100+ Free CISAW Risk Management Practice Questions
Prepare for the CISAW Risk Management Direction (信息安全保障人员认证-风险管理方向) exam with instant access — no signup required.
Loading practice questions...
Explore More China CISAW Information Security Assurance Workforce Certifications (信息安全保障人员认证)
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
Key Facts: CISAW Risk Management Exam
150 min
Official CISAW Risk Management sitting length
Authorized CISAW Risk Management outlines / CCRC CISAW examination notices
120 points
Full mark of the official mixed Chinese paper
Authorized CISAW Risk Management outlines
84 points
Inclusive pass mark (cheating scored as 0)
Authorized CISAW Risk Management outlines
RMB 1,080
Official certification/exam fee in the CCRC personnel-certification system
CCRC CISAW registration practice and authorized training notices
RMB 6,800
Common authorized training fee charged separately from the official exam fee
Authorized CISAW training providers
风险管理
Official CCRC-COP-C01:2023 Appendix A technical direction name (RM); historically also 风险评估
CCRC-COP-C01:2023 Appendix A
GB/T 20984
China national method for information security risk assessment used with ISO 31000 and ISO/IEC 27005
SAC / TC260 national standards programme
English MCQ adaptation
This practice bank is not an official Chinese mixed-paper simulation
OpenExamPrep practice-language policy
CISAW Risk Management (风险管理方向, historically 风险评估) is CCRC/ISCCC's ISO/IEC 17024 personnel certification for information-security 风险管理. The official Chinese paper is 150 minutes, 120 points, pass 84. Pay RMB 1,080 in the official system; authorized training is commonly RMB 6,800. Study ISO 31000, ISO/IEC 27005, GB/T 20984, asset-threat-vulnerability identification, SLE/ALE and matrix/multiplication calculation, treatment/acceptance, and 等保. These 100 English MCQs are a study adaptation, not the official mixed paper.
Sample CISAW Risk Management Practice Questions
Try these sample questions to test your CISAW Risk Management exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.
1Under the current CCRC Information Security Assurance Personnel Certification Criteria (CCRC-COP-C01:2023), what is the official technical-direction name of the CISAW credential historically also called 风险评估?
2According to ISO 31000, what is the purpose of 风险管理 (risk management)?
3Which definition of risk is consistent with ISO 31000 and CISAW 风险管理 teaching?
4Which item is an ISO 31000:2018 principle of effective 风险管理?
5In the ISO 31000 process, which group of activities constitutes risk assessment?
6What is the role of ISO/IEC 27005 in CISAW 风险管理 study?
7How should a CISAW candidate describe the relationship among ISO 31000, ISO/IEC 27005, and ISO/IEC 27001?
8What is GB/T 20984 in the CISAW 风险管理 outline?
9GB/T 20984-2022 organizes information security risk assessment into which four stages?
10What is the primary role of GB/T 31509 relative to GB/T 20984?
About the CISAW Risk Management Exam
The CISAW Risk Management Direction (信息安全保障人员认证-风险管理方向) is the CCRC / ISCCC personnel certification for practitioners who identify, analyze, evaluate, treat, and monitor information-security risk. CCRC-COP-C01:2023 Appendix A lists the official technical direction name as 风险管理 (RM); the direction is historically also called 风险评估. The official 150-minute Chinese paper is scored out of 120 points with a pass mark of 84. This OpenExamPrep set is an English-language MCQ study adaptation of the authorized outline (ISO 31000, ISO/IEC 27005, GB/T 20984, GB/T 31509, calculation, treatment, and 等保 context), not an official translation or a mixed-format simulation.
Assessment
Closed-book 150-minute sitting under CCRC CISAW personnel-certification rules. Authorized outline topics include ISO 31000, ISO/IEC 27005, GB/T 20984, GB/T 31509, asset/threat/vulnerability/control identification, risk analysis and calculation (矩阵法 and 相乘法), evaluation, treatment, acceptance, communication, and monitoring, plus China 等保 and cybersecurity-law context. Foundation-level (基础级) and professional-level (专业级) certificates use the same direction paper with different experience criteria.
