100+ Free CISP-PTS Practice Questions
Prepare for the CISP-PTS Penetration Testing Specialist (注册信息安全专业人员-渗透测试专家) exam with instant access — no signup required.
Loading practice questions...
Explore More China CNITSEC CISP Personnel Registration Certifications (注册信息安全专业人员)
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
Key Facts: CISP-PTS Exam
70/100
CISP-PTS passing score on an all-practical 100-point CNITSEC exam (no official MCQ paper).
CNITSEC CISP-PTE/PTS knowledge system / authorized outline
30/30/10/30
Official PTS weights: Web 30%, OS and middleware 30%, data and logs 10%, penetration testing 30%.
CNITSEC CISP-PTE/PTS knowledge-system structure
CNY 27,800
November 2022 whitepaper initial package: CNY 19,800 training plus CNY 8,000 exam-center fees.
CNITSEC CISP-PTE/CISP-PTS whitepaper (Nov 2022)
3 years
CISP-PTS certificate validity; maintenance requires a CNITSEC offensive-domain maintenance exam.
CNITSEC CISP-PTE/CISP-PTS whitepaper (Nov 2022)
PTS-only middleware
WebLogic, WebSphere, and JBoss are required for PTS and are not required at the same depth for CISP-PTE.
CNITSEC CISP-PTE/PTS knowledge framework (red/PTS-only topics)
PTS-only data stores
Oracle, Redis, and MongoDB are required for PTS in addition to Microsoft SQL Server and MySQL.
CNITSEC CISP-PTE/PTS knowledge framework (red/PTS-only topics)
Chinese practical exam
Official CISP-PTS is delivered in Chinese as practical tasks; this bank is an English MCQ study adaptation only.
CNITSEC / officialLanguages zh
Official CISP-PTS is an all-practical CNITSEC exam (100 points, 70% to pass) in Chinese, with weights Web 30%, OS/middleware 30%, data and logs 10%, and penetration testing 30%. PTS goes beyond PTE by requiring WebLogic, WebSphere, JBoss, Oracle, Redis, MongoDB, and internal-network methods. Initial package fees in the November 2022 whitepaper total CNY 27,800 (CNY 19,800 training + CNY 8,000 exam-center fees). This 100-question bank is a free English-language MCQ study adaptation — not an official translation and not a simulation of the practical exam.
Sample CISP-PTS Practice Questions
Try these sample questions to test your CISP-PTS exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.
1During a PTS-level web review, a REST create endpoint returns HTTP 200 with an empty body after inserting a row. Which status best matches HTTP semantics for a successful create that also returns a locator for the new resource?
2A session cookie is readable from document.cookie in a victim browser even though the application already uses HTTPS. Which cookie attribute is the primary control to stop that JavaScript access?
3A comment field stores a script that later executes in every moderator's browser when they open the queue. Which XSS class is this?
4Which condition is the core prerequisite for classic cookie-based CSRF against a state-changing request?
5Which coding pattern is the primary cause of SQL injection in application queries?
6A registration form stores a profile 'nickname' without executing SQL. Weeks later, an admin report concatenates that nickname into a SELECT and dumps extra tables. What class is this?
7An XML upload feature parses documents with a fully featured DTD processor and external-entity resolution enabled. Which outcome is the defining XXE impact class?
8A server-side PDF renderer accepts a user-supplied URL and fetches it from the application host. Blocking literal IP literals in 169.254.169.254 is the only control. Why is that insufficient against SSRF?
9Which CSRF defense combination is the most robust for a cookie-authenticated browser application?
10Which file-upload control set actually reduces web-shell risk rather than trusting attacker-controlled metadata?
About the CISP-PTS Exam
CISP-PTS (Certified Information Security Professional — Penetration Testing Specialist; 注册信息安全专业人员-渗透测试专家) is CNITSEC's specialist-level penetration-testing credential above CISP-PTE. Holders are expected to perform vulnerability research and code analysis, follow current offensive-security developments, and design solutions. The official exam is 100% practical (100 points, 70 to pass) and is delivered in Chinese after authorized training. This page is an English-language multiple-choice study adaptation of the official knowledge weights — Web 30%, OS and middleware 30%, data and logs 10%, and penetration testing 30% — with extra PTS depth on WebLogic/WebSphere/JBoss, Oracle/Redis/MongoDB, internal-network methods, and code-analysis concepts. It is not an official lab simulation and does not replace the practical exam.
Assessment
Official CISP-PTS (CNITSEC): all practical operations, 100 points, 70 to pass, delivered in Chinese. Knowledge weights: Web security 30%; operating systems and middleware 30% (Apache, IIS, Tomcat, plus PTS-only WebLogic, WebSphere, and JBoss); data and logs 10% (Microsoft SQL Server and MySQL, plus PTS-only Oracle, Redis, and MongoDB); penetration testing 30% (including internal-network methods, post-exploitation concepts, vulnerability research, and code-analysis concepts). This local bank uses four-option English MCQs to practice those knowledge decisions only.
