Ship Security Officer (SSO) Certification Exam — Questions and Answers
Question 1: Which document contains the specific security procedures and measures a ship must follow at each security level?
- Maritime Declaration of Health
- International Safety Management (ISM) Code Certificate
- Continuous Synopsis Record
- Ship Security Plan (SSP) (Correct answer)
Correct answer: Ship Security Plan (SSP)
The Ship Security Plan (SSP) contains all security procedures, measures, and actions the ship must implement at Security Levels 1, 2, and 3.
Question 2: How often must SSO drills incorporating security equipment checks typically be conducted under the ISPS Code?
- At least once every three months (Correct answer)
- Annually
- Only when new crew members are signed on
- Monthly
Correct answer: At least once every three months
The ISPS Code requires that drills be conducted at least once every three months to ensure crew familiarity with security equipment and procedures.
Question 3: Which type of training exercise involves all relevant ship and shore-based personnel responding to a simulated security scenario in real time without advance notice of the scenario content?
- Scheduled drill
- Tabletop exercise
- Orientation briefing
- Unannounced full-scale security exercise (Correct answer)
Correct answer: Unannounced full-scale security exercise
An unannounced full-scale exercise tests genuine readiness by preventing advance preparation, revealing true competence levels and system reliability.
Question 4: Under ISPS Code Part A, Section 9, which of the following is a mandatory element of every Ship Security Plan?
- Detailed cargo pricing schedules for each voyage
- Marketing strategies for the shipping company
- Procedures for crew salary disbursement during emergencies
- Measures to prevent weapons or dangerous substances from being brought aboard (Correct answer)
Correct answer: Measures to prevent weapons or dangerous substances from being brought aboard
Section 9 of ISPS Code Part A requires that the SSP include measures to prevent unauthorized weapons and dangerous substances from being brought aboard.
Question 5: Which document proves a ship's compliance with the ISPS Code?
- Cargo Manifest
- International Ship Security Certificate (Correct answer)
- Classification Certificate
- Ship Registry Certificate
Correct answer: International Ship Security Certificate
The International Ship Security Certificate (ISSC) is issued to a ship after it has been verified to comply with the requirements of the International Ship and Port Facility Security (ISPS) Code. This certificate serves as official proof that the ship's security arrangements, including its Ship Security Plan, meet international standards.
Question 6: Which scenario best illustrates the correct use of a Ship Security Alert System (SSAS)?
- The SSAS is activated during every port arrival as a routine check-in signal
- A deck officer activates the SSAS during a man-overboard emergency to summon rescue
- The master activates the SSAS to notify the company of a late cargo delivery
- The SSO activates the SSAS when armed pirates board the vessel and take control of the bridge (Correct answer)
Correct answer: The SSO activates the SSAS when armed pirates board the vessel and take control of the bridge
The SSAS is designed exclusively for genuine security threats such as piracy or armed robbery, transmitting a covert alert to authorities without alerting the attacker.
Question 7: Which parties may request a Declaration of Security?
- Only the Contracting Government
- Either the ship or the port facility (Correct answer)
- Only the port facility
- Only the ship's Master
Correct answer: Either the ship or the port facility
Either the ship or the port facility may request a Declaration of Security when they believe their interface presents a security risk requiring formal documented agreement.
Question 8: When a conflict arises between standard procedures and a unique situation in Contract Types & Administration, what should a SSO professional prioritize?
- The most cost-effective solution available
- Safety and ethical obligations while seeking expert consultation (Correct answer)
- The preference of the client or stakeholder
- Strict adherence to written procedures without exception
Correct answer: Safety and ethical obligations while seeking expert consultation
Safety and ethics always take priority in Contract Types & Administration. When standard procedures don't adequately address a unique situation, consulting with experienced colleagues or supervisors ensures both safety and professional standards are maintained.
Question 9: Which regulation requires vessels to transmit a 96-hour advance notice of arrival (NOA) to U.S. ports?
- 46 CFR Part 2
- 33 CFR Part 101
- 33 CFR Part 104
- 33 CFR Part 160 (Correct answer)
Correct answer: 33 CFR Part 160
33 CFR Part 160 governs vessel traffic management and establishes the 96-hour advance notice of arrival requirement for vessels entering U.S. ports.
