All Practice Exams

100+ Free CNITSEC CISM Practice Questions

Prepare for the CNITSEC Certified Information Security Member (注册信息安全员) exam with instant access — no signup required.

✓ No registration✓ No credit card✓ No hidden fees✓ Start practicing immediately
100+ Questions
100% Free

Loading practice questions...

2026 Statistics

Key Facts: CNITSEC CISM Exam

100

Official single-choice items

CNITSEC CISM Knowledge-System Outline v3.0

2 hours

Official time limit

CNITSEC CISM Knowledge-System Outline v3.0

70/100

Passing score (inclusive)

CNITSEC CISM Knowledge-System Outline v3.0

20/50/30

Assurance / technology / management weights

CNITSEC CISM Knowledge-System Outline v3.0 Table 1-1

Not ISACA

CNITSEC 注册信息安全员, not ISACA Certified Information Security Manager

CNITSEC outline vs ISACA CISM

18 hours

Official 3-day authorized training outline

CNITSEC CISM Knowledge-System Outline v3.0 Table 1-2

CNITSEC CISM (注册信息安全员 / Certified Information Security Member) is China's entry-level CNITSEC personnel exam, not ISACA CISM. Official format: 100 single-choice items, 2 hours, 70/100 to pass, weights 20/50/30. This page is an English MCQ study adaptation of the Chinese outline still listed on itsec.gov.cn (v3.0, 2015).

Sample CNITSEC CISM Practice Questions

Try these sample questions to test your CNITSEC CISM exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.

1In information security, the three basic elements of the CIA triad (机密性、完整性、可用性) are which of the following?
A.Authentication, authorization, and accounting
B.Confidentiality, integrity, and availability
C.Policy, protection, detection, and response
D.People, technology, and operations
Explanation: The CNITSEC CISM outline requires mastery of information security's three basic elements: confidentiality (机密性), integrity (完整性), and availability (可用性)—the CIA triad. Authentication/authorization/accounting is an identity-management model, P2DR is a process model, and people/technology/operations are IATF defense-in-depth aspects.
2Confidentiality (机密性) is primarily concerned with which outcome?
A.Preventing unauthorized modification of data
B.Ensuring systems remain usable when authorized users need them
C.Proving that a sender cannot later deny having sent a message
D.Preventing unauthorized disclosure of information
Explanation: Confidentiality means information is disclosed only to authorized parties. Unauthorized modification is integrity, timely usable access is availability, and non-repudiation is a related but separate security property often provided by digital signatures.
3A payroll file is altered so that several employees' salaries increase without authorization, but the file remains readable only to payroll staff. Which CIA property was violated?
A.Confidentiality
B.Availability
C.Integrity
D.Non-repudiation
Explanation: Integrity is the property that information is not created, changed, or destroyed in an unauthorized way. The file was not disclosed more widely (confidentiality held) and it remained usable (availability held). Non-repudiation concerns denying an action, which is not the issue described.
4A ransomware incident encrypts file shares so that authorized staff cannot open business records for two days. Which CIA property is most directly lost?
A.Confidentiality of the encryption keys
B.Availability
C.Integrity of backup media labels
D.Authenticity of user identities
Explanation: Availability means authorized users can access information and systems when needed. Ransomware that locks records for days is a classic availability impact, even if confidentiality and integrity issues may also appear later. The question asks which property is most directly lost.
5Which set best represents typical information-security threats that an information security member should be able to recognize?
A.Only nation-state cryptographic attacks against classified networks
B.Only accidental hardware wear-out inside the data center
C.Malware, social engineering, insider misuse, natural disasters, and technical failures
D.Only denial-of-service floods on public websites
Explanation: The CISM outline asks candidates to understand typical security threats. Threats include deliberate attacks (malware, social engineering), insiders, environmental/natural events, and technical failures. Narrowing the set to one actor or one failure mode under-prepares an entry-level member.
6A recurring finding in information-security practice is that problems rarely have a single technical root. Which statement best describes common sources of information-security problems?
A.Only missing antivirus signatures on endpoints
B.Only the absence of a national cryptographic algorithm
C.Only physical perimeter fences around the computer room
D.Weaknesses in people, processes, and technology, often combined with poor management
Explanation: Information-security problems typically arise from people (errors, insiders, social engineering), processes (missing procedures, poor change control), technology (vulnerabilities, misconfiguration), and management (unclear ownership, underfunding). Treating antivirus, a national algorithm, or a fence as the sole source is too narrow.
7Chinese information-security teaching commonly describes the field's development as moving through which sequence of stages?
A.Cloud security, then mobile security, then IoT security, then AI security
B.ISO 27001, then PCI DSS, then NIST CSF, then Zero Trust
C.Communication secrecy, then computer security, then information-system security, then information assurance
D.Firewall deployment, then SIEM, then SOAR, then XDR
Explanation: CNITSEC/CISP teaching typically frames development as communication secrecy (通信保密), computer security (计算机安全), information-system security (信息系统安全), and information assurance (信息保障). Product generations and Western framework lists are not that historical staging.
8Information assurance (信息保障), as used in the CNITSEC CISM knowledge system, is best described as which of the following?
A.Installing a single perimeter firewall and declaring the organization secure
B.A comprehensive, mission-oriented approach to protecting information and the systems that process it across people, operations, and technology
C.Encrypting every file with a consumer password zip tool
D.Outsourcing all security work so the organization has no residual risk
Explanation: Information assurance is broader than a gadget or a one-time control. It protects information and supporting systems so the mission can continue, combining technical safeguards with operations and people. A single firewall, zip passwords, or outsourcing cannot by themselves provide assurance or eliminate residual risk.
9In information-assurance thinking, how are mission, information systems, risk, and assurance related?
A.The mission exists only to justify buying more firewalls
B.Risk should be maximized so that assurance spending looks necessary
C.Information systems should be isolated from the mission so security is easier
D.Assurance measures manage risk to information systems so the mission can be accomplished
Explanation: The outline asks candidates to understand the relationship among systems, risk, assurance, and mission. Systems exist to support the mission; they face risk; assurance is the set of measures that keep residual risk acceptable so the mission can proceed. Security that ignores the mission, or that seeks more risk, is the opposite of that model.
10The information-system security-assurance model used in CNITSEC teaching is commonly described along which three dimensions?
A.CPU, memory, and disk
B.Sales, marketing, and legal
C.IPv4, IPv6, and MPLS
D.Security characteristics, assurance elements, and lifecycle
Explanation: The CISM outline requires understanding the assurance model's elements, lifecycle, and security characteristics. CNITSEC teaching treats those as three dimensions: security characteristics (CIA and related properties), assurance elements (strategy, management, technology, engineering), and lifecycle (plan, design, implement, operate, dispose). Hardware layers, business departments, and network protocols are not that model.

