All Practice Exams

Free Practice Questions for BTS SIO

Exam-style questions and explanations by OpenExamPrep.

✓ No registration✓ No credit card
100+ Questions
100% Free

Loading practice questions...

Exam Review

Key Facts: BTS SIO Exam

Level 5 (Bac+2)

RNCP and EQF vocational qualification level

France compétences RNCP40792

10/20

Minimum overall weighted average required to graduate

Code de l'éducation, art. D. 643-1

22

Total compulsory coefficients across all examination units

Arrêté du 29 avril 2019 modifié, règlement d'examen

120 ECTS

European Credit Transfer and Accumulation System credits awarded

Arrêté du 29 avril 2019 modifié

10 weeks

Mandatory professional internship duration in an organization

Référentiel BTS SIO Éduscol

RNCP40792

Official national registry identifier for BTS SIO

France compétences

The BTS SIO is an active French national Level 5 qualification (Bac+2, 120 ECTS) certified by the Ministry of Higher Education and administered by regional académies. Regulated by the Arrêté du 29 avril 2019 as modified in 2024 (RNCP40792), it equips students for IT careers through two options: SISR (infrastructure and networks) and SLAM (software applications and development). Seven compulsory examination units total 22 coefficients, combining national written examinations (including E7 Cybersecurity and E4 CEJM) with oral project defenses (E5, E6). Graduation requires an overall weighted average of at least 10/20. While the official assessment is held in French, OpenExamPrep's 100 English MCQs provide an essential study adaptation covering ITIL support, infrastructure administration, database design, OOP, and cybersecurity regulations.

Sample BTS SIO Practice Questions

Try these sample questions to review concepts for the BTS SIO exam. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.

