All Practice Exams

100+ Free CISAW Secure Software Practice Questions

Prepare for the CISAW Secure Software Direction (信息安全保障人员认证-安全软件方向, SS) exam with instant access — no signup required.

✓ No registration✓ No credit card✓ No hidden fees✓ Start practicing immediately
100+ Questions
100% Free

Loading practice questions...

2026 Statistics

Key Facts: CISAW Secure Software Exam

150 min

Official CISAW Secure Software written duration

CACE/ISCCC CISAW notices

120 points

Official full mark

CACE/ISCCC CISAW notices

84

Passing score (inclusive)

CACE/ISCCC CISAW notices

RMB 1,080

Certification/exam fee paid to ISCCC

CACE CISAW training and exam notices

RMB 6,800

Common authorized training fee for this direction

CACE CISAW training notices

CISAW Secure Software (安全软件方向) is a 150-minute, 120-point Chinese written exam administered by CCRC/ISCCC, with 84 as the pass mark and an RMB 1,080 exam fee (training commonly RMB 6,800). Official item count is not published. This page offers 100 free English MCQs on SSDLC, threat modeling, secure coding, testing, supply chain, and Chinese software-security standards — a study aid, not an official paper.

Sample CISAW Secure Software Practice Questions

Try these sample questions to test your CISAW Secure Software exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.

1What is the main difference between a conventional SDLC and an SSDLC?
A.An SSDLC forbids agile methods and requires a pure waterfall schedule
B.An SSDLC is only a Chinese GB/T document number and is not a development process
C.An SSDLC adds security activities throughout requirements, design, implementation, verification, release, and response instead of treating security as a late testing add-on
D.An SSDLC replaces functional testing with penetration testing only
Explanation: A secure software development life cycle (SSDLC) weaves security work into every phase rather than waiting for a final scan. CISAW Secure Software training contrasts ordinary development models with security-aware models so defects are prevented earlier.
2When should security requirements first be identified in an SSDLC?
A.Only in the final week of system testing
B.Only when a customer requests a penetration test
C.Only after the first production incident
D.During requirements and planning, before detailed design and coding
Explanation: Security requirements belong in the requirements phase so design, coding, and tests can implement them. Identifying them only after incidents or at the end of testing is the opposite of shift-left SSDLC practice taught in CISAW Secure Software.
3Which statement best describes a security requirement as opposed to an ordinary functional requirement?
A.It only lists screen layouts and color themes
B.It only describes batch job run times
C.It states a needed security property such as authentication, authorization, confidentiality, integrity, or auditability
D.It is always identical to a performance SLA
Explanation: Security requirements specify how the software must protect assets and users: who is identified, what is authorized, what is logged, and how data is protected. Functional features may still need security constraints, but a color theme or a runtime SLA is not itself a security requirement.
4In software security, the CIA triad refers to:
A.Coding, integration, and acceptance testing only
B.Cost, inventory, and accounting controls only
C.Customer, integrator, and auditor roles only
D.Confidentiality, integrity, and availability
Explanation: CIA is confidentiality, integrity, and availability. CISAW software-security work still uses this triad when writing requirements and selecting controls, often adding authenticity, non-repudiation, and privacy.
5What does “shift left” mean in secure development?
A.Delay code review until after public release
B.Replace developers with a single security scanner
C.Move security analysis, requirements, and testing earlier so defects are cheaper to fix
D.Move all security work to the production operations team
Explanation: Shift left means doing threat modeling, secure requirements, coding standards, and automated checks earlier in the life cycle. Later fixes cost more and may require design changes that a last-minute scan cannot provide.
6A team using agile two-week sprints asks how to apply SSDLC. Which approach is most consistent with secure agile practice?
A.Forbid automated tests because agile only values working software demos
B.Document security only in a binder that developers never see
C.Skip security until a yearly waterfall hardening project
D.Add small security stories, threat-model changes, and automated checks inside each sprint rather than one isolated security phase
Explanation: Agile SSDLC spreads security work across sprints: backlog security stories, lightweight threat modeling of changed flows, coding standards, and pipeline checks. CISAW covers multiple development models; agile still needs continuous security, not a yearly bolt-on.
7What is the purpose of a security gate between SSDLC phases?
A.To guarantee that no future vulnerability can ever appear
B.To replace all functional quality reviews
C.To require evidence that agreed security activities were completed before the work proceeds
D.To delay release until marketing approves the logo
Explanation: A security gate is a go/no-go check: threat model updated, high-severity findings treated, required reviews or tests done. It does not prove the software is forever invulnerable, but it stops silent skipping of security work.
8How do abuse cases (misuse cases) help security requirements?
A.They replace all threat modeling diagrams
B.They are used only to estimate advertising click-through rates
C.They list only happy-path shopping-cart steps
D.They describe how an attacker or misuser might abuse functions so controls and tests can be specified
Explanation: Abuse or misuse cases invert use cases: they ask how login, upload, or payment could be abused. That drives authentication, authorization, validation, and logging requirements and later negative tests.
9Microsoft SDL is a typical secure-development model taught alongside others in CISAW Secure Software. Which set of activities matches that style of model?
A.Only rewriting the GUI theme each year
B.Only counting lines of code as a security metric
C.Security training, requirements, threat-informed design, secure implementation, verification, release, and response
D.Only network firewall purchase after go-live
Explanation: Classic Microsoft SDL organizes security training, requirements, design (including threat modeling), implementation, verification, release, and incident response. CISAW expects candidates to recognize such end-to-end models rather than a single post-production control.
10What is the most useful role of a security champion on a software team?
A.To approve every marketing screenshot
B.To be the only person allowed to write application code
C.To coach the team on standards, reviews, and tools so security is not isolated in a distant team
D.To disable all logging to improve performance
Explanation: A security champion is a developer or tester who spreads secure-coding practice, helps with reviews, and connects the team to specialists. SSDLC fails if security knowledge lives only in a remote group that never sees the code.