Time Limit
150 minutes
Passing Score
84 out of 120 points (inclusive)
Exam Fee
RMB 1,080 official certification/exam fee (authorized training commonly RMB 6,800 separately) (China Cybersecurity Review, Certification and Market Regulation Big Data Center (CCRC / 中国网络安全审查认证和市场监管大数据中心; historically ISCCC))
CISAW Risk Management Exam Content Outline
Risk Management Concepts and Standards (风险管理基本概念)
Information security, 风险管理, information security risk, information security risk management and assessment, standardization bodies, ISO 31000, ISO/IEC 27005, and GB/T 20984.
Project Preparation and Context Establishment (项目管理基础和环境建立)
Project-management basics, assessment context, scope, stakeholders, risk criteria, and environment-establishment process and outputs.
Risk Identification (风险识别)
Business and strategy identification; asset identification and CIA assignment; threat identification; physical, network, system-software, middleware, application, and management vulnerability identification; and identification of existing controls (已有安全措施).
Risk Analysis and Calculation (风险分析与计算)
Likelihood and loss analysis, risk-element association, matrix method (矩阵法), multiplication method (相乘法), SLE = AV × EF, ALE = SLE × ARO, and residual-risk calculation.
Risk Evaluation and Assessment Outputs (风险评价和评估输出)
Risk-evaluation criteria and process, risk ranking against organizational appetite, and assessment documentation including the risk-assessment report.
Risk Treatment, Acceptance, Communication, and Monitoring (风险处置、接受、沟通与监视)
Treatment options and plans, residual risk and informed acceptance, communication and consultation, monitoring and review, and China 等保 / legal context for 风险管理.
How to Pass the CISAW Risk Management Exam
What You Need to Know
- Passing score: 84 out of 120 points (inclusive)
- Assessment: Closed-book 150-minute sitting under CCRC CISAW personnel-certification rules. Authorized outline topics include ISO 31000, ISO/IEC 27005, GB/T 20984, GB/T 31509, asset/threat/vulnerability/control identification, risk analysis and calculation (矩阵法 and 相乘法), evaluation, treatment, acceptance, communication, and monitoring, plus China 等保 and cybersecurity-law context. Foundation-level (基础级) and professional-level (专业级) certificates use the same direction paper with different experience criteria.
- Time limit: 150 minutes
- Exam fee: RMB 1,080 official certification/exam fee (authorized training commonly RMB 6,800 separately)
Keys to Passing
- Work through all 100 available questions
- Review every answer and explanation
- Track weak areas and revisit them
- Use our AI tutor for tough concepts
CISAW Risk Management Study Tips from Top Performers
Frequently Asked Questions
What is the official name of this CISAW direction?
CCRC-COP-C01:2023 Appendix A names the technical direction 风险管理 (RM), in English Risk Management. The same direction is historically also called 风险评估 (risk assessment). OpenExamPrep keeps the exam ID cn-cisaw-risk-assessment for URL stability.
Who administers CISAW and in what language is the official exam delivered?
The China Cybersecurity Review, Certification and Market Regulation Big Data Center (CCRC), historically the China Information Security Certification Center (ISCCC), administers CISAW under ISO/IEC 17024. The official assessment is in Chinese (zh). This practice bank is an English-language MCQ study adaptation, not an official English sitting.
What are the time limit, score, fee, and training cost?
The sitting is 150 minutes, 120 points, with 84 points (inclusive) to pass. The official exam/certification fee in the CCRC system is RMB 1,080. Authorized training is commonly RMB 6,800 and is paid to the training provider, not as a substitute for the official fee.
What topics does the authorized Risk Management outline cover?
ISO 31000, ISO/IEC 27005, GB/T 20984 information security risk assessment, GB/T 31509 implementation guidance, asset/threat/vulnerability identification, existing controls, risk analysis and calculation (including 矩阵法 and 相乘法), evaluation, treatment, acceptance, communication, and monitoring, used together with China 等保 and cybersecurity-law context.
How does this OpenExamPrep question bank relate to the official Chinese exam?
The official paper is a mixed Chinese assessment with single-choice, multiple-choice, short-answer, calculation, and comprehensive items as commonly reported by authorized trainers. This 100-question OpenExamPrep bank is an English-language MCQ study adaptation. It is not an official translation, not a CCRC item bank, and not a simulation of the unpublished exact item mix.