1What is the primary role of an IT Asset Management tool such as GLPI integrated with a Configuration Management Database (CMDB)?
A.To track, inventory, and manage the complete lifecycle, configuration, software licenses, and maintenance contracts of all hardware and digital assets across the organization
B.To automatically compile C++ programs into machine code on user workstations
C.To replace the corporate router and perform BGP dynamic routing
D.To encrypt local hard drives with BitLocker without administrator credentials
Explanation: IT Asset Management systems (like GLPI, often paired with OCS Inventory or FusionInventory) maintain an up-to-date repository of hardware, installed software, peripherals, network equipment, warranties, and service contracts throughout their entire lifecycle.
2In the ITIL 4 service management framework, what is the primary purpose of the Service Desk practice?
A.To serve as the single point of contact (SPOC) between the service provider and all users for incident reporting and service requests
B.To manufacture custom electrical cables for data centers
C.To conduct criminal forensic investigations for national law enforcement
D.To write production code for enterprise relational database engines
Explanation: Under ITIL 4, the Service Desk serves as the Single Point of Contact (SPOC) for users, capturing demand for incident resolution and service requests, communicating outages, and coordinating tier-1 and tier-2 support workflows.
3What is the fundamental difference between an Incident and a Service Request according to ITIL terminology?
A.An Incident is an unplanned interruption or reduction in quality of a service, whereas a Service Request is a formal user request for a standard service, asset, or advice
B.An Incident is always caused by hackers, whereas a Service Request is caused by hardware failure
C.An Incident requires purchasing new servers, whereas a Service Request is free
D.There is no difference; ITIL treats them as identical tickets
Explanation: An Incident is an unplanned failure, error, or performance degradation of an existing IT service (e.g., email server down, printer offline). A Service Request is a routine user request for something predefined (e.g., password reset, new laptop requisition, access to a shared folder).
4What is a Service Level Agreement (SLA) in professional IT service delivery?
A.A documented agreement between an IT service provider and a customer that identifies both services required and the expected level of service, including response and resolution times
B.A hardware warranty card packaged inside a computer box
C.A criminal nondisclosure agreement signed by employees
D.A software license key for activating Microsoft Windows
Explanation: An SLA is a formal negotiated agreement defining the scope, quality, availability, response time (GTR/GTI in French contracts: Garantie de Temps de Réponse / Garantie de Temps d'Intervention), and resolution time of IT services between the provider and customer.
5In an IT support ticketing system (e.g., GLPI, Jira Service Management), what does setting a ticket status to 'Pending' ('En attente') typically signify?
A.The ticket is waiting for necessary input, feedback, or verification from the user or an external third-party vendor before work can resume
B.The technician has permanently deleted the ticket from the database
C.The issue has been completely fixed and the ticket is permanently closed
D.The entire IT department is offline
Explanation: The 'Pending' status pauses SLA resolution timers while the support technician waits for required information, confirmation, or action from the reporting user or an external equipment supplier.
6Which standard remote desktop protocol natively integrated into Windows operating systems allows IT support technicians to access and control a remote workstation over TCP port 3389?
A.RDP (Remote Desktop Protocol)
B.FTP (File Transfer Protocol)
C.SNMP (Simple Network Management Protocol)
D.SMTP (Simple Mail Transfer Protocol)
Explanation: Microsoft Remote Desktop Protocol (RDP) operates on TCP port 3389 and provides graphical remote access and management for Windows workstations and servers. FTP is for file transfer (port 21), SNMP is for network monitoring (port 161), and SMTP is for sending email (port 25).
7How do the objectives of Incident Management differ from Problem Management in ITIL 4?
A.Incident Management aims to restore normal service operation as quickly as possible with minimal business disruption, while Problem Management aims to identify root causes and eliminate recurring incidents
B.Incident Management writes software, while Problem Management installs network cabling
C.Incident Management is performed by end-users, while Problem Management is handled by HR
D.There is no difference; they are performed by the same automated bot
Explanation: Incident Management focuses on rapid service restoration (often using temporary workarounds). Problem Management investigates the underlying root causes of past or potential incidents, develops permanent fixes, and prevents recurring disruptions.
8What is the purpose of the Known Error Database (KEDB) in ITIL Problem Management?
A.To store documented root causes of problems and their approved temporary workarounds, allowing support technicians to resolve matching incidents rapidly
B.To list all employees who have made procedural mistakes for disciplinary review
C.To block known malicious IP addresses at the perimeter firewall
D.To store expired SSL certificates
Explanation: The KEDB maintains records of identified 'known errors' (problems with an analyzed root cause and a documented workaround). When a new incident occurs, technicians search the KEDB to immediately apply the proven workaround while a permanent fix is engineered.
9In ITIL Change Enablement (formerly Change Management), what is the role of the Change Advisory Board (CAB)?
A.To assess the business risks, technical impacts, resource requirements, and scheduling of proposed changes before authorizing deployment
B.To physically install RAM and hard drives into servers
C.To write marketing brochures for external customers
D.To audit the financial tax filings of the corporate board
Explanation: The Change Advisory Board (CAB) is a cross-functional body composed of IT leaders, technical experts, and business stakeholders that reviews, assesses risks, evaluates rollback plans, and authorizes normal changes to production environments to prevent unintended outages.
10A production database server operates during a 30-day month (720 total operating hours). During this month, the server suffers 3 unscheduled outages lasting 2 hours, 1 hour, and 3 hours respectively (total downtime = 6 hours). What is the Mean Time To Repair (MTTR) and the Mean Time Between Failures (MTBF)?
A.MTTR = 2.0 hours; MTBF = 238.0 hours
B.MTTR = 6.0 hours; MTBF = 720.0 hours
C.MTTR = 1.0 hour; MTBF = 240.0 hours
D.MTTR = 3.0 hours; MTBF = 120.0 hours
Explanation: Total downtime = 2 + 1 + 3 = 6 hours across 3 failures. MTTR = Total Downtime / Number of Breakdowns = 6 / 3 = 2.0 hours. Total uptime = 720 - 6 = 714 hours. MTBF = Total Uptime / Number of Failures = 714 / 3 = 238.0 hours.

About the BTS SIO Exam

The Brevet de Technicien Supérieur Services Informatiques aux Organisations (BTS SIO) is a two-year French national higher education vocational diploma (Bac+2, Level 5 RNCP, 120 ECTS). Governed by the Arrêté du 29 avril 2019 as modified by the Arrêté du 8 juillet 2024, it prepares IT professionals across two distinct tracks: SISR (Solutions d'Infrastructure, Systèmes et Réseaux) for systems and network administrators, and SLAM (Solutions Logicielles et Applications Métiers) for software and web developers. The curriculum is structured around core competency blocks including IT service management, specialized technical tracks, cybersecurity (Unit E7), and digital economic/legal management (CEJM). OpenExamPrep provides an English-language MCQ study adaptation of that French curriculum; it does not replace the official French written examinations, student portfolio validations, or oral project defenses.

Exam sponsor: Ministère de l'Enseignement supérieur et de la Recherche / académies / SIEC. The requirements and fees below concern the certification or admission exam, separate from our free practice resources.