About the CISAW Secure Software Exam

CISAW Secure Software Direction (信息安全保障人员认证-安全软件方向, SS) is the software-security personnel certification administered by the China Cybersecurity Review, Certification and Market Regulation Big Data Center (CCRC / ISCCC) under ISO/IEC 17024. The official Chinese paper lasts 150 minutes and is scored out of 120 points, with 84 as the passing mark. CACE/ISCCC notices list an RMB 1,080 certification fee and commonly quote RMB 6,800 for authorized training. Outline topics include software-security concepts, secure development models, vulnerability management, Common Criteria-style security functions, secure coding defects, security testing, and software-security management in a Chinese GB/T and Cybersecurity Law context. This OpenExamPrep bank is a free English-language MCQ study adaptation, not an official translation, language environment, or item-type simulation.

Assessment

Official assessment: 150-minute Chinese written paper, 120 points, mixed single-choice, multiple-choice, short-answer, and applied/experimental items. Passing mark 84. After a passing score, ISCCC grants a foundation-level or professional-level CISAW certificate according to the personnel certification criteria. This local bank is 100 original four-option English MCQs for study only.

Time Limit

150 minutes

Passing Score

84 out of 120 points (70%)

Exam Fee

RMB 1,080 certification/exam fee; authorized training commonly RMB 6,800 (China Cybersecurity Review, Certification and Market Regulation Big Data Center (CCRC / ISCCC / 中国网络安全审查认证和市场监管大数据中心))

CISAW Secure Software Exam Content Outline

20%

SSDLC and Secure Development Process

Software security scope, SDLC versus SSDLC, waterfall/iterative/agile methods, security requirements and gates, security training, and CISAW-taught secure development models

20%

Secure Design and Threat Modeling

STRIDE-style threat modeling, data-flow and trust-boundary analysis, least privilege and related design principles, and security functions such as audit, cryptographic support, identification and authentication, privacy, and trusted path/channel

30%

Secure Coding Defects

Injection, XSS, CSRF, authentication and authorization flaws, cryptographic misuse, secrets, integer/string/memory/concurrency issues, and input/output validation

15%

Security Testing and Code Review

Manual review, SAST/DAST/SCA, fuzzing, negative tests, test organization, and GB/T 39412-2020 code-security audit process and defect classes

15%

Supply Chain, Vulnerability Management, and Chinese Governance

SCAP, CVE/CWE/CVSS, third-party and build-pipeline risk, SBOM, software security management, Cybersecurity Law duties for critical software, and GB/T software-security context

