All Practice Exams

100+ Free CISAW SI Practice Questions

Prepare for the CISAW Security Integration Direction (信息安全保障人员认证-安全集成方向, SI) exam with instant access — no signup required.

✓ No registration✓ No credit card✓ No hidden fees✓ Start practicing immediately
100+ Questions
100% Free

Loading practice questions...

2026 Statistics

Key Facts: CISAW SI Exam

120 points

Official CCRC-COP-R05:2021 written-paper full mark

CCRC-COP-R05:2021

84 points

Inclusive pass mark on the 120-point SI written paper

CCRC-COP-R05:2021

150 minutes

Closed-book written sitting time

CCRC-COP-R05:2021

RMB 1,080

CISAW examination/certification fee in the CCRC personnel system

CCRC personnel certification business system / authorized training notices

3 years

CISAW certificate validity before recertification

CCRC-COP-C01 Information Security Assurance Personnel Certification Criteria

20%

Official weight of the Data Security (数据安全) knowledge block

CCRC-COP-R05:2021 paper content structure

GB/T 20261

Chinese SSE-CMM process-reference model (ISO/IEC 21827 modified adoption)

GB/T 20261-2020 / ISO/IEC 21827

4 stages

SI service stages: preparation, scheme design, construction, assurance

CCRC-COP-R05:2021 and CCRC information-security service specifications

CISAW SI is China's CCRC/ISCCC personnel credential for information-system security integration under CCRC-COP-R05:2021. The official closed-book Chinese paper is 150 minutes and 120 points (70 single-choice + 10 multiple-choice + 1 short-answer + 2 comprehensive items); 84 points passes. Domain weights are data security 20%, fundamentals 15%, boundary security 15%, SI engineering 15%, SI models 10%, SSE-CMM 10%, environment 8%, and carrier security 7%. Expect firewalls and 网闸, commercial cryptography for data at rest and in transit, and SSE-CMM (GB/T 20261 / ISO/IEC 21827) process areas. The 100 questions here are an English MCQ study adaptation, not the official mixed written paper.

Sample CISAW SI Practice Questions

Try these sample questions to test your CISAW SI exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.

