All Practice Exams

100+ Free CISAW Risk Management Practice Questions

Prepare for the CISAW Risk Management Direction (信息安全保障人员认证-风险管理方向) exam with instant access — no signup required.

✓ No registration✓ No credit card✓ No hidden fees✓ Start practicing immediately
100+ Questions
100% Free

Loading practice questions...

2026 Statistics

Key Facts: CISAW Risk Management Exam

150 min

Official CISAW Risk Management sitting length

Authorized CISAW Risk Management outlines / CCRC CISAW examination notices

120 points

Full mark of the official mixed Chinese paper

Authorized CISAW Risk Management outlines

84 points

Inclusive pass mark (cheating scored as 0)

Authorized CISAW Risk Management outlines

RMB 1,080

Official certification/exam fee in the CCRC personnel-certification system

CCRC CISAW registration practice and authorized training notices

RMB 6,800

Common authorized training fee charged separately from the official exam fee

Authorized CISAW training providers

风险管理

Official CCRC-COP-C01:2023 Appendix A technical direction name (RM); historically also 风险评估

CCRC-COP-C01:2023 Appendix A

GB/T 20984

China national method for information security risk assessment used with ISO 31000 and ISO/IEC 27005

SAC / TC260 national standards programme

English MCQ adaptation

This practice bank is not an official Chinese mixed-paper simulation

OpenExamPrep practice-language policy

CISAW Risk Management (风险管理方向, historically 风险评估) is CCRC/ISCCC's ISO/IEC 17024 personnel certification for information-security 风险管理. The official Chinese paper is 150 minutes, 120 points, pass 84. Pay RMB 1,080 in the official system; authorized training is commonly RMB 6,800. Study ISO 31000, ISO/IEC 27005, GB/T 20984, asset-threat-vulnerability identification, SLE/ALE and matrix/multiplication calculation, treatment/acceptance, and 等保. These 100 English MCQs are a study adaptation, not the official mixed paper.

Sample CISAW Risk Management Practice Questions

Try these sample questions to test your CISAW Risk Management exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.

