All Practice Exams

100+ Free CISP-TRE Practice Questions

Prepare for the CISP-TRE Threat Response Engineer (注册威胁响应工程师, formerly CISP-IRE) exam with instant access — no signup required.

✓ No registration✓ No credit card✓ No hidden fees✓ Start practicing immediately
100+ Questions
100% Free

Loading practice questions...

2026 Statistics

Key Facts: CISP-TRE Exam

IRE→TRE on 2025-10-27

CNITSEC rename of CISP-IRE/IRS to CISP-TRE/TRS

https://www.itsec.gov.cn/zxxw/202510/t20251027_238753.html

20 MCQ + 80 practical

Official mixed sitting (100 points, 70 to pass)

CISP-IRE knowledge outline exam structure; TRE whitepaper continues objective-plus-practical for TRE

30% + 30%

Largest outline weights: IR fundamentals and typical enterprise incidents

CISP-IRE knowledge outline Table 2-1

CNY 3,000

Last published exam fee in the CNITSEC IRE/IRS whitepaper

https://www.itsec.gov.cn/ryzc/rsqsxz/PTE/201903/P020230103377205107558.pdf

3 years

Certificate validity; maintenance exam required after expiry

CNITSEC CISP-IRE/IRS whitepaper; TRE whitepaper restates three-year validity

Chinese (zh)

Official exam language; this bank is an English MCQ study adaptation

CNITSEC personnel-registration program practice

CISP-TRE is the renamed CISP-IRE threat-response engineer credential issued by CNITSEC. Official format is Chinese mixed assessment: 20 MCQ (20 pts) + practical (80 pts), 100 total, 70 to pass, typically 4 hours. Domain weights from the last published IRE outline are fundamentals 30% and typical enterprise incidents 30%, then analysis and handling 20%, overview 10%, and monitoring 10%. Authorized training is mandatory; no degree or experience proof is required. This 100-question English bank is a study aid, not the official 20-item paper or the 80-point lab.

Sample CISP-TRE Practice Questions

Try these sample questions to test your CISP-TRE exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.