Assessment

Regulated by the Arrêté du 29 avril 2019 (JORF n°0125 du 30 mai 2019), modified notably by the Arrêté du 8 juillet 2024 applicable from the 2025 session; current registration RNCP40792. The diploma comprises seven compulsory units totaling 22 coefficients: E1 Culture générale et expression (written 3 h, coef 2); E2 Expression et communication en langue anglaise (written 2 h + oral 20 min, coef 2); E3 Mathématiques pour l'informatique (CCF or written 2 h, coef 3); E4 Culture économique, juridique et managériale - CEJM (written 4 h, coef 3); E5 Support et mise à disposition de services informatiques (oral 40 min on a portfolio, coef 4); E6 Spécialité SISR ou SLAM (practical and oral, 40 min after 1 h 30 preparation, coef 4); and E7 Cybersécurité des services informatiques (written 4 h, coef 4). Passing requires an overall weighted average of at least 10/20 across all units.

Time Limit

Approximately 13 hours of national written examinations plus the English oral and the E5/E6 professional orals; eligible school pathways use CCF

Passing Score

10/20 overall weighted average across all examination units

Exam / Certification Fees

Free for public school and apprentice candidates; nominal fee (typically €5 to €10) for independent candidates via Cyclades depending on académie

Exam sponsor website

Our practice resources: topics covered

We aim to reflect publicly available exam outlines and topic information in our study resources. Coverage, format, and difficulty may differ from the actual exam, and we cannot guarantee that every detail is accurate or current. Confirm exam requirements, fees, and policies with the official exam sponsor.

20 of 100 questions

IT Support, Service Management & ITIL

IT asset management (GLPI, inventory discovery, lifecycle tracking), ITIL 4 service management practices (incident management, problem management, change enablement, service requests, service level agreements SLA/SLO), user assistance and ticketing workflows, MTBF/MTTR and service availability calculations, and digital presence and collaboration tools.

25 of 100 questions

Systems Administration & Network Infrastructure (SISR)

Windows Server Active Directory Domain Services (domain controllers, organizational units, Group Policy Objects GPO, FSMO roles), Linux server administration (DNS BIND, DHCP isc-dhcp/dnsmasq, web servers Apache/Nginx, Samba file shares), VLAN segmentation (IEEE 802.1Q), inter-VLAN routing, subnetting, backup methodologies (3-2-1 rule, full/differential/incremental), and disaster recovery RPO/RTO calculations.

25 of 100 questions

Software Design, Development & Databases (SLAM)

Object-oriented analysis and design (encapsulation, inheritance, polymorphism, abstract classes, interfaces), Model-View-Controller (MVC) architecture, relational database design (MERISE conceptual data model MCD and logical data model MLD, 3NF normalization), advanced SQL queries (JOIN, GROUP BY, HAVING, subqueries, DDL/DML, transactions), REST API design and JSON serialization, Git version control, and unit testing.

20 of 100 questions

Cybersecurity of Information Services

Information system security policy (PSSI), role-based access control (RBAC), multi-factor authentication (MFA), password hashing (bcrypt, Argon2, PBKDF2) vs encryption, TLS certificates and public key infrastructure (PKI), firewall rules, network segmentation, OWASP Top 10 web vulnerabilities (SQL injection, XSS, CSRF, SSRF, broken access control), and ANSSI security hygiene rules.

10 of 100 questions

Economic, Legal & Managerial Culture for IT (CEJM)

European General Data Protection Regulation (RGPD/GDPR) principles, Data Protection Officer (DPO) duties, 72-hour mandatory breach notification to CNIL, legal grounds for processing, software copyright and licensing models (open source GPL, MIT, Apache vs proprietary commercial licenses), SaaS and cloud service provider contracts, and French labor law rules on teleworking.

Preparing for the BTS SIO Exam

What You Need to Know

  • Passing score: 10/20 overall weighted average across all examination units
  • Assessment: Regulated by the Arrêté du 29 avril 2019 (JORF n°0125 du 30 mai 2019), modified notably by the Arrêté du 8 juillet 2024 applicable from the 2025 session; current registration RNCP40792. The diploma comprises seven compulsory units totaling 22 coefficients: E1 Culture générale et expression (written 3 h, coef 2); E2 Expression et communication en langue anglaise (written 2 h + oral 20 min, coef 2); E3 Mathématiques pour l'informatique (CCF or written 2 h, coef 3); E4 Culture économique, juridique et managériale - CEJM (written 4 h, coef 3); E5 Support et mise à disposition de services informatiques (oral 40 min on a portfolio, coef 4); E6 Spécialité SISR ou SLAM (practical and oral, 40 min after 1 h 30 preparation, coef 4); and E7 Cybersécurité des services informatiques (written 4 h, coef 4). Passing requires an overall weighted average of at least 10/20 across all units.
  • Time limit: Approximately 13 hours of national written examinations plus the English oral and the E5/E6 professional orals; eligible school pathways use CCF
  • Exam / certification fees: Free for public school and apprentice candidates; nominal fee (typically €5 to €10) for independent candidates via Cyclades depending on académie Official sources