Question 10: What is 'freight prepaid' notation on a bill of lading significant for in international trade?
- It means the cargo has been inspected and approved by customs
- It confirms freight has been paid by the shipper and the consignee owes no freight on delivery (Correct answer)
- It limits the carrier's liability to the prepaid amount
- It grants the consignee ownership of the vessel space
Correct answer: It confirms freight has been paid by the shipper and the consignee owes no freight on delivery
A 'freight prepaid' bill of lading confirms the shipper has settled freight charges, so the consignee can take delivery without paying additional freight to the carrier.
Question 11: Which FAR clause requires a contractor providing vessel security services to flow down certain contract requirements to all subcontractors?
- FAR 52.244-6 (Subcontracts for Commercial Items) (Correct answer)
- FAR 52.211-5 (Material Requirements)
- FAR 52.236-1 (Performance of Work by the Contractor)
- FAR 52.232-33 (Payment by Electronic Funds Transfer)
Correct answer: FAR 52.244-6 (Subcontracts for Commercial Items)
FAR 52.244-6 requires prime contractors to insert specified FAR clauses in subcontracts for commercial items and services, ensuring flow-down of key requirements.
Question 12: How frequently must a Ship Security Assessment be reviewed according to the ISPS Code?
- Before significant operational changes or security incidents, and at regular intervals (Correct answer)
- Every five years when the International Ship Security Certificate is renewed
- Every six months regardless of circumstances
- Only when requested by the flag state
Correct answer: Before significant operational changes or security incidents, and at regular intervals
The ISPS Code requires the SSA to be reviewed when there are significant changes to the ship's operations or following a security incident, as well as at regular intervals to remain current.
Question 13: Razor wire or electric fence installed along a ship's railings is classified as which type of security measure?
- Detection measure
- Response measure
- Deterrence and delay measure (Correct answer)
- Communication measure
Correct answer: Deterrence and delay measure
Physical barriers like razor wire deter boarding attempts and delay intruders, buying time for the crew to respond — they are classified as deterrence and delay measures.
Question 14: A Ship Security Assessment must include an evaluation of which of the following?
- Weather routing and navigation plans
- Cargo pricing and commercial agreements
- Existing security measures, procedures, and operations (Correct answer)
- Crew salary scales and employment contracts
Correct answer: Existing security measures, procedures, and operations
The SSA must evaluate all existing security measures, procedures, and operations to identify their strengths and weaknesses relative to identified threats.
Question 15: What is a 'vulnerability' in the context of a Ship Security Assessment?
- A weakness that could be exploited by a threat actor (Correct answer)
- A known security incident that occurred on the vessel
- An area of the ship that is difficult to navigate
- A crew member who lacks security training
Correct answer: A weakness that could be exploited by a threat actor
A vulnerability is any weakness or gap in security measures that could be exploited by a hostile actor to compromise ship security.
Question 16: A water cannon (fire hose used as a security measure) is best employed against which type of threat?
- Cyber intrusions targeting the ship's IT systems
- Smuggling of contraband in cargo containers
- Stowaways already aboard
- Small craft attempting to come alongside or board (Correct answer)
Correct answer: Small craft attempting to come alongside or board
Water cannons create a physical deterrent against small craft approaching the vessel and can repel boarding attempts without lethal force.
Question 17: What is a 'countermeasure' in the context of maritime security risk management?
- A legal action taken against a security offender
- A request for additional security personnel from the port authority
- A report filed after a security incident has occurred
- A measure implemented to reduce the risk posed by identified threats and vulnerabilities (Correct answer)
Correct answer: A measure implemented to reduce the risk posed by identified threats and vulnerabilities
A countermeasure is any security action or procedure implemented to reduce or mitigate the risk presented by identified threats and vulnerabilities.
Question 18: A vessel's crew member is suspected of providing security intelligence to external parties. What is the SSO's appropriate initial action?