1In the CISP-IRE/TRE knowledge system, what is the primary purpose of information-security incident response (应急响应)?
A.To guarantee that no intrusion can ever occur on a well-hardened network
B.To replace preventive controls such as patching, access control, and network segmentation
C.To prepare for sudden or major information-security events and take coordinated action after they occur so impact is limited and operations can resume
D.To prosecute attackers as the first and only objective of every ticket
Explanation: The IRE overview states that even the best infrastructure cannot guarantee that intrusion or other malicious activity will never occur. Incident response is the organization's plan, process, and trained people for preparing before events and acting after they occur. TRE study still uses this IRE framing after the 2025-10-27 rename.
2Which historical event is widely cited as the trigger for founding the first computer emergency response team (CERT/CC)?
A.The first publication of the PRC Cybersecurity Law
B.The 2017 WannaCry outbreak
C.The 1988 Morris worm incident
D.The creation of CNNVD by CNITSEC
Explanation: The 1988 Morris worm disrupted large parts of the early Internet and led Carnegie Mellon University's Software Engineering Institute to establish CERT/CC, the first widely recognized CSIRT. Chinese CISP-IRE materials list this as the origin story of international emergency-response organizations.
3Who issues the CISP-TRE (formerly CISP-IRE) personnel-registration certificate, and which body historically administers the offensive-defensive sitting?
A.MIIT issues the certificate; provincial public-security bureaus run the exam
B.CNCERT/CC issues the certificate; CNNVD runs the exam
C.China Information Technology Security Evaluation Center (CNITSEC) issues the certificate; the CISP offensive-defensive exam center, historically operated with Qianxin (奇安信), administers the exam
D.Qianxin issues the certificate independently without CNITSEC registration
Explanation: CNITSEC (中国信息安全测评中心) is the national body for CISP personnel registration. The CISP-IRE/IRS whitepaper on itsec.gov.cn is co-copyrighted with Qianxin NetHunter and names the CISP offensive-defensive exam center as the exam operator. The 2025-10-27 announcement renamed IRE/IRS to TRE/TRS without changing that CNITSEC issuance model.
4What did CNITSEC announce on 27 October 2025 regarding CISP-IRE and CISP-IRS?
A.Both credentials were withdrawn and replaced by CISP-PTE only
B.CISP-IRE became a 100-item English multiple-choice exam
C.CISP-IRE/IRS in the offensive-defensive domain were renamed CISP-TRE/TRS (注册威胁响应工程师/专家)
D.CISP-IRS was merged into core CISP (CISE/CISO) with no practical paper
Explanation: CNITSEC's 2025-10-27 news release on itsec.gov.cn renamed CISP offensive-defensive CISP-IRE/IRS to CISP-TRE/TRS. TRE remains the engineer-level threat-response identity. The last published knowledge system for this identity is still the IRE outline; this English bank is a study adaptation, not a new official English paper.
5In the CISP-IRE analysis subdomain, which four-level grading is used for cybersecurity incidents?
A.Red, yellow, green, and white operational colors only
B.Critical, high, medium, and informational CVSS ratings
C.Level I especially significant (特别重大), II significant (重大), III relatively large (较大), and IV general (一般)
D.P0 through P3 product-bug priorities copied from software ticketing
Explanation: The IRE outline's event-grading knowledge point uses the national four-level scale: I 特别重大, II 重大, III 较大, IV 一般, with I as the highest. Response start conditions and reporting paths follow that grade. CVSS and ticket priorities are different systems.
6Chapter 7 of the CISP-IRE outline groups typical enterprise incidents after the National Cybersecurity Incident Emergency Plan. Which four classes does it use?
A.Phishing, ransomware, insider threat, and cloud misconfiguration only
B.Confidentiality, integrity, availability, and non-repudiation events
C.Harmful-program events, network-attack events, information-destruction events, and other security events
D.Reconnaissance, weaponization, delivery, and exploitation from the Lockheed kill chain only
Explanation: IRE Chapter 7 explicitly maps to 有害程序事件, 网络攻击事件, 信息破坏事件, and 其它网络安全事件. Those four classes carry the 30% typical-event weight. CIA and kill-chain models are useful analysis lenses but are not the outline's event taxonomy.
7A SOC sees repeated failed logons but no confirmed account takeover and no service impact. How should CISP-IRE/TRE start-condition thinking treat this?
A.Always declare a Level I especially significant incident immediately
B.Ignore it because failed logons are never security events
C.Use documented start conditions to pick a response level—monitor or investigate as an alert, and escalate only if impact, asset criticality, or confirmation of compromise rises
D.Wipe the authentication server as the first action
Explanation: The overview subdomain requires understanding different start conditions and mapping them to response levels. Failed logons are worth detection and investigation, but grade and playbook—not a default Level I declaration or immediate destructive recovery.
8Which set best matches incident-response objectives in the CISP-IRE/TRE overview?
A.Keep the incident secret from legal, business, and national reporting channels in all cases
B.Maximize attacker dwell time so more IOCs can be collected indefinitely
C.Limit damage, eradicate the cause, restore operations, preserve evidence, and improve defenses
D.Rebuild every host in the enterprise before any containment
Explanation: IRE requires understanding IR goals and building a plan that meets them: stop the bleeding, remove the cause, restore service, keep forensic value, and feed lessons back into prevention. Indefinite dwell, blanket secrecy, or enterprise-wide rebuild-before-containment fight those goals.
9Which principle should guide writing an enterprise incident-response playbook (应急响应预案) under the IRE outline?
A.Write a one-page slogan with no roles, no contacts, and no decision criteria
B.Copy a foreign playbook verbatim and never test it
C.Define roles, start conditions, communication paths, evidence rules, and handling steps, then test and maintain the plan against realistic scenarios
D.Store the only copy on a compromised file server with no offline backup
Explanation: The outline requires mastering playbook principles and methods for different situations. A usable plan names who acts, when IR starts, how to communicate, how to preserve evidence, and what technical steps apply—then it is exercised. An untested slogan or a single copy on a possibly hit server fails that bar.
10The CISP-IRE handling flow uses six stages often taught as PDCERF. Which order is correct?
A.Eradicate, recover, detect, prepare, contain, follow-up
B.Detect, contain, prepare, eradicate, follow-up, recover
C.Prepare, detect, contain (抑制), eradicate, recover, follow-up (跟进)
D.Recover, follow-up, contain, detect, eradicate, prepare
Explanation: Outline section 6.3 lists 准备, 检测, 抑制, 根除, 恢复, and 跟进. Chinese IR training maps that sequence to PDCERF: Preparation, Detection, Containment, Eradication, Recovery, Follow-up. Skipping preparation or reversing contain/eradicate is a common exam trap.