1Under the current CCRC Information Security Assurance Personnel Certification Criteria (CCRC-COP-C01:2023), what is the official technical-direction name of the CISAW credential historically also called 风险评估?
A.安全运维 (Security Operations)
B.安全集成 (Security Integration)
C.应急服务 (Emergency Service)
D.风险管理 (RM / Risk Management)
Explanation: CCRC's certification criteria (CCRC-COP-C01:2023) and CCRC-authorized direction listings name this CISAW technical direction 风险管理 (RM / Risk Management). Training materials still use 风险评估 as a historical label for the same direction, which is why OpenExamPrep keeps the exam ID cn-cisaw-risk-assessment.
2According to ISO 31000, what is the purpose of 风险管理 (risk management)?
A.To eliminate every residual vulnerability before an information system may operate
B.To produce a one-time audit report that replaces monitoring
C.To assign criminal liability for every identified threat actor
D.The creation and protection of value by managing the effect of uncertainty on objectives
Explanation: ISO 31000 states that the purpose of risk management is the creation and protection of value. It improves performance and supports objectives by addressing the effect of uncertainty, not by promising zero residual risk.
3Which definition of risk is consistent with ISO 31000 and CISAW 风险管理 teaching?
A.Any vulnerability found by a scanner, regardless of threat or asset value
B.The total replacement cost of hardware in the assessment scope
C.The effect of uncertainty on objectives
D.A mandatory 等保 level assigned to every public website
Explanation: ISO 31000 defines risk as the effect of uncertainty on objectives. Information-security risk is that effect expressed through assets, threats, vulnerabilities, and consequences for confidentiality, integrity, and availability.
4Which item is an ISO 31000:2018 principle of effective 风险管理?
A.Risk management is performed only by an external auditor after an incident
B.Risk management is limited to insurable financial loss
C.Risk management is integrated into all organizational activities
D.Risk management requires a single global likelihood table for every sector
Explanation: ISO 31000:2018 principles include integrated, structured and comprehensive, customized, inclusive, dynamic, best available information, human and cultural factors, and continual improvement. Integration means 风险管理 is part of ordinary activities, not a disconnected annual ritual.
5In the ISO 31000 process, which group of activities constitutes risk assessment?
A.Insurance placement, outsourcing, and contract transfer only
B.Leadership commitment, framework design, and framework evaluation only
C.Incident forensics, malware reverse engineering, and patch deployment only
D.Risk identification, risk analysis, and risk evaluation
Explanation: ISO 31000 risk assessment is the combination of identification, analysis, and evaluation. Treatment, communication and consultation, monitoring and review, and recording and reporting are related process elements but are not the assessment trio.
6What is the role of ISO/IEC 27005 in CISAW 风险管理 study?
A.It is the China classified-protection (等保) baseline catalog replacing GB/T 22239
B.It provides guidelines for information security risk management in support of an ISMS aligned with ISO/IEC 27001
C.It is a product Common Criteria evaluation methodology
D.It publishes the official CISAW multiple-choice item count
Explanation: ISO/IEC 27005 gives guidelines for information security risk management and supports ISO/IEC 27001 ISMS implementation. CISAW RM candidates are expected to understand how it sits beside ISO 31000 and GB/T 20984.
7How should a CISAW candidate describe the relationship among ISO 31000, ISO/IEC 27005, and ISO/IEC 27001?
A.ISO 31000 is generic 风险管理 guidance; ISO/IEC 27005 applies that thinking to information security in support of ISO/IEC 27001
B.ISO/IEC 27001 replaces ISO 31000, so 27005 is obsolete
C.The three documents are identical word-for-word translations of GB/T 20984
D.ISO 31000 is only for safety engineering and must not be cited in information-security work
Explanation: ISO 31000 is generic risk-management guidance. ISO/IEC 27005 specializes it for information security and is used to support ISO/IEC 27001 ISMS risk processes. They are complementary, not substitutes for GB/T 20984 in a China assessment project.
8What is GB/T 20984 in the CISAW 风险管理 outline?
A.The Cybersecurity Law implementing regulation for personal-information fines
B.A CCRC fee schedule for certificate reprinting
C.The exclusive catalog of 等保 Level 5 control points
D.The China national standard method for information security risk assessment (信息安全风险评估)
Explanation: GB/T 20984 is the national standard for information security risk assessment method (信息安全技术 信息安全风险评估方法 in the 2022 edition). CISAW RM treats it as a core China assessment standard alongside ISO 31000 and ISO/IEC 27005.
9GB/T 20984-2022 organizes information security risk assessment into which four stages?
A.Procurement, coding, penetration testing, and certificate printing
B.Assessment preparation, risk identification, risk analysis, and risk evaluation
C.Insurance, outsourcing, litigation, and write-off
D.Detection, containment, eradication, and recovery only
Explanation: GB/T 20984-2022 structures the method as 评估准备, 风险识别, 风险分析, and 风险评价. Identification includes assets, threats, existing measures, and vulnerabilities. Treatment remains part of the wider 风险管理 cycle even though the 2022 method text focuses the four assessment stages.
10What is the primary role of GB/T 31509 relative to GB/T 20984?
A.It replaces ISO 31000 for all Chinese listed companies
B.It is the criminal code chapter on network intrusion
C.It sets the official CISAW pass mark of 84 points
D.It is the implementation guide for organizing, executing, and accepting information security risk-assessment projects
Explanation: GB/T 31509 (信息安全技术 信息安全风险评估实施指南) guides how to implement a GB/T 20984-style assessment project, including organization, stages, and acceptance. It is a companion implementation guide, not a criminal statute or an exam-fee rule.

About the CISAW Risk Management Exam

The CISAW Risk Management Direction (信息安全保障人员认证-风险管理方向) is the CCRC / ISCCC personnel certification for practitioners who identify, analyze, evaluate, treat, and monitor information-security risk. CCRC-COP-C01:2023 Appendix A lists the official technical direction name as 风险管理 (RM); the direction is historically also called 风险评估. The official 150-minute Chinese paper is scored out of 120 points with a pass mark of 84. This OpenExamPrep set is an English-language MCQ study adaptation of the authorized outline (ISO 31000, ISO/IEC 27005, GB/T 20984, GB/T 31509, calculation, treatment, and 等保 context), not an official translation or a mixed-format simulation.

Assessment

Closed-book 150-minute sitting under CCRC CISAW personnel-certification rules. Authorized outline topics include ISO 31000, ISO/IEC 27005, GB/T 20984, GB/T 31509, asset/threat/vulnerability/control identification, risk analysis and calculation (矩阵法 and 相乘法), evaluation, treatment, acceptance, communication, and monitoring, plus China 等保 and cybersecurity-law context. Foundation-level (基础级) and professional-level (专业级) certificates use the same direction paper with different experience criteria.

Time Limit

150 minutes

Passing Score

84 out of 120 points (inclusive)

Exam Fee

RMB 1,080 official certification/exam fee (authorized training commonly RMB 6,800 separately) (China Cybersecurity Review, Certification and Market Regulation Big Data Center (CCRC / 中国网络安全审查认证和市场监管大数据中心; historically ISCCC))

CISAW Risk Management Exam Content Outline

27%

Risk Management Concepts and Standards (风险管理基本概念)

Information security, 风险管理, information security risk, information security risk management and assessment, standardization bodies, ISO 31000, ISO/IEC 27005, and GB/T 20984.

5%

Project Preparation and Context Establishment (项目管理基础和环境建立)

Project-management basics, assessment context, scope, stakeholders, risk criteria, and environment-establishment process and outputs.

