100+ Free CISAW Secure Software Practice Questions
Prepare for the CISAW Secure Software Direction (信息安全保障人员认证-安全软件方向, SS) exam with instant access — no signup required.
Loading practice questions...
Explore More China CISAW Information Security Assurance Workforce Certifications (信息安全保障人员认证)
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
Key Facts: CISAW Secure Software Exam
150 min
Official CISAW Secure Software written duration
CACE/ISCCC CISAW notices
120 points
Official full mark
CACE/ISCCC CISAW notices
84
Passing score (inclusive)
CACE/ISCCC CISAW notices
RMB 1,080
Certification/exam fee paid to ISCCC
CACE CISAW training and exam notices
RMB 6,800
Common authorized training fee for this direction
CACE CISAW training notices
CISAW Secure Software (安全软件方向) is a 150-minute, 120-point Chinese written exam administered by CCRC/ISCCC, with 84 as the pass mark and an RMB 1,080 exam fee (training commonly RMB 6,800). Official item count is not published. This page offers 100 free English MCQs on SSDLC, threat modeling, secure coding, testing, supply chain, and Chinese software-security standards — a study aid, not an official paper.
Sample CISAW Secure Software Practice Questions
Try these sample questions to test your CISAW Secure Software exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.
1What is the main difference between a conventional SDLC and an SSDLC?
2When should security requirements first be identified in an SSDLC?
3Which statement best describes a security requirement as opposed to an ordinary functional requirement?
4In software security, the CIA triad refers to:
5What does “shift left” mean in secure development?
6A team using agile two-week sprints asks how to apply SSDLC. Which approach is most consistent with secure agile practice?
7What is the purpose of a security gate between SSDLC phases?
8How do abuse cases (misuse cases) help security requirements?
9Microsoft SDL is a typical secure-development model taught alongside others in CISAW Secure Software. Which set of activities matches that style of model?
10What is the most useful role of a security champion on a software team?
About the CISAW Secure Software Exam
CISAW Secure Software Direction (信息安全保障人员认证-安全软件方向, SS) is the software-security personnel certification administered by the China Cybersecurity Review, Certification and Market Regulation Big Data Center (CCRC / ISCCC) under ISO/IEC 17024. The official Chinese paper lasts 150 minutes and is scored out of 120 points, with 84 as the passing mark. CACE/ISCCC notices list an RMB 1,080 certification fee and commonly quote RMB 6,800 for authorized training. Outline topics include software-security concepts, secure development models, vulnerability management, Common Criteria-style security functions, secure coding defects, security testing, and software-security management in a Chinese GB/T and Cybersecurity Law context. This OpenExamPrep bank is a free English-language MCQ study adaptation, not an official translation, language environment, or item-type simulation.
Assessment
Official assessment: 150-minute Chinese written paper, 120 points, mixed single-choice, multiple-choice, short-answer, and applied/experimental items. Passing mark 84. After a passing score, ISCCC grants a foundation-level or professional-level CISAW certificate according to the personnel certification criteria. This local bank is 100 original four-option English MCQs for study only.
Time Limit
150 minutes
Passing Score
84 out of 120 points (70%)
Exam Fee
RMB 1,080 certification/exam fee; authorized training commonly RMB 6,800 (China Cybersecurity Review, Certification and Market Regulation Big Data Center (CCRC / ISCCC / 中国网络安全审查认证和市场监管大数据中心))
CISAW Secure Software Exam Content Outline
SSDLC and Secure Development Process
Software security scope, SDLC versus SSDLC, waterfall/iterative/agile methods, security requirements and gates, security training, and CISAW-taught secure development models
Secure Design and Threat Modeling
STRIDE-style threat modeling, data-flow and trust-boundary analysis, least privilege and related design principles, and security functions such as audit, cryptographic support, identification and authentication, privacy, and trusted path/channel
Secure Coding Defects
Injection, XSS, CSRF, authentication and authorization flaws, cryptographic misuse, secrets, integer/string/memory/concurrency issues, and input/output validation
Security Testing and Code Review
Manual review, SAST/DAST/SCA, fuzzing, negative tests, test organization, and GB/T 39412-2020 code-security audit process and defect classes
Supply Chain, Vulnerability Management, and Chinese Governance
SCAP, CVE/CWE/CVSS, third-party and build-pipeline risk, SBOM, software security management, Cybersecurity Law duties for critical software, and GB/T software-security context
How to Pass the CISAW Secure Software Exam
What You Need to Know
- Passing score: 84 out of 120 points (70%)
- Assessment: Official assessment: 150-minute Chinese written paper, 120 points, mixed single-choice, multiple-choice, short-answer, and applied/experimental items. Passing mark 84. After a passing score, ISCCC grants a foundation-level or professional-level CISAW certificate according to the personnel certification criteria. This local bank is 100 original four-option English MCQs for study only.
- Time limit: 150 minutes
- Exam fee: RMB 1,080 certification/exam fee; authorized training commonly RMB 6,800
Keys to Passing
- Work through all 100 available questions
- Review every answer and explanation
- Track weak areas and revisit them
- Use our AI tutor for tough concepts
CISAW Secure Software Study Tips from Top Performers
Frequently Asked Questions
What is the CISAW Secure Software Direction exam?
It is the software-security direction (安全软件方向, often abbreviated SS) of CISAW (信息安全保障人员认证), China's ISO/IEC 17024 personnel certification for information-security assurance roles. CCRC/ISCCC administers the exam. The outline covers secure development models, vulnerability management, security-function design, secure coding, and software security testing.
Who should take CISAW Secure Software?
CACE notices target software project managers and design, development, testing, and technical-service staff who need a Chinese personnel credential in secure software development, including teams supporting government, finance, energy, and other critical-industry software.
What are the official time limit, score, and fee?
Published CACE/ISCCC notices for this direction specify 150 minutes, 120 points, and a passing mark of 84 (inclusive). The certification/exam fee is RMB 1,080, paid on the ISCCC CISAW portal. Authorized training is commonly RMB 6,800.
Does ISCCC publish an official question count?
Reviewed official notices publish duration, full mark, passing score, and mixed item types, but not a single authoritative item count for Secure Software. This site therefore records examQuestions as not-published and does not treat training-brochure counts as official.
Is the official exam in English multiple-choice format?
No. The official assessment is a Chinese written paper with single-choice, multiple-choice, short-answer, and applied/experimental items. This bank is a free English-language MCQ study adaptation. It is not an official translation, not a language-environment simulation, and not a substitute for Chinese constructed-response practice.
How do foundation-level and professional-level certificates differ?
Candidates sit the direction exam; ISCCC then grants a foundation-level (基础级) or professional-level (专业级) certificate according to education and experience in the CISAW personnel certification criteria. Senior professional (专业高级) requirements are stricter. Confirm current routes on the ISCCC portal.
Where do I register?
Register and pay the RMB 1,080 exam fee on the ISCCC CISAW personnel portal at https://ryrzcisaw.isccc.gov.cn/. Training enrollment is separate through authorized providers such as those announced by CACE.
How does this relate to CISP-SSDP?
CISP-SSDP is a CNITSEC software-security development registration credential. CISAW Secure Software is an ISCCC/CCRC personnel certification. They overlap on SSDLC and secure coding but are different bodies, rules, and certificates.