1In CISAW information-security fundamentals, which three attributes form the classic CIA triad (信息安全三要素)?
A.Confidentiality (机密性), integrity (完整性), and availability (可用性)
B.Authentication (鉴别), authorization (授权), and accounting (审计)
C.Warning (预警), detection (检测), and recovery (恢复)
D.Identification (标识), encryption (加密), and backup (备份)
Explanation: The classic information-security triad is confidentiality (机密性), integrity (完整性), and availability (可用性). CISAW training treats these as the core attributes that later CIA-plus properties (authenticity, non-repudiation, controllability) extend rather than replace.
2Which statement best describes confidentiality (机密性) as used in CISAW information-security fundamentals?
A.Information can be modified by any system user so that it stays current
B.Information services remain reachable even when cryptographic keys are published
C.Information is destroyed immediately after it is transmitted
D.Information is disclosed only to authorized entities and remains hidden from unauthorized entities
Explanation: Confidentiality (机密性) means information is not disclosed to unauthorized persons, processes, or devices. Encryption, access control, and need-to-know are typical supporting controls; they serve this attribute rather than redefine it.
3A hospital information system must remain usable during a regional power event. Which CIA attribute is the integration team primarily protecting?
A.Non-repudiation (抗抵赖)
B.Steganography (隐写术)
C.Availability (可用性)
D.Confidentiality (机密性)
Explanation: Availability (可用性) is the property that authorized users can access information and services when needed. Power redundancy, UPS, clustering, and disaster recovery are typical SI measures that support this attribute.
4In CISAW risk vocabulary, which statement correctly distinguishes threat (威胁), vulnerability (脆弱性), and risk (风险)?
A.A threat, a vulnerability, and a risk are three names for the same residual score after treatment
B.A threat is a potential cause of harm, a vulnerability is a weakness that can be exploited, and risk is the combination of that possibility with consequence
C.A threat is a missing patch, a vulnerability is an attacker, and risk is a firewall rule
D.A threat is always a natural disaster, a vulnerability is always a virus, and risk is always residual after encryption
Explanation: CISAW fundamentals require understanding definitions and classification of risk, threat, and vulnerability. A threat (威胁) is a potential cause of an unwanted incident; a vulnerability (脆弱性) is a weakness that a threat may exploit; risk (风险) reflects the combination of likelihood and impact, not any one of those elements alone.
5Which of the following is a common information-security threat (常见威胁) that a CISAW SI engineer should expect to see in requirements analysis?
A.Phishing that tricks a privileged operator into revealing credentials
B.A documented residual-risk acceptance signed by the asset owner
C.A correctly configured UPS in the computer room
D.A completed SSE-CMM assurance argument
Explanation: Common threats include social-engineering (phishing), malware, insider misuse, denial of service, and physical intrusion. SI requirements analysis starts from such threats plus asset value and known weaknesses, not from completed assurance artifacts.
6The CISAW unified assurance model extends PDR into WPDRRC. What do the six WPDRRC capability links represent?
A.Write, patch, detect, report, restore, and comply
B.Wireless, physical, data, routing, RAID, and cryptography
C.Watch, policy, DMZ, RADIUS, RBAC, and checksum
D.Warning (预警), protection (保护), detection (检测), response (反应), recovery (恢复), and counter-attack (反击)
Explanation: CISAW training presents the evolution from PDR to WPDRRC. The six links are warning/预警, protection/保护, detection/检测, response/反应, recovery/恢复, and counter-attack/反击. They describe assurance activities around the protected object, not a product shopping list.
7Relative to the classic PDR model (protection, detection, response), what does WPDRRC add as explicit capability links?
A.Only physical fences and guards
B.Only SSE-CMM capability Level 5
C.Warning (预警) before protection, plus recovery (恢复) and counter-attack (反击) after response
D.Only encryption and digital signatures
Explanation: PDR covers protection, detection, and response. WPDRRC keeps those three and adds warning (前瞻脆弱性/威胁感知), recovery (业务与数据恢复), and counter-attack (取证与依法打击). CISAW uses this series as the unified assurance-link view.
8Under the PRC Cybersecurity Law (网络安全法), network operators of information systems in China are expected to implement which graded protection approach?
A.Exemption from any protection grade if a firewall is purchased
B.Cybersecurity classified protection (网络安全等级保护, MLPS)
C.A voluntary US FedRAMP authorization in place of Chinese obligations
D.Replacement of all Chinese standards with PCI DSS alone
Explanation: The Cybersecurity Law requires network operators to implement cybersecurity classified protection (网络安全等级保护, commonly MLPS). SI designs in China are therefore expected to align controls with the system's determined protection grade rather than with an unrelated foreign authorization scheme.
9The PRC Data Security Law (数据安全法) requires data to be protected according to its importance. Which grouping matches the law's classified-protection idea for data?
A.Core data (核心数据), important data (重要数据), and general data (一般数据)
B.Public data, secret data, and top-secret data as the only three MLPS grades
C.Personal data, payment data, and health data as statutory encryption algorithms
D.Hot data, warm data, and cold data as legal classification labels
Explanation: The Data Security Law establishes a classified and graded data-protection idea. Practice and implementing rules treat core data, important data, and general data as the operative importance classes. SI designs must match protection strength to that classification, not to storage-tier nicknames.
10When an SI project must protect identified natural persons' information in China, which law is the primary personal-information statute, distinct from the Data Security Law's focus on data as a national/organizational asset?
A.Company Law (公司法) director-liability chapter
B.Patent Law (专利法) disclosure rules
C.Auction Law (拍卖法) notice rules
D.Personal Information Protection Law (个人信息保护法, PIPL)
Explanation: PIPL (个人信息保护法) is the dedicated personal-information statute. The Data Security Law addresses data security more broadly (including important/core data). SI requirements for consent, purpose limitation, and sensitive personal information come from PIPL, not from unrelated commercial codes.

About the CISAW SI Exam

CISAW Security Integration Direction (信息安全保障人员认证-安全集成方向, SI) is the CCRC/ISCCC personnel certification for practitioners who perform information-system security integration: requirements analysis, security design, construction, testing, commissioning, hardening, and assurance. The official outline is CCRC-COP-R05:2021 (foundation/professional levels). The official assessment is a 150-minute closed-book Chinese written paper of 120 points (70 single-choice, 10 multiple-choice, 1 short-answer, 2 comprehensive-application items) with a pass mark of 84. This OpenExamPrep bank is an English-language MCQ study adaptation of that outline, not an official translation and not a simulation of the short-answer or comprehensive-application items.

Assessment

Closed-book written paper under CCRC-COP-R05:2021: 70 single-choice items (1 point each), 10 multiple-choice items (2 points each), 1 short-answer item (6 points), and 2 comprehensive-application items (12 points each). Knowledge weights: information security fundamentals 15%, data security 20%, carrier security 7%, environment security 8%, boundary security 15%, SI concepts and models 10%, system security engineering theory 10%, SI engineering fundamentals 15%.

Time Limit

150 minutes

Passing Score

84 out of 120 points (inclusive)

Exam Fee

RMB 1,080 examination/certification fee (China Cybersecurity Review, Certification and Market Regulation Big Data Center (CCRC / ISCCC))

CISAW SI Exam Content Outline

15%

Information Security Fundamentals (信息安全基础)

Information-security concepts; risk, threat and vulnerability definitions and classes; common threats; technology evolution; and related PRC laws and standards.

20%

Data Security (数据安全)

Data-security scope; cryptographic principles and typical algorithms; algorithm application; key management; fault-tolerance and disaster recovery; anti-spam.