How to Pass the CISAW Secure Software Exam

What You Need to Know

  • Passing score: 84 out of 120 points (70%)
  • Assessment: Official assessment: 150-minute Chinese written paper, 120 points, mixed single-choice, multiple-choice, short-answer, and applied/experimental items. Passing mark 84. After a passing score, ISCCC grants a foundation-level or professional-level CISAW certificate according to the personnel certification criteria. This local bank is 100 original four-option English MCQs for study only.
  • Time limit: 150 minutes
  • Exam fee: RMB 1,080 certification/exam fee; authorized training commonly RMB 6,800

Keys to Passing

  • Work through all 100 available questions
  • Review every answer and explanation
  • Track weak areas and revisit them
  • Use our AI tutor for tough concepts

CISAW Secure Software Study Tips from Top Performers

1Study SSDLC as security activities woven through requirements, design, implementation, verification, release, and response — not a single test phase at the end.
2Memorize STRIDE as Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, and Elevation of privilege, and map each to a control class (authentication, integrity, non-repudiation, confidentiality, availability, authorization).
3For coding items, prefer parameterized queries, contextual output encoding, anti-CSRF tokens, unique password salts with a slow hash, and a secrets vault — never exploit payloads.
4Keep SAST (code without execution), DAST (running application), and SCA (third-party inventory) distinct; CISAW expects you to know when each is appropriate.
5Use GB/T 39412-2020 as the Chinese code-audit frame: preparation, implementation, report, and follow-up, covering security-function, implementation, resource-use, and environmental defects.
6Place software duties in Cybersecurity Law terms: no malicious programs, timely defect handling and user notification, and extra review obligations when software supports critical information infrastructure.
7Practice explaining security functions in Common Criteria language (audit, cryptographic support, I&A, user-data protection, trusted path) because that list appears in the CISAW Secure Software outline.
8Remember this English MCQ bank cannot replace Chinese short-answer and applied items; outline a threat model, a test plan, and a vulnerability-handling workflow in Chinese before exam day.

Frequently Asked Questions

What is the CISAW Secure Software Direction exam?

It is the software-security direction (安全软件方向, often abbreviated SS) of CISAW (信息安全保障人员认证), China's ISO/IEC 17024 personnel certification for information-security assurance roles. CCRC/ISCCC administers the exam. The outline covers secure development models, vulnerability management, security-function design, secure coding, and software security testing.

Who should take CISAW Secure Software?

CACE notices target software project managers and design, development, testing, and technical-service staff who need a Chinese personnel credential in secure software development, including teams supporting government, finance, energy, and other critical-industry software.

What are the official time limit, score, and fee?

Published CACE/ISCCC notices for this direction specify 150 minutes, 120 points, and a passing mark of 84 (inclusive). The certification/exam fee is RMB 1,080, paid on the ISCCC CISAW portal. Authorized training is commonly RMB 6,800.

Does ISCCC publish an official question count?

Reviewed official notices publish duration, full mark, passing score, and mixed item types, but not a single authoritative item count for Secure Software. This site therefore records examQuestions as not-published and does not treat training-brochure counts as official.

Is the official exam in English multiple-choice format?

No. The official assessment is a Chinese written paper with single-choice, multiple-choice, short-answer, and applied/experimental items. This bank is a free English-language MCQ study adaptation. It is not an official translation, not a language-environment simulation, and not a substitute for Chinese constructed-response practice.

How do foundation-level and professional-level certificates differ?

Candidates sit the direction exam; ISCCC then grants a foundation-level (基础级) or professional-level (专业级) certificate according to education and experience in the CISAW personnel certification criteria. Senior professional (专业高级) requirements are stricter. Confirm current routes on the ISCCC portal.

Where do I register?

Register and pay the RMB 1,080 exam fee on the ISCCC CISAW personnel portal at https://ryrzcisaw.isccc.gov.cn/. Training enrollment is separate through authorized providers such as those announced by CACE.

How does this relate to CISP-SSDP?

CISP-SSDP is a CNITSEC software-security development registration credential. CISAW Secure Software is an ISCCC/CCRC personnel certification. They overlap on SSDLC and secure coding but are different bodies, rules, and certificates.