100+ Free CISP-SSDP Practice Questions
Prepare for the CISP-SSDP Software Security Development Professional (注册信息安全专业人员-软件安全开发专业人员) exam with instant access — no signup required.
Loading practice questions...
Explore More China CNITSEC CISP Personnel Registration Certifications (注册信息安全专业人员)
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
Key Facts: CISP-SSDP Exam
70/100
Official passing score (inclusive) on the mixed CISP-SSDP exam
CNITSEC CISP-SSDP knowledge-system outline, 11 October 2025, §2.2
20 + 80
Official score split: 20 multiple-choice points and 80 practical points
CNITSEC CISP-SSDP knowledge-system outline, 11 October 2025, §2.2
30%
Largest knowledge class: software-security development practice
CNITSEC CISP-SSDP knowledge-system outline, 11 October 2025, Table 2-1
3 years
CISP-SSDP certificate validity before operations-center maintenance
CNITSEC/Venustech CISP-SSDP white paper, October 2025
RMB 1,000
Official examination fee (考试费), excluding training and registration
CNITSEC/Venustech CISP-SSDP white paper, October 2025, fee table
CISP-SSDP is CNITSEC's software-security development credential, co-developed with Venustech. The official exam is mixed: 20 points multiple-choice and 80 points practical, with 70/100 to pass. Content follows the 11 October 2025 outline (laws 10%, foundations 10%, core 20%, DevSecOps 20%, governance/supply chain 10%, practice 30%). This page offers 100 free English MCQs as a study aid, not an official translation or practical-lab simulation.
Sample CISP-SSDP Practice Questions
Try these sample questions to test your CISP-SSDP exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.
1According to the CISP-SSDP information-assurance knowledge domain, which trio is the CIA triad that software security attributes must protect?
2The CISP-SSDP outline treats cyberspace as which kind of national domain?
3How does the CISP-SSDP knowledge system describe the relationship between cybersecurity and informatization?
4A CISP-SSDP holder is asked to use personal offensive-security skill to help a friend break into a competitor's business system. What does the professional code of ethics require?
5Which pairing best matches the primary focus of China's three core cybersecurity statutes that CISP-SSDP candidates must distinguish?
6When a software product supports a critical information infrastructure (CII) operator, which legal expectation is most consistent with China's cybersecurity legal system?
7A Chinese software organization must pick information-security standards. Which statement matches the CISP-SSDP standards knowledge domain?
8Which description of China's Multi-Level Protection Scheme (MLPS / 等级保护) is most accurate for a CISP-SSDP candidate?
9A product stores customer profiles and also trains models on industrial telemetry. Under the CISP-SSDP legal knowledge class, which split is the sound first compliance cut?
10A software vendor sells a SaaS platform to Chinese critical sectors and also uses overseas subprocessors. Which governance action best reflects CISP-SSDP legal and standards knowledge?
About the CISP-SSDP Exam
CISP-SSDP (Certified Information Security Professional — Software Security Development Professional; 注册信息安全专业人员-软件安全开发专业人员) is China's CNITSEC personnel-registration credential for software developers, architects, testers, project managers, and infrastructure maintainers who must build security into the software lifecycle. The official 11 October 2025 knowledge-system outline, co-published with Venustech (启明星辰), covers six knowledge classes: cybersecurity laws and regulations; software-security foundations including SDLC versus SSDLC; secure-development core (requirements, threat modeling, architecture, secure coding, SAST, DAST, fuzzing); advanced protection and DevSecOps (IAST, RASP, penetration-testing methodology, SCA, CI/CD, monitoring); governance and software supply-chain protection; and hands-on software-security practice. The real exam is mixed (20 MCQ points + 80 practical points, 70% pass) and delivered in Chinese. This OpenExamPrep bank is an English-language MCQ study adaptation of that outline.
Assessment
Mixed computer-based credential exam: objective items worth 20 points plus practical items worth 80 points. Knowledge-class weights are cybersecurity laws 10% (objective), software-security foundations 10% (objective), secure-development core 20% (objective + practical), advanced protection and DevSecOps 20% (objective + practical), governance and supply-chain protection 10% (objective + practical), and software-security development practice 30% (objective + practical).
