All Practice Exams

100+ Free NISP Level 1 — Security Awareness Practice Questions

Prepare for the National Information Security Proficiency Examination Level 1 — Security Awareness (国家信息安全水平考试一级-安全意识) exam with instant access — no signup required.

✓ No registration✓ No credit card✓ No hidden fees✓ Start practicing immediately
100+ Questions
100% Free

Loading practice questions...

Same family resources

Explore More China NISP National Information Security Proficiency Examinations (国家信息安全水平考试)

Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.

2026 Statistics

Key Facts: NISP Level 1 — Security Awareness Exam

50 objective items

Authorized-operator 2026 general sitting size (CNITSEC announcement does not restate a nationwide count)

nisp.org.cn 2026 NISP Level 1 exam schedule

100 minutes

Authorized-operator 2026 sitting window (18:00–19:40); the published 考试大纲 specifies 120 minutes for its mixed paper

nisp.org.cn 2026 NISP Level 1 exam schedule; CNITSEC Level 1 考试大纲

70%

Authorized-operator sitting pass mark (70/100)

nisp.org.cn NISP Level 1 introduction

Chinese (zh)

Official exam language

CNITSEC NISP program

Eight syllabus areas

Overview, laws, foundational technology, network, OS, applications, mobile, management

CNITSEC 《国家信息安全水平考试(一级)考试大纲》

Three Level-1 directions

Security awareness, security operations, and penetration testing (this bank is awareness only)

Xinhua, 2025-05-16

CNITSEC

Issuing and examining body (中国信息安全测评中心)

https://www.itsec.gov.cn/

CNITSEC NISP Level 1 Security Awareness is a Chinese computer-based exam for general information-system users. Authorized 2026 operator sittings commonly use 50 items, 100 minutes, and 70% to pass. The published outline covers eight awareness-level areas, not SOC operations or penetration testing. This page is an English MCQ study adaptation, not an official translation.

Sample NISP Level 1 — Security Awareness Practice Questions

Try these sample questions to test your NISP Level 1 — Security Awareness exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.