About the CISP-TRE Exam

CISP-TRE (Certified Information Security Professional — Threat Response Engineer, 注册威胁响应工程师) is CNITSEC's national personnel-registration credential for threat monitoring, analysis, and incident response. On 27 October 2025 CNITSEC announced that CISP-IRE/IRS (注册应急响应工程师/专家) was renamed CISP-TRE/TRS. The last published knowledge system for this identity remains the CISP-IRE outline: overview, Windows/Linux IR fundamentals and logs, threat-intel monitoring, analysis and handling, and typical enterprise events. The official Chinese sitting mixes 20 multiple-choice items (20 points) with an 80-point practical; 70/100 passes. This bank is an English-language MCQ study adaptation of that knowledge and judgment — not a lab simulator and not an official translation.

Assessment

Mixed assessment under the CISP offensive-defensive exam center: 20 objective single-choice items (20 points) and practical operation items (80 points). Knowledge weights from the last published CISP-IRE outline: IR overview 10%, IR fundamentals 30%, incident monitoring 10%, analysis and handling 20%, typical enterprise incidents 30%. Official delivery language is Chinese (zh).

Time Limit

4 hours (240 minutes) per last published CISP-IRE computer-based sittings; confirm the current CISP-TRE session notice

Passing Score

70/100 (70 inclusive)

Exam Fee

CNY 3,000 exam fee in the last published CNITSEC CISP-IRE/IRS whitepaper; typical authorized package CNY 19,800 including training, registration, and 3-year annuity (China Information Technology Security Evaluation Center (CNITSEC / 中国信息安全测评中心); CISP offensive-defensive exam center historically operated with Qianxin (奇安信))

CISP-TRE Exam Content Outline

10%

Incident Response Overview (应急响应概述)

IR concepts and importance; CERT/CC and CNCERT/CC; PRC cyber-emergency law and policy; event classification principles; start conditions and response levels; IR objectives; playbook principles; general handling flow.

30%

Incident Response Fundamentals (应急响应基础)

Windows and Linux system, file, process, network, tool, and backdoor checks plus tracing; OS, web (Apache/Nginx), database, middleware, and security-product logs; IR toolkit use. Highest-weight knowledge domain.

10%

Incident Monitoring (应急响应事件监测)

Threat-intel source operations, IOC collection, WAF/IDS/IPS alert logs, network scanning, and traffic analysis with tcpdump and Wireshark.

20%

Analysis and Handling (应急响应分析与处置)

Understand the situation, type the event, estimate impact and severity, grade I–IV, write the response plan, execute PDCERF (prepare, detect, contain, eradicate, recover, follow-up), write the IR report, and track lessons learned.

30%

Typical Enterprise Incidents (企业应急响应典型事件)

Harmful programs (cryptomining, virus, worm, Trojan, botnet, blended, web-malware); network attacks (DDoS, backdoors, vulnerability exploitation, scanning/sniffing, phishing); information destruction (ransomware, tampering, spoofing, leakage, loss); other events (prohibited content, facility faults, disasters).