Time Limit
Authorized providers commonly report 4 hours for the practical sitting; confirm with CNITSEC or your authorized training institution. Official published format is all practical, not a timed MCQ paper.
Passing Score
70%
Exam Fee
CNY 8,000 exam-center fees (exam CNY 5,500 + registration CNY 1,000 + 3-year annuity CNY 1,500); authorized training CNY 19,800; total initial package CNY 27,800 (November 2022 CNITSEC whitepaper). Retake CNY 4,000. (China Information Technology Security Evaluation Center (CNITSEC / 中国信息安全测评中心))
CISP-PTS Exam Content Outline
Web Security
HTTP protocol, injection classes, XSS, SSRF, CSRF, file handling, access control, session management, and code-audit source/sink reasoning.
Operating Systems and Middleware
Windows and Linux privilege and hardening, Apache, IIS, Tomcat, and PTS-only WebLogic, WebSphere, and JBoss management and Java-middleware concepts.
Data and Logs
Microsoft SQL Server and MySQL plus PTS-only Oracle, Redis, and MongoDB controls, dangerous packages/commands, and log-integrity analysis.
Penetration Testing
Authorized recon, vulnerability discovery, exploitation methodology without payloads, internal-network methods, post-exploitation concepts, vulnerability research, and reporting.
How to Pass the CISP-PTS Exam
What You Need to Know
- Passing score: 70%
- Assessment: Official CISP-PTS (CNITSEC): all practical operations, 100 points, 70 to pass, delivered in Chinese. Knowledge weights: Web security 30%; operating systems and middleware 30% (Apache, IIS, Tomcat, plus PTS-only WebLogic, WebSphere, and JBoss); data and logs 10% (Microsoft SQL Server and MySQL, plus PTS-only Oracle, Redis, and MongoDB); penetration testing 30% (including internal-network methods, post-exploitation concepts, vulnerability research, and code-analysis concepts). This local bank uses four-option English MCQs to practice those knowledge decisions only.
- Time limit: Authorized providers commonly report 4 hours for the practical sitting; confirm with CNITSEC or your authorized training institution. Official published format is all practical, not a timed MCQ paper.
- Exam fee: CNY 8,000 exam-center fees (exam CNY 5,500 + registration CNY 1,000 + 3-year annuity CNY 1,500); authorized training CNY 19,800; total initial package CNY 27,800 (November 2022 CNITSEC whitepaper). Retake CNY 4,000.
Keys to Passing
- Work through all 100 available questions
- Review every answer and explanation
- Track weak areas and revisit them
- Use our AI tutor for tough concepts
CISP-PTS Study Tips from Top Performers
Frequently Asked Questions
Is the official CISP-PTS exam multiple choice?
No. CNITSEC's CISP-PTS exam is entirely practical operations scored out of 100 points, with 70 required to pass. This site's 100 English multiple-choice items are a study adaptation of PTS knowledge. They are not an official translation, not a lab, and not a simulation of the practical exam.
What score do I need to pass CISP-PTS?
70 points out of 100 (70%). The official exam awards all 100 points on practical tasks. Confirm current scoring details with CNITSEC or your authorized training institution.
How is CISP-PTS different from CISP-PTE?
CISP-PTE is engineer-level and mixes objective items with practical tasks (commonly described as 20 objective points plus 80 practical). CISP-PTS is specialist-level and is 100% practical. PTS also weights OS/middleware and penetration testing more heavily (30% each vs 20% on PTE) and uniquely requires WebLogic, WebSphere, JBoss, Oracle, Redis, MongoDB, and internal-network methods.
What are the official CISP-PTS domain weights?
Web security 30%; operating systems and middleware 30%; data and logs 10%; penetration testing 30%. Those weights come from the CNITSEC CISP-PTE/PTS knowledge-system structure used by authorized training.
What language is the official CISP-PTS exam?
Official CISP-PTS is a Chinese-language practical assessment (officialLanguages: zh). This practice bank is an English-language MCQ study adaptation for people who prepare in English. It is not an official English sitting and not a translation of live tasks.
How much does CISP-PTS cost?
The November 2022 CNITSEC whitepaper lists CNY 19,800 authorized training plus CNY 8,000 exam-center fees (CNY 5,500 exam, CNY 1,000 registration, CNY 1,500 three-year annuity), totaling CNY 27,800. The listed retake fee is CNY 4,000. Fees are collected through authorized training institutions; confirm current amounts before you enroll.
How long is the CISP-PTS certificate valid?
Three years. After expiry, holders maintain the credential through a CNITSEC CISP offensive-domain maintenance examination rather than by sitting the original exam unchanged. The 2022 whitepaper lists a CISP-PTS maintenance package of CNY 6,000.
Can these practice questions replace official lab preparation?
No. CISP-PTS is a performance-based practical exam. Use these MCQs to rehearse specialist knowledge and decision-making (especially middleware, databases, methodology, and code-analysis concepts). You still need authorized training and hands-on lab practice for the official sitting.