1A coworker photographs salary figures on your unlocked monitor and later posts them in a group chat. Which information-security property was primarily violated?
A.Confidentiality (机密性)
B.Availability (可用性)
C.Integrity (完整性)
D.Non-repudiation (不可否认性)
Explanation: Confidentiality (机密性) is the CIA property that limits information to authorized parties. Unauthorized viewing and sharing of salary data is a disclosure failure, which is the core of the CNITSEC Level 1 overview of information-security attributes.
2Someone changes a few cells in a shared grade spreadsheet so that scores look higher, but the file still opens normally. Which CIA property was primarily violated?
A.Availability (可用性)
B.Non-repudiation (不可否认性)
C.Integrity (完整性)
D.Confidentiality (机密性)
Explanation: Integrity (完整性) means information has not been altered or destroyed in an unauthorized way. Quietly changing stored scores is an integrity failure even when the file remains readable and the system stays up.
3A campus Wi-Fi flood keeps students from reaching the registration portal during course-selection hour. Which CIA property is primarily under attack?
A.Confidentiality (机密性)
B.Integrity (完整性)
C.Non-repudiation (不可否认性)
D.Availability (可用性)
Explanation: Availability (可用性) is the property that authorized users can use systems and services when needed. Resource-flooding that blocks legitimate access is a classic availability attack in the Level 1 overview.
4CNITSEC's Level 1 outline treats information security as having four historical stages whose meaning steadily widened. Which order is correct?
A.Communication security, information-system security, computer security, information assurance
B.Computer security, information-system security, communication security, information assurance
C.Communication security, computer security, information-system security, information assurance
D.Computer security, communication security, information-system security, information assurance
Explanation: The published Level 1 考试大纲 sample item states the sequence 通信安全 → 计算机安全 → 信息系统安全 → 信息安全保障 (communication security, computer security, information-system security, information assurance). Later stages add host, then system, then people/process/assurance concerns rather than replacing earlier ones.
5In NISP Level 1, what is the main idea of information assurance (信息安全保障) compared with older 'keep the secret' thinking?
A.Keeping message content secret in transit, as in the earliest communication-security stage
B.Physically protecting the computer room, cabinets, and equipment
C.Buying and installing security products such as antivirus and firewalls
D.Combining technology, management, people, and process across the information system's whole life cycle
Explanation: The Level 1 overview asks candidates to recall the concept and role of information assurance. Assurance covers confidentiality, integrity, availability and related attributes, and it combines technical controls with management across the information-system life cycle rather than treating security as encryption alone.
6Besides the CIA triad, Level 1 also expects you to recognize extra information-security attributes. Which pair is correctly matched?
A.Authenticity (真实性) confirms an origin or identity is genuine; non-repudiation (不可否认性) makes it hard to deny a prior action
B.Authenticity means a prior action cannot be denied; non-repudiation means the claimed identity is genuine
C.Authenticity is another word for availability; non-repudiation is another word for confidentiality
D.Authenticity means the data has not been altered; non-repudiation means the service stays reachable
Explanation: Level 1 overview items treat authenticity and non-repudiation as basic attributes alongside CIA. Authenticity is about a genuine source or identity; non-repudiation is about not being able to deny a completed action, often supported by digital signatures.
7The Level 1 outline asks you to grasp an information-assurance model with three kinds of content. Which grouping matches that model?
A.Confidentiality, integrity, and availability
B.Safeguard elements, life-cycle stages, and security characteristics
C.Prevention, detection, and response
D.Technology, management, and personnel
Explanation: The published 考试大纲 '领会' items for Part 1 include the contents and meaning of safeguard elements (保障要素), life cycle (生命周期), and security characteristics (安全特征) in the information-system assurance model. Those three strands are the model's axes; the safeguard elements are then broken down further into technology, management, engineering, and personnel.
8Why do information-security problems keep appearing in ordinary work and study, according to the Level 1 overview?
A.Because security is purely a product problem — buying the right software removes the risk
B.Because only large organisations hold information worth attacking, so ordinary users create the exposure
C.Because information has value, systems have weaknesses, and people, process, and technology can fail or be attacked
D.Because vulnerabilities exist only in outdated systems, so replacing the computer removes them
Explanation: The outline's '领会' line on the roots of information-security problems points to valuable information, inherent vulnerabilities, and the mix of human, process, and technical failures. Level 1 wants candidates to see security as more than a single product bug.
9Under the PRC Cybersecurity Law as amended by the NPC Standing Committee on 28 October 2025 and in force from 1 January 2026, which article currently sets the Multi-Level Protection Scheme and the operator duty to retain relevant network logs for at least six months?
A.Article 21 (the pre-2026 number, no longer current)
B.Article 23
C.Article 39
D.Article 27
Explanation: After the 2025 amendment (Presidential Order No. 61), the former Article 21 content was renumbered. Current Article 23 establishes 网络安全等级保护制度 and lists operator duties, including retaining relevant network logs for no less than six months.
10A network operator in China is writing the 2026 compliance checklist. Which statement about log retention is correct under current Cybersecurity Law Article 23?
A.Relevant network logs must be retained for no less than six months
B.Relevant network logs must be retained for no less than 30 days
C.Relevant network logs must be retained for no less than three years
D.Log retention is discretionary as long as an internal security management system exists
Explanation: Current Article 23 requires operators, under the Multi-Level Protection Scheme, to monitor and record network operating status and cybersecurity incidents and to retain relevant network logs for no less than six months (不少于六个月).

About the NISP Level 1 — Security Awareness Exam

NISP Level 1 — Security Awareness (国家信息安全水平考试一级-安全意识) is CNITSEC's entry-level national information-security proficiency exam for information-system users and non-security-major students. Xinhua reported on 16 May 2025 that CNITSEC split the Level 1 certificate into three directions — security awareness, security operations, and penetration testing. This bank covers only the general/awareness syllabus in 《国家信息安全水平考试(一级)考试大纲》: overview, laws, foundational technology, network protection, operating-system protection, application safety, mobile-terminal safety, and information-security management. The official exam is in Chinese. Authorized-operator 2026 sittings commonly use 50 objective items, 100 minutes, and a 70/100 pass mark; CNITSEC's public announcement does not restate that count. This independent English-language MCQ bank is a study aid only, not an official translation.

Assessment

Chinese-language online closed-book computer exam (线上闭卷机考) with face-recognition identity checks and remote proctoring; the paper is set centrally by CNITSEC. Current authorized-operator general sittings are all single-choice. The published CNITSEC 考试大纲 also specifies multiple-choice, material-completion, and case-study components. This page is an English-language single-answer MCQ study adaptation, not an official translation or format simulation.