Using Our Practice Resources

  • Work through all 100 available questions
  • Review every answer and explanation
  • Track weak areas and revisit them
  • Use our AI tutor for tough concepts

BTS SIO: Suggested Study Strategy

1Master the ITIL 4 service desk terminology: know the exact distinctions between Service Requests, Incidents, Problems, and Changes
2Practice SQL queries involving multi-table INNER JOIN and LEFT JOIN operations, aggregate functions (COUNT, SUM, AVG), and HAVING filtering
3Understand the 3-2-1 backup rule (3 copies of data, on 2 different media types, with 1 copy off-site) and calculate data loss windows against RPO targets
4Review Active Directory domain architecture: FSMO roles (Schema Master, Domain Naming Master, RID Master, PDC Emulator, Infrastructure Master) and GPO precedence (LSDOU: Local, Site, Domain, OU)
5Learn the OWASP Top 10 vulnerabilities, especially SQL Injection (use parameterized prepared statements) and Cross-Site Scripting (sanitize input and escape output)
6Memorize key RGPD/CNIL requirements: the 72-hour breach notification deadline, data minimization principle, and consent validity conditions

Frequently Asked Questions

What is the BTS SIO diploma?

The Brevet de Technicien Supérieur Services Informatiques aux Organisations (BTS SIO) is a French national higher education vocational diploma at Level 5 of the RNCP (Bac+2, 120 ECTS). Certified by the French Ministry of Higher Education, it prepares professionals to manage, deploy, develop, and secure IT systems and software services across public and private organizations.

What are the two options in BTS SIO?

BTS SIO offers two specialized options: SISR (Solutions d'Infrastructure, Systèmes et Réseaux), which focuses on systems administration, network design, server deployment, and infrastructure security; and SLAM (Solutions Logicielles et Applications Métiers), which focuses on software analysis, application development, database management, and web programming.

What is the role of Épreuve E7 (Cybersécurité des services informatiques)?

Created as a dedicated cybersecurity unit by the Arrêté du 8 juillet 2024, which reorganized the BTS SIO épreuves from the 2025 session, Épreuve E7 is a compulsory national 4-hour written examination (coefficient 4) taken by candidates in both the SISR and SLAM options, each on a subject adapted to their option. It tests candidates on analyzing security requirements, managing digital identities, securing workstations and mobile devices, protecting data, and responding to cyber incidents according to ANSSI guidelines.

What is the difference between an Incident and a Problem in ITIL 4?

In ITIL 4, an Incident is an unplanned interruption to a service or reduction in the quality of a service, and Incident Management aims to restore normal service operation as quickly as possible. A Problem is a cause, or potential cause, of one or more incidents, and Problem Management focuses on identifying root causes, managing workarounds, and preventing recurring incidents.

What are RPO and RTO in disaster recovery planning?

RPO (Recovery Point Objective) defines the maximum acceptable amount of data loss measured in time (e.g., maximum 4 hours of data lost between the last backup and failure). RTO (Recovery Time Objective) defines the maximum acceptable duration of downtime before a system or service must be restored to operation.

What are the core principles of the 3NF (Third Normal Form) in relational databases?

A relational database table is in Third Normal Form (3NF) if and only if: 1) it is in Second Normal Form (2NF), meaning all non-key attributes are fully functionally dependent on the entire primary key; and 2) no non-key attribute is transitively dependent on the primary key (every non-key attribute depends directly and solely on the primary key).

What are the mandatory GDPR data breach notification requirements under French law?

Under Article 33 of the General Data Protection Regulation (RGPD) enforced in France by the CNIL, the data controller must notify the supervisory authority (CNIL) of a personal data breach without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals.

Is this BTS SIO practice test in French or English?

Official BTS SIO national examinations are conducted in French, with unit E2 evaluating English communication. OpenExamPrep provides a 100-question English-language MCQ study adaptation covering technical principles, network protocols, coding concepts, and security regulations. It serves as a study tool and does not replace official French exam papers or oral project defenses.