About the CNITSEC CISM Exam

CNITSEC CISM is 注册信息安全员 (English: Certified Information Security Member), the entry-level information-security personnel registration issued by China's Information Technology Security Evaluation Center. It is not ISACA's Certified Information Security Manager (exam id cism). The official Chinese paper has 100 single-choice questions in 2 hours with a 70-point pass, weighted 20% assurance fundamentals (CIA, models, IATF/PDCA, China policy), 50% technology (crypto and network security, endpoint and data security, attacks and defense), and 30% management (risk, MLPS classified protection, incident response and disaster recovery, ISMS controls). This bank is an English-language MCQ study adaptation, not an official translation.

Assessment

One 100-item single-choice paper weighted 20% information-security assurance fundamentals, 50% information-security technology, and 30% information-security management, as specified in the CNITSEC CISM Knowledge-System Outline v3.0 (2015).

Time Limit

2 hours (120 minutes)

Passing Score

70/100 (70% inclusive)

Exam Fee

RMB 300 exam fee on the CNITSEC 2017 authorized-training schedule; packaged training-plus-exam prices are set by authorized organizations (China Information Technology Security Evaluation Center (CNITSEC / 中国信息安全测评中心))

CNITSEC CISM Exam Content Outline

20%

Information Security Assurance Fundamentals (信息安全保障基础)

CIA triad, typical threats and problem sources, information-assurance models, PDCA, IATF people/technology/operations and four technology focus areas, plus China's laws, policies, and standards system

50%

Information Security Technology (信息安全技术)