Time Limit

100 minutes

Passing Score

70%

Exam Fee

RMB 480 for the bundled online study-and-exam package at authorized centres (training, exam, certificate, and two free retakes). CNITSEC's public announcement PDF does not restate a nationwide exam-only fee. (China Information Technology Security Evaluation Center (CNITSEC / 中国信息安全测评中心))

NISP Level 1 — Security Awareness Exam Content Outline

not-published

Information security overview

Information and IT concepts, four historical stages, CIA plus extra attributes, information assurance, and the information-assurance model.

not-published

Information security laws and regulations

Cybersecurity Law numbering in force from 1 January 2026, state secrets, commercial secrets, personal information, DSL classification concepts, and electronic-signature rules.

not-published

Foundational security technology

Symmetric/asymmetric crypto, hashes, hybrid encryption, digital signatures, authentication, PKI/CA, access control, and security audit.

not-published

Network security protection

TCP/IP basics, IPsec/TLS, VPN, firewalls, wireless AP hygiene, and common attacks including social engineering, phishing, sniffing, and denial of service.

not-published

Operating-system and application safety

Patches, unused services, Windows password/audit policy, malware and Trojans, browser, email, online banking, backup and ransomware defence, and password hygiene.

not-published

Mobile terminals and information-security management

Fake base stations, QR-code risks, lost-device steps, mobile malware, ISMS/PDCA, risk elements, incident grading, emergency response, and disaster backup.

How to Pass the NISP Level 1 — Security Awareness Exam

What You Need to Know

  • Passing score: 70%
  • Assessment: Chinese-language online closed-book computer exam (线上闭卷机考) with face-recognition identity checks and remote proctoring; the paper is set centrally by CNITSEC. Current authorized-operator general sittings are all single-choice. The published CNITSEC 考试大纲 also specifies multiple-choice, material-completion, and case-study components. This page is an English-language single-answer MCQ study adaptation, not an official translation or format simulation.
  • Time limit: 100 minutes
  • Exam fee: RMB 480 for the bundled online study-and-exam package at authorized centres (training, exam, certificate, and two free retakes). CNITSEC's public announcement PDF does not restate a nationwide exam-only fee.

Keys to Passing

  • Work through all 100 available questions
  • Review every answer and explanation
  • Track weak areas and revisit them
  • Use our AI tutor for tough concepts

NISP Level 1 — Security Awareness Study Tips from Top Performers

1Study official Chinese terms next to the English concepts: 机密性/完整性/可用性, 等级保护, 关键信息基础设施, 安全意识, 伪基站.
2For Cybersecurity Law items, use the numbering in force from 1 January 2026: Article 23 (MLPS and operator duties, including logs for at least six months), Article 27 (incident emergency plan / start immediately / report), Article 39 (CII personal information and important data stored in China, with security assessment before outbound transfer). Do not cite the pre-2026 numbers (21 / 25 / 37) as current.
3This direction is end-user awareness, not SOC engineering or penetration testing. Prioritize browser, email, password, online-banking, mobile, and backup hygiene over SIEM, SOAR, or exploit steps.
4The published outline weights application safety heavily (browser, email, banking, backup, passwords). Practice those scenarios more than advanced cryptography.

Frequently Asked Questions

Is the official NISP Level 1 Security Awareness exam in English?

No. OfficialLanguages is Chinese (zh). CNITSEC delivers NISP in Chinese. This bank is an English-language MCQ study adaptation, not an official translation and not a simulation of the Chinese exam environment.

How is this different from NISP Level 1 Security Operations and Penetration Tester?

Xinhua reported on 16 May 2025 that CNITSEC split Level 1 into three directions: 安全意识 (security awareness), 安全运营 (security operations), and 渗透测试 (penetration testing). This bank is the general/awareness syllabus only. The operations bank covers SOC products and workflow; the penetration-tester bank covers introductory pentest and web/host vulnerabilities. Do not use this page as a substitute for those direction sittings.

How many questions are on the official exam?

Authorized-operator 2026 general sittings use 50 single-choice items worth 2 marks each. CNITSEC's published Level 1 考试大纲 still specifies a mixed 100-mark paper — 40 marks single-choice, 10 multiple-choice, 20 material-completion, 30 case study, which are mark allocations rather than item counts — and the 2025-04-17 certificate announcement does not restate a nationwide item count. This site's 100 English items are a study bank, not the official length.

What are the time limit and passing score?

Authorized-operator 2026 monthly sittings are scheduled 18:00–19:40 (100 minutes) with 70/100 (70%) to pass. The published CNITSEC 考试大纲 lists 120 minutes for a mixed paper. Treat 100 minutes / 70% as operator sitting logistics unless CNITSEC restates a nationwide figure.

What does the general Level 1 outline cover?

Eight areas: information-security overview, laws and regulations, foundational technology, network protection, operating-system protection, application safety (browser, banking, email, passwords, backup), mobile-terminal safety, and information-security management. It is awareness-level content for non-security-major students and ordinary information-system users.

Who issues the certificate?

China Information Technology Security Evaluation Center (CNITSEC / 中国信息安全测评中心). Training and computer sittings are commonly delivered by authorized NISP operators. CNITSEC's 15 April 2025 announcement (published 17 April 2025) changed new Level 1 certificates to a simplified single-page paper form from 1 January 2025; previously issued certificates with covers remain valid.