- Confront the crew member publicly to deter others
- Immediately confine the crew member in the ship's brig without notifying the Master
- Report suspicions to the Master and CSO, document evidence, and restrict the individual's access to sensitive areas pending investigation (Correct answer)
- Ignore the suspicion until concrete evidence is obtained
Correct answer: Report suspicions to the Master and CSO, document evidence, and restrict the individual's access to sensitive areas pending investigation
Suspected insider threats must be escalated to the Master and CSO with documented evidence while limiting the suspect's access to sensitive systems.
Question 19: What type of training is mandatory for all crew members regarding security?
- Navigation chart plotting
- Security awareness training (Correct answer)
- Cargo loading
- Medical first aid
Correct answer: Security awareness training
International maritime regulations, such as the ISPS Code, mandate that all shipboard personnel receive appropriate security awareness training. This training ensures that every crew member understands their role in maintaining ship security, recognizing security threats, and knowing how to respond. It fosters a collective security culture, making the ship less vulnerable to security incidents.
Question 20: Which device is used to monitor access to restricted areas on a ship?
- Automatic sprinkler
- Radar scanner
- Smoke detector
- CCTV system (Correct answer)
Correct answer: CCTV system
A Closed-Circuit Television (CCTV) system is specifically designed for surveillance and monitoring, making it ideal for observing access points and restricted areas on a ship. It provides real-time visual information, allowing security personnel to detect unauthorized entry or suspicious activities. This visual record also serves as evidence for investigations if a security incident occurs.
Question 21: Which document must a ship present to port State control officers to demonstrate ISPS Code compliance?
- International Ship Security Certificate (ISSC) (Correct answer)
- Continuous Synopsis Record only
- Ship Safety Management Certificate
- Port Facility Security Record
Correct answer: International Ship Security Certificate (ISSC)
The International Ship Security Certificate (ISSC) is the primary document verifying that a ship complies with ISPS Code requirements.
Question 22: Under Security Level 3, which action is most appropriate for the Ship Security Officer?
- Maintaining normal security watch rotations
- Implementing all measures specified in the Ship Security Plan for Level 3 (Correct answer)
- Requesting a Declaration of Security from the nearest port
- Reducing crew access to secure areas only
Correct answer: Implementing all measures specified in the Ship Security Plan for Level 3
At Security Level 3, the SSO must implement all specific security measures identified in the SSP for that level, as an imminent attack is probable or has occurred.
Question 23: Under the ISPS Code, which of the following is the SSO's responsibility regarding crew security training records?
- Flag State inspectors are the sole party responsible for recording training
- Training records are only required for officers, not ratings
- Training records are maintained solely by the Company Security Officer
- The SSO must ensure that records of all security training and drills are maintained on board (Correct answer)
Correct answer: The SSO must ensure that records of all security training and drills are maintained on board
The ISPS Code places responsibility on the SSO to ensure that all security training and drill records are maintained on board and available for inspection.
Question 24: What is the SSO's duty with respect to security equipment on board?
- The SSO only needs to inspect equipment during port state control visits
- The SSO must ensure that security equipment is properly operated, tested, calibrated, and maintained (Correct answer)
- Security equipment maintenance is solely the Chief Engineer's responsibility
- The SSO is only responsible for CCTV systems
Correct answer: The SSO must ensure that security equipment is properly operated, tested, calibrated, and maintained
The SSO is responsible for ensuring that all shipboard security equipment is properly operated, tested, calibrated, and maintained in good working order.
Question 25: Which entity has the authority to approve amendments to the Ship Security Plan?
- The flag state Administration or an authorized Recognized Security Organization (RSO) (Correct answer)
- The SSO alone
- The Master alone
- The port state control officer
Correct answer: The flag state Administration or an authorized Recognized Security Organization (RSO)
Amendments to the SSP must be approved by the flag state Administration or a Recognized Security Organization (RSO) acting on its behalf.
Question 26: A solicitation for ship security officer training services includes FAR 52.215-3. What does this clause require offerors to do?
- Provide cost or pricing data
- Request explanations for any solicitation terms they find ambiguous (Correct answer)
- Certify compliance with small business subcontracting goals
- Acknowledge all amendments to the solicitation
Correct answer: Request explanations for any solicitation terms they find ambiguous
FAR 52.215-3 (Request for Information or Solicitation for Planning Purposes) informs offerors that responses may be used for market research and invites questions about unclear solicitation requirements.
