100+ Free CISP-TRE Practice Questions
Prepare for the CISP-TRE Threat Response Engineer (注册威胁响应工程师, formerly CISP-IRE) exam with instant access — no signup required.
Loading practice questions...
Explore More China CNITSEC CISP Personnel Registration Certifications (注册信息安全专业人员)
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
Key Facts: CISP-TRE Exam
IRE→TRE on 2025-10-27
CNITSEC rename of CISP-IRE/IRS to CISP-TRE/TRS
https://www.itsec.gov.cn/zxxw/202510/t20251027_238753.html
20 MCQ + 80 practical
Official mixed sitting (100 points, 70 to pass)
CISP-IRE knowledge outline exam structure; TRE whitepaper continues objective-plus-practical for TRE
30% + 30%
Largest outline weights: IR fundamentals and typical enterprise incidents
CISP-IRE knowledge outline Table 2-1
CNY 3,000
Last published exam fee in the CNITSEC IRE/IRS whitepaper
https://www.itsec.gov.cn/ryzc/rsqsxz/PTE/201903/P020230103377205107558.pdf
3 years
Certificate validity; maintenance exam required after expiry
CNITSEC CISP-IRE/IRS whitepaper; TRE whitepaper restates three-year validity
Chinese (zh)
Official exam language; this bank is an English MCQ study adaptation
CNITSEC personnel-registration program practice
CISP-TRE is the renamed CISP-IRE threat-response engineer credential issued by CNITSEC. Official format is Chinese mixed assessment: 20 MCQ (20 pts) + practical (80 pts), 100 total, 70 to pass, typically 4 hours. Domain weights from the last published IRE outline are fundamentals 30% and typical enterprise incidents 30%, then analysis and handling 20%, overview 10%, and monitoring 10%. Authorized training is mandatory; no degree or experience proof is required. This 100-question English bank is a study aid, not the official 20-item paper or the 80-point lab.
Sample CISP-TRE Practice Questions
Try these sample questions to test your CISP-TRE exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.
1In the CISP-IRE/TRE knowledge system, what is the primary purpose of information-security incident response (应急响应)?
2Which historical event is widely cited as the trigger for founding the first computer emergency response team (CERT/CC)?
3Who issues the CISP-TRE (formerly CISP-IRE) personnel-registration certificate, and which body historically administers the offensive-defensive sitting?
4What did CNITSEC announce on 27 October 2025 regarding CISP-IRE and CISP-IRS?
5In the CISP-IRE analysis subdomain, which four-level grading is used for cybersecurity incidents?
6Chapter 7 of the CISP-IRE outline groups typical enterprise incidents after the National Cybersecurity Incident Emergency Plan. Which four classes does it use?
7A SOC sees repeated failed logons but no confirmed account takeover and no service impact. How should CISP-IRE/TRE start-condition thinking treat this?
8Which set best matches incident-response objectives in the CISP-IRE/TRE overview?
9Which principle should guide writing an enterprise incident-response playbook (应急响应预案) under the IRE outline?
10The CISP-IRE handling flow uses six stages often taught as PDCERF. Which order is correct?
About the CISP-TRE Exam
CISP-TRE (Certified Information Security Professional — Threat Response Engineer, 注册威胁响应工程师) is CNITSEC's national personnel-registration credential for threat monitoring, analysis, and incident response. On 27 October 2025 CNITSEC announced that CISP-IRE/IRS (注册应急响应工程师/专家) was renamed CISP-TRE/TRS. The last published knowledge system for this identity remains the CISP-IRE outline: overview, Windows/Linux IR fundamentals and logs, threat-intel monitoring, analysis and handling, and typical enterprise events. The official Chinese sitting mixes 20 multiple-choice items (20 points) with an 80-point practical; 70/100 passes. This bank is an English-language MCQ study adaptation of that knowledge and judgment — not a lab simulator and not an official translation.
Assessment
Mixed assessment under the CISP offensive-defensive exam center: 20 objective single-choice items (20 points) and practical operation items (80 points). Knowledge weights from the last published CISP-IRE outline: IR overview 10%, IR fundamentals 30%, incident monitoring 10%, analysis and handling 20%, typical enterprise incidents 30%. Official delivery language is Chinese (zh).
Time Limit
4 hours (240 minutes) per last published CISP-IRE computer-based sittings; confirm the current CISP-TRE session notice
Passing Score
70/100 (70 inclusive)
Exam Fee
CNY 3,000 exam fee in the last published CNITSEC CISP-IRE/IRS whitepaper; typical authorized package CNY 19,800 including training, registration, and 3-year annuity (China Information Technology Security Evaluation Center (CNITSEC / 中国信息安全测评中心); CISP offensive-defensive exam center historically operated with Qianxin (奇安信))
CISP-TRE Exam Content Outline
Incident Response Overview (应急响应概述)
IR concepts and importance; CERT/CC and CNCERT/CC; PRC cyber-emergency law and policy; event classification principles; start conditions and response levels; IR objectives; playbook principles; general handling flow.
