updated CISAW penetration-testing outline effective 1 September 2026; always follow the current notice in the personnel system.
- Time limit: 150 minutes typical CISAW sitting, with an additional practical/performance component for LPT as published in the exam notice
- Exam fee: RMB 1,080 exam/certification fee via ryrzcisaw.isccc.gov.cn (CACE 2025 notice); authorized training RMB 8,800
Keys to Passing
- Work through all 100 available questions
- Review every answer and explanation
- Track weak areas and revisit them
- Use our AI tutor for tough concepts
CISAW-LPT Study Tips from Top Performers
Frequently Asked Questions
What is CISAW-LPT?
CISAW-LPT is the penetration-testing direction of China’s Information Security Assurance Workforce certification (信息安全保障人员认证-渗透测试方向), issued by CCRC/ISCCC. It certifies authorized testing knowledge and skill for networks and applications, not a license to attack systems without written permission.
What is the official exam format and passing score?
CISAW uses a 120-point mixed assessment with a passing score of 84. Typical written sitting time is 150 minutes. CISAW-LPT also includes practical/performance tasks. Exact item mix is published in the current CCRC outline and exam notice, not as a single public MCQ count.
Does this OpenExamPrep bank replace the official Chinese exam?
No. Official delivery is in Chinese and mixes written and practical work. This bank is a free 2026 English-language MCQ study adaptation for concept recognition, legal/scope judgment, sequencing, and mitigation. It is not an official translation and does not simulate the practical range.
What fees apply?
The CACE CISAW-LPT notice dated 19 March 2025 lists training at RMB 8,800 per person and the exam/certification fee at RMB 1,080 per person, paid to the exam body through https://ryrzcisaw.isccc.gov.cn. Confirm any later fee change in that system before you register.
Is unauthorized penetration testing legal in China?
No. The PRC Cybersecurity Law prohibits illegally intruding into another party’s network, disrupting normal network functions, stealing network data, and providing tools or assistance for those acts. CISAW-LPT work requires documented authorization and a defined scope.
How long is the certificate valid?
CISAW certificates are typically valid for three years. Holders generally complete published continuing-education hours (commonly 16 hours) in the CCRC personnel system before expiry and then apply for recertification. Always follow the current system instructions.