Question 27: Which information gathered during a Ship Security Assessment is treated as confidential?
- Identified vulnerabilities and specific countermeasures in the Ship Security Plan (Correct answer)
- The number of crew members aboard
- The ship's scheduled port calls
- The ship's name and IMO number
Correct answer: Identified vulnerabilities and specific countermeasures in the Ship Security Plan
Vulnerabilities identified in the SSA and the countermeasures outlined in the Ship Security Plan are confidential to prevent adversaries from exploiting this knowledge.
Question 28: Which frequency is designated as the international distress and safety calling frequency for VHF radio?
- VHF Channel 70
- VHF Channel 16 (Correct answer)
- VHF Channel 6
- VHF Channel 22A
Correct answer: VHF Channel 16
VHF Channel 16 is the internationally designated distress, safety, and calling frequency monitored by all vessels and coast stations.
Question 29: A contracting officer includes FAR 52.217-8 in a vessel security contract. This clause gives the government the right to:
- Reduce the contract price if performance is unsatisfactory
- Terminate the contract if the contractor's security clearance lapses
- Require the contractor to hire additional security personnel on short notice
- Extend services for up to 6 months beyond the contract period of performance (Correct answer)
Correct answer: Extend services for up to 6 months beyond the contract period of performance
FAR 52.217-8 (Option to Extend Services) allows the government to extend the contract for a period up to 6 months at the same rates when it needs additional time to compete or award a follow-on contract.
Question 30: The ISPS Code requires a ship to maintain records of security activities for a minimum of:
- 6 months
- 3 years
- 12 months (Correct answer)
- 5 years
Correct answer: 12 months
The ISPS Code requires ships to maintain records of security activities for at least the minimum period specified, generally accepted as three years in practice, but the Code specifies records must be kept on board and accessible; many flag States set 3 years — however ISPS Part A 10.1 requires the SSP itself to address record-keeping without mandating a specific duration, while MSC circulars suggest 12 months minimum for activity logs.
Question 31: What is the primary purpose of a ship's Automatic Identification System (AIS) in the context of maritime security?
- To monitor crew fatigue levels
- To provide vessel tracking and identity information to other ships and authorities (Correct answer)
- To control the ship's steering from a remote location
- To automate cargo loading operations
Correct answer: To provide vessel tracking and identity information to other ships and authorities
AIS broadcasts vessel identity, position, course, and speed, enabling maritime authorities and other vessels to track and identify ships for safety and security purposes.
Question 32: What role does the crew play during a security drill?
- Assist passengers only
- Check personal belongings
- Observe silently from a distance
- Participate actively to rehearse response protocols (Correct answer)
Correct answer: Participate actively to rehearse response protocols
During a security drill, the crew's role is to participate actively to rehearse response protocols and familiarize themselves with their duties in a security incident. Active involvement allows for testing the effectiveness of the Ship Security Plan, identifying weaknesses, and improving coordination and readiness. This practical experience is crucial for an effective response in a real emergency.
Question 33: What is the purpose of a Declaration of Security (DoS)?
- To authorize the embarkation of additional security personnel
- To certify that a ship's security plan has been approved
- To document the security measures agreed between a ship and a port facility (Correct answer)
- To formally report a security incident to authorities
Correct answer: To document the security measures agreed between a ship and a port facility
A DoS documents the security responsibilities and specific measures that both the ship and port facility agree to implement during their interface.
Question 34: Which regulation requires U.S.-flagged vessels and foreign vessels in U.S. waters to maintain a working Ship Security Alert System (SSAS)?
- ISM Code and 46 CFR Part 97
- MARPOL Annex VI and 33 CFR Part 160
- COLREGS Rule 35 and 33 CFR Part 83
- SOLAS Regulation XI-2/6 and 33 CFR Part 104 (Correct answer)
Correct answer: SOLAS Regulation XI-2/6 and 33 CFR Part 104
SOLAS XI-2/6 mandates SSAS for applicable vessels, and 33 CFR Part 104 implements this requirement for vessels subject to U.S. jurisdiction.