How to Pass the CISP-TRE Exam

What You Need to Know

  • Passing score: 70/100 (70 inclusive)
  • Assessment: Mixed assessment under the CISP offensive-defensive exam center: 20 objective single-choice items (20 points) and practical operation items (80 points). Knowledge weights from the last published CISP-IRE outline: IR overview 10%, IR fundamentals 30%, incident monitoring 10%, analysis and handling 20%, typical enterprise incidents 30%. Official delivery language is Chinese (zh).
  • Time limit: 4 hours (240 minutes) per last published CISP-IRE computer-based sittings; confirm the current CISP-TRE session notice
  • Exam fee: CNY 3,000 exam fee in the last published CNITSEC CISP-IRE/IRS whitepaper; typical authorized package CNY 19,800 including training, registration, and 3-year annuity

Keys to Passing

  • Work through all 100 available questions
  • Review every answer and explanation
  • Track weak areas and revisit them
  • Use our AI tutor for tough concepts

CISP-TRE Study Tips from Top Performers

1Treat the 80-point practical as the official exam: use these MCQs to lock decisions (contain vs wipe, which log, which event ID), then practice the same checks on isolated lab hosts.
2Memorize PDCERF in outline order: prepare, detect, contain (抑制), eradicate, recover, follow-up — and never skip evidence preservation before eradication.
3Windows Security 4624 (success) and 4625 (failure), plus logon type 10 for RDP and type 3 for network, are high-yield IR fundamentals.
4On Debian/Ubuntu read /var/log/auth.log; on RHEL-family hosts read /var/log/secure. Pair last/lastb with ss/ps and crontab/authorized_keys checks.
5Typical enterprise incidents are 30% of the outline — drill cryptomining CPU/network signs, ransomware isolation-and-restore, webshell webroot clues, and DDoS upstream mitigation, without exploit payloads.
6Official training and the sitting are in Chinese; keep the Chinese domain names (应急响应概述, 基础, 监测, 分析与处置, 典型事件) alongside these English stems.

Frequently Asked Questions

Is CISP-TRE the same credential as CISP-IRE?

Yes for identity continuity. CNITSEC announced on 27 October 2025 that CISP-IRE/IRS (注册应急响应工程师/专家) was renamed CISP-TRE/TRS (注册威胁响应工程师/专家). This bank preserves the historical CISP-IRE name and uses the last published IRE knowledge outline as the scope for TRE study.

How is the official CISP-TRE exam scored?

The last published IRE (now TRE) format is a mixed Chinese computer-based exam totaling 100 points: 20 single-choice items worth 20 points plus practical items worth 80 points. 70/100 (inclusive) is a pass. CISP-TRS is practical-only. This 100-question English bank is a study adaptation of knowledge and judgment, not a clone of the 20 official MCQs and not a lab simulator.

What language is the official exam delivered in?

Official delivery is Chinese (zh). CNITSEC has not published an official English sitting. These questions are an English-language MCQ study adaptation for people who research and prepare in English; they are not an official translation and do not reproduce the Chinese lab environment.

What knowledge domains and weights does CISP-TRE use?

The last published CISP-IRE knowledge outline (the TRE identity's last public CNITSEC syllabus) weights five domains: incident-response overview 10%, IR fundamentals (Windows/Linux/logs/tools) 30%, incident monitoring 10%, analysis and handling 20%, and typical enterprise incidents 30%.

Who issues CISP-TRE and who runs the exam?

China Information Technology Security Evaluation Center (CNITSEC / 中国信息安全测评中心) issues the credential. The CISP offensive-defensive exam center administers the sitting and has historically been operated with Qianxin (奇安信 / 奇安信网神信息技术), which co-published the IRE/IRS whitepaper on itsec.gov.cn.

What are the eligibility and fee rules?

No degree or work-experience proof is required, but authorized CISP offensive-defensive training is mandatory. The last published CNITSEC IRE/IRS whitepaper lists CNY 3,000 exam, CNY 500 registration, CNY 1,500 three-year annuity, CNY 14,800 training, CNY 19,800 typical package, and CNY 2,500 retake. Confirm current TRE fees with an authorized institution.

How long is the certificate valid?

Three years. After expiry, holders maintain the credential by taking a CISP-TRE maintenance exam rather than simply paying a fee. Last published IRE maintenance sittings used a shorter mixed paper; follow current TRE maintenance notices.