43%

Risk Identification (风险识别)

Business and strategy identification; asset identification and CIA assignment; threat identification; physical, network, system-software, middleware, application, and management vulnerability identification; and identification of existing controls (已有安全措施).

9%

Risk Analysis and Calculation (风险分析与计算)

Likelihood and loss analysis, risk-element association, matrix method (矩阵法), multiplication method (相乘法), SLE = AV × EF, ALE = SLE × ARO, and residual-risk calculation.

5%

Risk Evaluation and Assessment Outputs (风险评价和评估输出)

Risk-evaluation criteria and process, risk ranking against organizational appetite, and assessment documentation including the risk-assessment report.

11%

Risk Treatment, Acceptance, Communication, and Monitoring (风险处置、接受、沟通与监视)

Treatment options and plans, residual risk and informed acceptance, communication and consultation, monitoring and review, and China 等保 / legal context for 风险管理.

How to Pass the CISAW Risk Management Exam

What You Need to Know

  • Passing score: 84 out of 120 points (inclusive)
  • Assessment: Closed-book 150-minute sitting under CCRC CISAW personnel-certification rules. Authorized outline topics include ISO 31000, ISO/IEC 27005, GB/T 20984, GB/T 31509, asset/threat/vulnerability/control identification, risk analysis and calculation (矩阵法 and 相乘法), evaluation, treatment, acceptance, communication, and monitoring, plus China 等保 and cybersecurity-law context. Foundation-level (基础级) and professional-level (专业级) certificates use the same direction paper with different experience criteria.
  • Time limit: 150 minutes
  • Exam fee: RMB 1,080 official certification/exam fee (authorized training commonly RMB 6,800 separately)

Keys to Passing

  • Work through all 100 available questions
  • Review every answer and explanation
  • Track weak areas and revisit them
  • Use our AI tutor for tough concepts

CISAW Risk Management Study Tips from Top Performers

1Memorize the GB/T 20984 relationship Risk = R(L(T, V), F(Ia, Va)): likelihood from threat and vulnerability exploitability, loss from asset value and vulnerability impact, then combine with 矩阵法 or 相乘法.
2Drill genuine calculation items: SLE = AV × EF, ALE = SLE × ARO, residual ALE after a control changes EF or ARO, and simple 5×5 scores only when the stem states the scoring rule. Do not memorize unpublished GB/T lookup tables.
3Keep ISO 31000 (principles, framework, process), ISO/IEC 27005 (information-security risk management supporting ISO/IEC 27001), GB/T 20984 (assessment method), and GB/T 31509 (implementation guide) distinct. Do not blend them into one invented framework.
4In identification, always pair assets, threats, vulnerabilities, and existing controls (已有安全措施). GB/T 20984-2022 treats business, system, and component/unit assets as a hierarchy rather than a flat hardware list.
5Treatment is avoid, share/transfer, reduce/modify, or retain/accept with an informed owner decision. Residual risk that still exceeds criteria is not automatically accepted.
6For 等保 and China law questions, stay conceptual: classified protection (等级保护) is a statutory cybersecurity scheme distinct from a GB/T 20984 project, and do not invent statute article numbers.

Frequently Asked Questions

What is the official name of this CISAW direction?

CCRC-COP-C01:2023 Appendix A names the technical direction 风险管理 (RM), in English Risk Management. The same direction is historically also called 风险评估 (risk assessment). OpenExamPrep keeps the exam ID cn-cisaw-risk-assessment for URL stability.

Who administers CISAW and in what language is the official exam delivered?

The China Cybersecurity Review, Certification and Market Regulation Big Data Center (CCRC), historically the China Information Security Certification Center (ISCCC), administers CISAW under ISO/IEC 17024. The official assessment is in Chinese (zh). This practice bank is an English-language MCQ study adaptation, not an official English sitting.

What are the time limit, score, fee, and training cost?

The sitting is 150 minutes, 120 points, with 84 points (inclusive) to pass. The official exam/certification fee in the CCRC system is RMB 1,080. Authorized training is commonly RMB 6,800 and is paid to the training provider, not as a substitute for the official fee.

What topics does the authorized Risk Management outline cover?

ISO 31000, ISO/IEC 27005, GB/T 20984 information security risk assessment, GB/T 31509 implementation guidance, asset/threat/vulnerability identification, existing controls, risk analysis and calculation (including 矩阵法 and 相乘法), evaluation, treatment, acceptance, communication, and monitoring, used together with China 等保 and cybersecurity-law context.

How does this OpenExamPrep question bank relate to the official Chinese exam?

The official paper is a mixed Chinese assessment with single-choice, multiple-choice, short-answer, calculation, and comprehensive items as commonly reported by authorized trainers. This 100-question OpenExamPrep bank is an English-language MCQ study adaptation. It is not an official translation, not a CCRC item bank, and not a simulation of the unpublished exact item mix.