7%

Carrier Security (载体安全)

Carrier scope; storage-media security; transmission-carrier scope and typical threats; common security protocols.

8%

Environment Security (环境安全)

Environment scope; computer-room physical environment; host security; access control; security audit; identity authentication; malware defense.

15%

Boundary Security (边界安全)

Physical and logical boundaries; perimeter protection; network-boundary firewalls and isolation gateways (网闸); host-boundary controls.

10%

Security Integration Concepts and Models (安全集成基本概念与模型)

SI scope and definition; CISAW information-system SI model; two SI modes and their relationship; essential problems; typical security incidents.

10%

System Security Engineering Theory (系统安全工程基本理论)

System security engineering definitions and models; SSE-CMM architecture; engineering, risk, and assurance process-area practices (GB/T 20261 / ISO/IEC 21827).

15%

Security Integration Engineering Fundamentals (安全集成工程基础)

Four SI service stages; engineering links and inputs/outputs; requirements analysis; scheme design; construction/implementation; testing; trial operation; comprehensive application.

How to Pass the CISAW SI Exam

What You Need to Know

  • Passing score: 84 out of 120 points (inclusive)
  • Assessment: Closed-book written paper under CCRC-COP-R05:2021: 70 single-choice items (1 point each), 10 multiple-choice items (2 points each), 1 short-answer item (6 points), and 2 comprehensive-application items (12 points each). Knowledge weights: information security fundamentals 15%, data security 20%, carrier security 7%, environment security 8%, boundary security 15%, SI concepts and models 10%, system security engineering theory 10%, SI engineering fundamentals 15%.
  • Time limit: 150 minutes
  • Exam fee: RMB 1,080 examination/certification fee

Keys to Passing

  • Work through all 100 available questions
  • Review every answer and explanation
  • Track weak areas and revisit them
  • Use our AI tutor for tough concepts

CISAW SI Study Tips from Top Performers

1Memorize the official eight knowledge-block weights in CCRC-COP-R05:2021: data security 20%; fundamentals, boundary security, and SI engineering 15% each; SI models and SSE-CMM 10% each; environment 8%; carrier 7%.
2Treat 网闸 (security isolation gateway / GAP) as a protocol-breaking physical-isolation ferry between security domains, not as a stateful firewall that forwards TCP/IP sessions.
3Drill commercial cryptography roles without mixing algorithms: SM4 is the 128-bit block cipher for confidentiality, SM3 is the hash, and SM2 is the elliptic-curve public-key algorithm for signatures and key exchange under the Cryptography Law's 商用密码 category.
4Map SSE-CMM's two dimensions (domain vs capability) and three security-engineering areas (risk, engineering, assurance) to the 11 security process areas PA01–PA11; GB/T 20261 is the Chinese adoption of ISO/IEC 21827.
5Keep the four SI service stages distinct: 集成准备 (preparation, including requirements), 方案设计 (scheme design), 建设实施 (construction/implementation), and 安全保障 (assurance, including verification/validation and trial operation).
6Practice distinguishing data at rest (storage encryption, media control, backup) from data in transit (TLS, IPsec, SSH) and from boundary controls (firewall, 网闸) so comprehensive-application items do not blend layers.

Frequently Asked Questions

What is the CISAW Security Integration Direction examination?

It is the CCRC/ISCCC personnel written examination for the Security Integration (安全集成, SI) technical direction of Certified Information Security Assurance Worker (信息安全保障人员认证). The current outline is CCRC-COP-R05:2021 for foundation and professional levels. It tests knowledge and applied judgment for integrating security units and products into information systems using system security engineering.

What is the official format, timing, and pass mark?

CCRC-COP-R05:2021 specifies a closed-book independent written paper (笔试,闭卷), 150 minutes, 120 points. Item types are 70 single-choice (1 point), 10 multiple-choice (2 points), 1 short-answer (6 points), and 2 comprehensive-application items (12 points each). 84 points inclusive is the pass mark.

How much is the official examination fee?

The CCRC examination/certification fee commonly charged in the personnel certification business system is RMB 1,080. Authorized training tuition is billed separately by the training organization and is not the CCRC exam fee.

In what language is the official exam delivered?

The official paper is in Chinese (officialLanguages: zh). This OpenExamPrep bank is an English-language MCQ study adaptation. It is not an official translation and does not simulate the Chinese language environment, short-answer writing, or comprehensive-application items.

What standards does the SI direction emphasize?

The SI knowledge block on system security engineering is built around SSE-CMM as adopted in China by GB/T 20261 and internationally by ISO/IEC 21827. Service evaluation also references CCRC information-security service specifications (including CNCA/CTS 0052 in related service-certification rules). Do not confuse SSE-CMM process areas with unrelated maturity models.

How long is the certificate valid?

The CISAW certificate is valid for three years. Holders apply for recertification in the CCRC personnel system after completing at least 16 hours of continuing education (typically two 8-hour online courses) in the three months before expiry. A lapsed certificate generally requires a new examination.