Question 35: SOLAS Chapter XI-2 entered into force on which date?
- January 1, 2000
- January 1, 2002
- September 11, 2001
- July 1, 2004 (Correct answer)
Correct answer: July 1, 2004
SOLAS Chapter XI-2 and the ISPS Code entered into force on July 1, 2004.
Question 36: In a contract of affreightment (COA), what is the primary feature that distinguishes it from a single voyage charter?
- It eliminates all laytime provisions
- It covers a series of voyages over a period of time (Correct answer)
- It applies only to tanker trades
- It requires a fixed vessel assignment
Correct answer: It covers a series of voyages over a period of time
A COA obliges the shipowner to carry a specified total quantity of cargo over multiple voyages during a defined period, without nominating a specific vessel upfront.
Question 37: The Declaration of Security (DoS) is an agreement between which parties?
- The company and the flag state administration
- The master and the port authority
- The SSO and the CSO
- The ship and a port facility or another ship (Correct answer)
Correct answer: The ship and a port facility or another ship
A Declaration of Security is a formal agreement between a ship and a port facility (or another ship) that outlines the security measures each will implement.
Question 38: What are the three security levels defined under the ISPS Code?
- Security Levels 1, 2, and 3 (Correct answer)
- Alert, Warning, and Emergency
- Green, Yellow, and Red
- Low, Medium, and High
Correct answer: Security Levels 1, 2, and 3
The ISPS Code establishes three security levels: Level 1 (normal), Level 2 (heightened), and Level 3 (exceptional threat).
Question 39: Who is responsible for the daily implementation of security measures onboard the ship?
- Port Facility Security Officer (PFSO)
- Ship Security Officer (SSO) (Correct answer)
- Company Security Officer (CSO)
- Flag State Security Inspector
Correct answer: Ship Security Officer (SSO)
The SSO is the person aboard the ship responsible for implementing and maintaining the Ship Security Plan on a day-to-day basis.
Question 40: When testing CCTV cameras for security coverage effectiveness, what is the most important factor an SSO should verify?
- Cameras are visible and act as a deterrent
- All designated access points and restricted areas are covered without blind spots (Correct answer)
- Camera resolution is set to maximum
- Footage is stored in color rather than black-and-white
Correct answer: All designated access points and restricted areas are covered without blind spots
Effective CCTV coverage requires that all critical areas such as gangways, engine room entries, and the bridge are fully monitored without blind spots.
Question 41: Which term describes the formal process of reviewing and updating a Ship Security Plan after a significant security incident?
- Continuous synopsis amendment
- Security level reassessment
- Post-incident security review (Correct answer)
- Flag state verification audit
Correct answer: Post-incident security review
A post-incident security review evaluates whether the SSP adequately addressed the incident and determines necessary amendments.
Question 42: When conducting a threat assessment, the SSO should consider which combination of factors?
- The ship type, cargo, trading routes, and regional threat intelligence (Correct answer)
- The ship's profitability and commercial routes only
- The personal security history of each crew member only
- Only incidents that have previously occurred on the vessel itself
Correct answer: The ship type, cargo, trading routes, and regional threat intelligence
A comprehensive threat assessment combines ship-specific factors such as type, cargo, and routes with available intelligence about threats in the regions the ship will transit.
Question 43: During a security training session, an officer asks why crew members must learn to recognize signs of tampering with security equipment. What is the most accurate response?
- Only the SSO and master need to recognize tampering signs; general crew awareness is unnecessary
- Tampering is extremely rare and not worth devoting training time to
- It is purely a regulatory requirement with no practical security value
- Tampered equipment may fail at a critical moment, and early detection allows restoration before a threat materializes (Correct answer)
Correct answer: Tampered equipment may fail at a critical moment, and early detection allows restoration before a threat materializes
Threat actors may pre-disable cameras, alarms, or locks before an attack; trained crew who recognize tampering can restore equipment and raise the alarm before an incident occurs.
Question 44: Which document must the SSO be thoroughly familiar with to carry out their duties?