Incident Response Fundamentals (应急响应基础)
Windows and Linux system, file, process, network, tool, and backdoor checks plus tracing; OS, web (Apache/Nginx), database, middleware, and security-product logs; IR toolkit use. Highest-weight knowledge domain.
Incident Monitoring (应急响应事件监测)
Threat-intel source operations, IOC collection, WAF/IDS/IPS alert logs, network scanning, and traffic analysis with tcpdump and Wireshark.
Analysis and Handling (应急响应分析与处置)
Understand the situation, type the event, estimate impact and severity, grade I–IV, write the response plan, execute PDCERF (prepare, detect, contain, eradicate, recover, follow-up), write the IR report, and track lessons learned.
Typical Enterprise Incidents (企业应急响应典型事件)
Harmful programs (cryptomining, virus, worm, Trojan, botnet, blended, web-malware); network attacks (DDoS, backdoors, vulnerability exploitation, scanning/sniffing, phishing); information destruction (ransomware, tampering, spoofing, leakage, loss); other events (prohibited content, facility faults, disasters).
How to Pass the CISP-TRE Exam
What You Need to Know
- Passing score: 70/100 (70 inclusive)
- Assessment: Mixed assessment under the CISP offensive-defensive exam center: 20 objective single-choice items (20 points) and practical operation items (80 points). Knowledge weights from the last published CISP-IRE outline: IR overview 10%, IR fundamentals 30%, incident monitoring 10%, analysis and handling 20%, typical enterprise incidents 30%. Official delivery language is Chinese (zh).
- Time limit: 4 hours (240 minutes) per last published CISP-IRE computer-based sittings; confirm the current CISP-TRE session notice
- Exam fee: CNY 3,000 exam fee in the last published CNITSEC CISP-IRE/IRS whitepaper; typical authorized package CNY 19,800 including training, registration, and 3-year annuity
Keys to Passing
- Work through all 100 available questions
- Review every answer and explanation
- Track weak areas and revisit them
- Use our AI tutor for tough concepts
CISP-TRE Study Tips from Top Performers
Frequently Asked Questions
Is CISP-TRE the same credential as CISP-IRE?
Yes for identity continuity. CNITSEC announced on 27 October 2025 that CISP-IRE/IRS (注册应急响应工程师/专家) was renamed CISP-TRE/TRS (注册威胁响应工程师/专家). This bank preserves the historical CISP-IRE name and uses the last published IRE knowledge outline as the scope for TRE study.
How is the official CISP-TRE exam scored?
The last published IRE (now TRE) format is a mixed Chinese computer-based exam totaling 100 points: 20 single-choice items worth 20 points plus practical items worth 80 points. 70/100 (inclusive) is a pass. CISP-TRS is practical-only. This 100-question English bank is a study adaptation of knowledge and judgment, not a clone of the 20 official MCQs and not a lab simulator.
What language is the official exam delivered in?
Official delivery is Chinese (zh). CNITSEC has not published an official English sitting. These questions are an English-language MCQ study adaptation for people who research and prepare in English; they are not an official translation and do not reproduce the Chinese lab environment.
What knowledge domains and weights does CISP-TRE use?
The last published CISP-IRE knowledge outline (the TRE identity's last public CNITSEC syllabus) weights five domains: incident-response overview 10%, IR fundamentals (Windows/Linux/logs/tools) 30%, incident monitoring 10%, analysis and handling 20%, and typical enterprise incidents 30%.
Who issues CISP-TRE and who runs the exam?
China Information Technology Security Evaluation Center (CNITSEC / 中国信息安全测评中心) issues the credential. The CISP offensive-defensive exam center administers the sitting and has historically been operated with Qianxin (奇安信 / 奇安信网神信息技术), which co-published the IRE/IRS whitepaper on itsec.gov.cn.
What are the eligibility and fee rules?
No degree or work-experience proof is required, but authorized CISP offensive-defensive training is mandatory. The last published CNITSEC IRE/IRS whitepaper lists CNY 3,000 exam, CNY 500 registration, CNY 1,500 three-year annuity, CNY 14,800 training, CNY 19,800 typical package, and CNY 2,500 retake. Confirm current TRE fees with an authorized institution.
How long is the certificate valid?
Three years. After expiry, holders maintain the credential by taking a CISP-TRE maintenance exam rather than simply paying a fee. Last published IRE maintenance sittings used a shorter mixed paper; follow current TRE maintenance notices.