Time Limit
Not published in the official 11 October 2025 CISP-SSDP knowledge-system outline
Passing Score
70 out of 100 points (70%), inclusive
Exam Fee
RMB 1,000 examination fee (考试费); authorized training RMB 9,800; registration RMB 500; three-year annuity RMB 1,500; retake RMB 500 (China Information Technology Security Evaluation Center (CNITSEC / 中国信息安全测评中心), with Venustech (北京启明星辰信息安全技术有限公司) as R&D, training, and operations partner)
CISP-SSDP Exam Content Outline
Cybersecurity Laws and Regulations (网络安全法律法规)
Cyber power strategy, cyberspace as a sovereignty domain, CIA and information-assurance frameworks, China's cybersecurity legal system (including the Cybersecurity Law, Data Security Law, and Personal Information Protection Law), professional ethics, and domestic/international information-security standards
Software Security Foundations (软件安全基础概述)
Software characteristics, the three software crises, enterprise and supply-chain risk, traditional SDLC models, the cost of late-stage security, shift-left, and SSDLC stages from requirements through operations
Secure Software Development Core (软件安全开发核心)
Security-requirement sources and user stories, STRIDE and DFD threat modeling, secure design principles and identity/API patterns, GB/T 38674-2020 secure coding, SAST, DAST, and fuzz testing
Advanced Protection and DevSecOps (高级防护与DevSecOps)
IAST and RASP, black/white/gray-box penetration-testing methodology, SCA and SBOM, CI/CD and IaC security, OS/middleware/container/cloud hardening, SIEM, and incident response
Software Security Governance and Supply-Chain Protection (软件安全治理与供应链防护)
COBIT and NIST CSF-style governance, security culture, compliance and software-security audit, dependency and vendor risk, code signing, pipeline hardening, and AI-generated-code review
Software Security Development Practice (软件安全开发实践)
Conceptual identification and code-level defenses for injection, XSS, CSRF, IDOR, file upload, SSRF, insecure deserialization, API BOLA/BFLA, weak crypto, and SAST/DAST/SCA/CI/CD tool practice without exploit payloads
How to Pass the CISP-SSDP Exam
What You Need to Know
- Passing score: 70 out of 100 points (70%), inclusive
- Assessment: Mixed computer-based credential exam: objective items worth 20 points plus practical items worth 80 points. Knowledge-class weights are cybersecurity laws 10% (objective), software-security foundations 10% (objective), secure-development core 20% (objective + practical), advanced protection and DevSecOps 20% (objective + practical), governance and supply-chain protection 10% (objective + practical), and software-security development practice 30% (objective + practical).
- Time limit: Not published in the official 11 October 2025 CISP-SSDP knowledge-system outline
- Exam fee: RMB 1,000 examination fee (考试费); authorized training RMB 9,800; registration RMB 500; three-year annuity RMB 1,500; retake RMB 500
Keys to Passing
- Work through all 100 available questions
- Review every answer and explanation
- Track weak areas and revisit them
- Use our AI tutor for tough concepts
CISP-SSDP Study Tips from Top Performers
Frequently Asked Questions
What is CISP-SSDP and who issues it?
CISP-SSDP (Certified Information Security Professional — Software Security Development Professional; 注册信息安全专业人员-软件安全开发专业人员) is issued by the China Information Technology Security Evaluation Center (CNITSEC / 中国信息安全测评中心). Venustech (北京启明星辰信息安全技术有限公司) is the official R&D, training, and operations partner.
What is the official exam format and passing score?
The 11 October 2025 knowledge-system outline states that the exam uses multiple-choice and practical items totaling 100 points: 20 points for multiple-choice and 80 points for practical work. A score of 70 or above (inclusive) is a pass. Session length is not published in that outline.
Is this practice bank an official Chinese exam simulation?
No. The official assessment is delivered in Chinese and is mixed MCQ plus practical. OpenExamPrep publishes one English-language MCQ study bank at this URL as a study aid. It is not an official translation, not a practical-lab simulator, and not a substitute for authorized training.
Are there education or experience prerequisites?
The October 2025 white paper states there is no education or work-experience requirement. Candidates should have basic software-development ability or intend to work in software development, complete authorized training, pass the exam, accept the professional code of ethics, and complete registration.
What does the credential cost, and how long is it valid?
The October 2025 white paper lists RMB 9,800 training, RMB 1,000 exam, RMB 500 registration, and RMB 1,500 three-year annuity (RMB 12,800 combined), with a RMB 500 retake fee. The certificate is valid for three years and must be maintained through the operations center.
What topics are weighted on the official outline?
Cybersecurity laws 10%, software-security foundations 10%, secure-development core 20%, advanced protection and DevSecOps 20%, governance and supply-chain protection 10%, and software-security development practice 30%.