Cryptography (including SM2/SM3/SM4), PKI, firewalls, IDS/IPS, VPNs, OS/browser and data protection, malware, and attack-and-defense methods including authorized penetration testing

30%

Information Security Management (信息安全管理)

Security-management and risk fundamentals, MLPS classified protection, incident response, disaster recovery (RTO/RPO and capability levels), and ISMS/ISO 27000 control measures

How to Pass the CNITSEC CISM Exam

What You Need to Know

  • Passing score: 70/100 (70% inclusive)
  • Assessment: One 100-item single-choice paper weighted 20% information-security assurance fundamentals, 50% information-security technology, and 30% information-security management, as specified in the CNITSEC CISM Knowledge-System Outline v3.0 (2015).
  • Time limit: 2 hours (120 minutes)
  • Exam fee: RMB 300 exam fee on the CNITSEC 2017 authorized-training schedule; packaged training-plus-exam prices are set by authorized organizations

Keys to Passing

  • Work through all 100 available questions
  • Review every answer and explanation
  • Track weak areas and revisit them
  • Use our AI tutor for tough concepts

CNITSEC CISM Study Tips from Top Performers

1Keep CNITSEC CISM (注册信息安全员) and ISACA CISM (Certified Information Security Manager) on separate study maps; domain names look similar and will mix you up.
2Spend about half your time on technology (crypto, network devices, endpoint/data, attacks), then 30% on management including MLPS, IR/DR, and ISMS, and 20% on CIA/models/China policy.
3Memorize CIA, PDCA, IATF people/technology/operations plus the four technology focus areas, and SM2 (public-key), SM3 (hash), SM4 (block cipher).
4For classified protection, know five MLPS levels and that China's Cybersecurity Law requires network operators to implement the classified-protection system.
5Drill RTO versus RPO and the idea of six disaster-recovery capability levels in China's national DR specification (GB/T 20988), with Level 6 as zero data loss and remote cluster support.
6Treat this English bank as concept practice; the official paper is Chinese single-choice.

Frequently Asked Questions

Is this the same exam as ISACA CISM?

No. This is CNITSEC 注册信息安全员 (Certified Information Security Member), China's entry-level information-security personnel registration under 中国信息安全测评中心. ISACA CISM is Certified Information Security Manager, a different international management certification (150 questions, 4 hours, 450/800 scaled pass) already published on this site as exam id cism. Do not mix the two outlines, fees, or experience rules.

What is the official CNITSEC CISM exam format?

The CNITSEC CISM Knowledge-System Outline v3.0 (released 30 January 2015 and still listed on itsec.gov.cn 2026 downloads) specifies 100 single-choice questions in 2 hours, 1 point each, with 70 or higher (inclusive) required to pass. The official assessment is in Chinese. These practice items are an English-language MCQ study adaptation, not an official translation or a simulation of the Chinese-language sitting.

What are the official domain weights?

Table 1-1 of the official outline weights Information Security Assurance Fundamentals at 20%, Information Security Technology at 50%, and Information Security Management at 30%. Optional information-security engineering and local/industry modules are customized outside the national scored paper.

How does CNITSEC CISM relate to CISP?

CISM (注册信息安全员) is the member/entry tier. CISP (注册信息安全专业人员) is the professional credential above it, with longer authorized training and a broader professional knowledge system. Specialist CISP tracks such as CISP-PTE, CISP-PTS, CISP-DSG, CISP-TRE, and CISP-SSDP sit on that professional family, not on this member exam.

How do I register and what does it cost?

CNITSEC uses authorized training organizations rather than open public self-scheduling. The last CNITSEC authorized-training fee schedule located (January 2017) listed CISM training RMB 2,100, exam RMB 300, registration RMB 200, three-year annuity RMB 300 (RMB 2,900 packaged) and a RMB 150 retake. Confirm the current package with an authorized organization listed via itsec.gov.cn.

Does the 2015 outline still mention Windows 7 and Internet Explorer?

The v3.0 course table still names Windows 7 and IE as desktop examples, but those products are obsolete. Study the durable controls—patching, least privilege, browser hygiene, email/IM caution, encryption, DLP, and backup—rather than retired desktop trivia.