- Only the SOLAS Convention
- The PFSO's facility security assessment
- The Ship Security Plan (SSP) and its confidential annexes (Correct answer)
- The company's commercial contracts
Correct answer: The Ship Security Plan (SSP) and its confidential annexes
The SSO must be thoroughly familiar with the Ship Security Plan, including its confidential annexes, to effectively implement and maintain shipboard security.
Question 45: What does 'consequence' mean in the risk assessment formula used in maritime security?
- The legal penalties for failing to follow security procedures
- The cost of implementing security countermeasures
- The time required to respond to a security incident
- The potential impact or harm resulting from a successful security breach (Correct answer)
Correct answer: The potential impact or harm resulting from a successful security breach
Consequence refers to the potential impact, harm, or damage that would result if a threat successfully exploited a vulnerability on the vessel.
Question 46: A vessel must comply with a new USCG security directive requiring upgraded communication equipment. This is best classified as which type of cost driver?
- Opportunity cost
- Discretionary cost
- Sunk cost
- Regulatory compliance cost (Correct answer)
Correct answer: Regulatory compliance cost
Costs mandated by a government regulatory body such as the USCG are classified as regulatory compliance costs, which are non-discretionary.
Question 47: Which of the following is a required element in a Ship Security Plan?
- Engine maintenance logs
- Security procedures and duties (Correct answer)
- Sailing schedule
- Crew recreational activities
Correct answer: Security procedures and duties
A Ship Security Plan (SSP) is a comprehensive document detailing measures to protect the ship from security threats. It must outline specific security procedures for various operations and clearly define the duties and responsibilities of all personnel involved in security, ensuring a structured approach to maintaining ship security.
Question 48: Which body is responsible for approving a ship's Security Plan under the ISPS Code?
- The flag state Administration or a Recognized Security Organization acting on its behalf (Correct answer)
- The Company Security Officer
- The International Maritime Organization (IMO)
- The port state control authority
Correct answer: The flag state Administration or a Recognized Security Organization acting on its behalf
The flag state Administration, or a Recognized Security Organization (RSO) it authorizes, is responsible for reviewing and approving the Ship Security Plan.
Question 49: What action should an SSO take if a crewmember refuses to participate in a mandatory security drill?
- Immediately revoke the crewmember's access rights as a disciplinary measure
- Excuse the crewmember if they provide a written reason for refusal
- Document the refusal, report it to the master, and ensure the crewmember is trained through an alternative arrangement (Correct answer)
- Accept the refusal since security drills are voluntary under IMO guidelines
Correct answer: Document the refusal, report it to the master, and ensure the crewmember is trained through an alternative arrangement
The SSO must document the refusal, escalate to the master, and arrange alternative training to ensure the crewmember achieves the required security competence.
Question 50: Under the ISPS Code, which party is responsible for approving a Ship Security Plan (SSP)?
- The Administration (flag state) (Correct answer)
- The Classification Society on behalf of the company
- The Port State Control authority
- The Company Security Officer
Correct answer: The Administration (flag state)
The Administration (flag state) or a recognized security organization acting on its behalf is responsible for approving the Ship Security Plan.
Question 51: Which international regulation mandates that certain ships carry a functioning Ship Security Alert System?
- ISM Code Regulation 12
- MARPOL Annex I
- SOLAS Chapter XI-2 (Correct answer)
- STCW Convention Chapter VI
Correct answer: SOLAS Chapter XI-2
SOLAS Chapter XI-2, which incorporates the ISPS Code, mandates that ships carry and maintain a functioning SSAS to transmit covert security alerts.
Question 52: Under ISPS Code Part B, what is the recommended frequency for ship security exercises involving all security stakeholders (full-scale exercises)?
- At least once per calendar year (Correct answer)
- Every 2 years
- Every 3 months
- Every 6 months
Correct answer: At least once per calendar year
ISPS Code Part B recommends that full-scale security exercises involving all relevant stakeholders be conducted at least once per calendar year.
Ship Security Officer (SSO) Certification Exam
This certification is for individuals designated to ensure the security of a ship, including implementing and maintaining the ship security plan, conducting security inspections, and coordinating with port facility security officers.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds