Ship Security Officer (SSO) Certification Exam — Questions and Answers
Question 1: A portable two-way radio used for security communications aboard a ship should primarily operate on which frequency band to ensure reliability in a maritime environment?
- UHF or VHF band (Correct answer)
- AM (amplitude modulation) band
- Satellite frequency band
- Shortwave HF band only
Correct answer: UHF or VHF band
UHF and VHF radios provide reliable short-range communications in the maritime environment and are the standard for shipboard security coordination.
Question 2: What is a 'vulnerability' in the context of a Ship Security Assessment?
- A known security incident that occurred on the vessel
- A weakness that could be exploited by a threat actor (Correct answer)
- A crew member who lacks security training
- An area of the ship that is difficult to navigate
Correct answer: A weakness that could be exploited by a threat actor
A vulnerability is any weakness or gap in security measures that could be exploited by a hostile actor to compromise ship security.
Question 3: Which best describes the difference between Security Level 1 and Security Level 2?
- Level 1 is the normal operating state; Level 2 is set when there is a heightened risk of a security incident (Correct answer)
- Level 1 applies in port; Level 2 applies at sea
- Level 1 applies to passenger ships; Level 2 applies to cargo ships
- Level 1 requires a Declaration of Security; Level 2 does not
Correct answer: Level 1 is the normal operating state; Level 2 is set when there is a heightened risk of a security incident
Security Level 1 represents normal operations with minimum appropriate protective security measures, while Level 2 is set when there is a heightened risk of a security incident.
Question 4: A Ship Security Assessment must include an evaluation of which of the following?
- Weather routing and navigation plans
- Crew salary scales and employment contracts
- Cargo pricing and commercial agreements
- Existing security measures, procedures, and operations (Correct answer)
Correct answer: Existing security measures, procedures, and operations
The SSA must evaluate all existing security measures, procedures, and operations to identify their strengths and weaknesses relative to identified threats.
Question 5: The ISPS Code requires a ship to maintain records of security activities for a minimum of:
- 5 years
- 3 years
- 6 months
- 12 months (Correct answer)
Correct answer: 12 months
The ISPS Code requires ships to maintain records of security activities for at least the minimum period specified, generally accepted as three years in practice, but the Code specifies records must be kept on board and accessible; many flag States set 3 years — however ISPS Part A 10.1 requires the SSP itself to address record-keeping without mandating a specific duration, while MSC circulars suggest 12 months minimum for activity logs.
Question 6: What is the SSO's responsibility regarding shore leave for crew members while in port?
- Shore leave must be cancelled at Security Level 1
- The SSO must ensure crew identification is verified upon return and monitor for any security concerns related to shore leave (Correct answer)
- Shore leave is not subject to any security considerations
- Only the Master can authorize shore leave; the SSO has no role
Correct answer: The SSO must ensure crew identification is verified upon return and monitor for any security concerns related to shore leave
The SSO must ensure that crew members returning from shore leave are properly identified and monitor for any security risks associated with crew movements ashore.
Question 7: The SSO is conducting a security inspection of the ship prior to entering port. Which area should receive particular attention regarding potential concealment of illicit items?
- Engine room bilges only
- The bridge and navigation equipment spaces only
- Void spaces, chain lockers, ballast tanks, and other seldom-accessed areas (Correct answer)
- Crew cabins and the galley only
Correct answer: Void spaces, chain lockers, ballast tanks, and other seldom-accessed areas
Void spaces, chain lockers, ballast tanks, and other seldom-visited areas are common locations for concealing weapons, drugs, or stowaways and require thorough inspection.
Question 8: A ship without a valid ISSC arriving at a US port may be subject to which action under 33 CFR Part 104?
- Detention, denial of entry, or expulsion from port (Correct answer)
- Mandatory dry-docking
- Criminal prosecution of the master only
- Expulsion from US waters permanently
Correct answer: Detention, denial of entry, or expulsion from port
Under 33 CFR Part 104, a vessel without a valid ISSC may be detained, denied entry, or expelled from the port by the USCG.
Question 9: Which international regulation mandates that certain ships carry a functioning Ship Security Alert System?
- SOLAS Chapter XI-2 (Correct answer)
- MARPOL Annex I
- ISM Code Regulation 12
- STCW Convention Chapter VI
Correct answer: SOLAS Chapter XI-2
SOLAS Chapter XI-2, which incorporates the ISPS Code, mandates that ships carry and maintain a functioning SSAS to transmit covert security alerts.
Question 10: What action should an SSO take if a crewmember refuses to participate in a mandatory security drill?
- Accept the refusal since security drills are voluntary under IMO guidelines
- Immediately revoke the crewmember's access rights as a disciplinary measure
- Excuse the crewmember if they provide a written reason for refusal
- Document the refusal, report it to the master, and ensure the crewmember is trained through an alternative arrangement (Correct answer)
Correct answer: Document the refusal, report it to the master, and ensure the crewmember is trained through an alternative arrangement
The SSO must document the refusal, escalate to the master, and arrange alternative training to ensure the crewmember achieves the required security competence.
Question 11: An SSO is evaluating security guard service providers for a high-risk port call. Which evaluation criterion is LEAST relevant to the security selection decision?
- The service provider's office interior design (Correct answer)
- Availability of armed vs. unarmed options
- Guard training standards and certifications
- Company's experience in maritime environments
Correct answer: The service provider's office interior design
Office aesthetics have no bearing on a security provider's capability to protect the vessel and crew.
Question 12: Which protocol governs the exchange of security-related information between a ship and a port facility when a Declaration of Security has NOT been requested?
- The Ship Security Plan and Port Facility Security Plan define their respective default procedures (Correct answer)
- No security information exchange is required without a DoS
- The master and port facility security officer must meet in person
- The SSAS is activated to initiate a secure communication channel
Correct answer: The Ship Security Plan and Port Facility Security Plan define their respective default procedures
When a DoS is not in place, each party defaults to the security procedures defined in their respective SSP or PFSP for routine interface operations.
Question 13: What information must be included in a ship's 96-hour advance notice of arrival (NOA) to U.S. authorities?
- Ship Security Plan summary and ISSC number only
- Last ten ports of call, crew and passenger lists, and cargo information (Correct answer)
- Voyage plan and anticipated berth assignment
- CSO contact details and last port facility security assessment
Correct answer: Last ten ports of call, crew and passenger lists, and cargo information
NOA submissions must include the last 10 ports of call, crew and passenger manifests, cargo details, and other vessel information as required by 33 CFR Part 160.
Question 14: Which standard of practice is MOST important for ensuring quality in Source Selection & Evaluation?
- Strictly adhering to the same procedure in every situation
- Using the most advanced technology available regardless of need
- Minimizing documentation to focus on practical work
- Following evidence-based protocols while adapting to specific circumstances (Correct answer)
Correct answer: Following evidence-based protocols while adapting to specific circumstances
Evidence-based protocols provide a foundation of proven practices, but effective Ship Security Officer professionals must also adapt their approach based on specific circumstances and individual case needs within Source Selection & Evaluation.
Question 15: Under FAR Part 22, a contract for vessel patrol and security guard services must comply with which labor law requiring minimum wages for service employees?
- Fair Labor Standards Act exclusively
- Walsh-Healey Public Contracts Act
- Service Contract Labor Standards (formerly Service Contract Act) (Correct answer)
- Davis-Bacon Act
Correct answer: Service Contract Labor Standards (formerly Service Contract Act)
The Service Contract Labor Standards (SCLS), formerly the Service Contract Act, applies to federal service contracts and requires prevailing wages and fringe benefits for service employees.
Question 16: Under ISPS Code requirements, which onboard record demonstrates that required security equipment has been maintained and tested?
- Safety Equipment Certificate
- International Ship Security Certificate (ISSC)
- Ship Security Log / Records of security activities (Correct answer)
- Continuous Synopsis Record (CSR)
Correct answer: Ship Security Log / Records of security activities
The Ship Security Log records all security activities, equipment tests, drills, and inspections, demonstrating ongoing compliance with the SSP.
Question 17: Under MTSA and 33 CFR Part 104, how often must a vessel subject to these regulations conduct a full security exercise involving all parties (ship, company, and port facility)?
- Once every five years, coinciding with ISSC renewal
- Annually on a date set by the company security officer
- At least once every calendar year, with no more than 18 months between exercises (Correct answer)
- Every six months, coordinated with the cognizant COTP
Correct answer: At least once every calendar year, with no more than 18 months between exercises
Full security exercises must occur at least once per calendar year with no more than 18 months between successive exercises, per 33 CFR Part 104.
Question 18: Under ISPS Code Part A, the Company Security Officer (CSO) is responsible for ensuring that the Ship Security Assessment is:
- Filed with the port State authority
- Completed within 30 days of ship acquisition
- Properly carried out and reviewed periodically (Correct answer)
- Conducted only by an RSO
Correct answer: Properly carried out and reviewed periodically
The CSO must ensure the Ship Security Assessment is properly carried out and reviewed to reflect changing threats and vulnerabilities.
Question 19: A Contracting Government may exempt certain ships from ISPS Code requirements if those ships:
- Were built before July 1, 2004
- Are under 300 GT
- Are not carrying dangerous goods
- Operate exclusively within a single Contracting Government's waters under bilateral agreements (Correct answer)
Correct answer: Operate exclusively within a single Contracting Government's waters under bilateral agreements
Contracting Governments may grant exemptions to ships operating on domestic voyages within their own waters or between two States under equivalent security agreements.
Question 20: In a time charter, what is typically meant by the 'redelivery' obligation?
- The charterer must return the vessel in the same condition as on delivery, fair wear and tear excepted (Correct answer)
- The charterer must pay additional hire for the final voyage
- The charterer must provide a replacement vessel
- The shipowner must collect the vessel from any port worldwide
Correct answer: The charterer must return the vessel in the same condition as on delivery, fair wear and tear excepted
Redelivery requires the charterer to return the vessel to the owner at the agreed place and in the condition it was received, allowing for normal wear and tear.
Question 21: Under ISPS Code Part B, what is the recommended frequency for ship security exercises involving all security stakeholders (full-scale exercises)?
- Every 2 years
- Every 3 months
- Every 6 months
- At least once per calendar year (Correct answer)
Correct answer: At least once per calendar year
ISPS Code Part B recommends that full-scale security exercises involving all relevant stakeholders be conducted at least once per calendar year.
Question 22: Which international body's guidelines most directly inform the selection of security equipment for SOLAS-regulated vessels?
- International Maritime Organization (IMO) (Correct answer)
- International Labour Organization (ILO)
- International Chamber of Commerce (ICC)
- World Customs Organization (WCO)
Correct answer: International Maritime Organization (IMO)
The IMO develops and maintains SOLAS and ISPS Code requirements that govern security equipment standards on regulated vessels.
Question 23: Which type of alarm system is specifically designed to alert the crew to unauthorized access attempts in restricted areas aboard a vessel?
- Intrusion detection alarm (Correct answer)
- General alarm
- Bilge high-level alarm
- Fire detection alarm
Correct answer: Intrusion detection alarm
Intrusion detection alarms use sensors such as motion detectors, door contacts, or vibration sensors to alert crew when unauthorized persons attempt to enter restricted areas.
Question 24: How frequently must a Ship Security Assessment be reviewed according to the ISPS Code?
- Every six months regardless of circumstances
- Every five years when the International Ship Security Certificate is renewed
- Only when requested by the flag state
- Before significant operational changes or security incidents, and at regular intervals (Correct answer)
Correct answer: Before significant operational changes or security incidents, and at regular intervals
The ISPS Code requires the SSA to be reviewed when there are significant changes to the ship's operations or following a security incident, as well as at regular intervals to remain current.
Question 25: Which body is responsible for approving a ship's Security Plan under the ISPS Code?
- The International Maritime Organization (IMO)
- The flag state Administration or a Recognized Security Organization acting on its behalf (Correct answer)
- The Company Security Officer
- The port state control authority
Correct answer: The flag state Administration or a Recognized Security Organization acting on its behalf
The flag state Administration, or a Recognized Security Organization (RSO) it authorizes, is responsible for reviewing and approving the Ship Security Plan.
Question 26: What is the primary purpose of establishing a contingency reserve within a ship security budget?
- To compensate for foreign currency exchange gains
- To fund routine patrol operations
- To cover unforeseen security expenditures not included in the base budget (Correct answer)
- To pay annual ISPS audit fees
Correct answer: To cover unforeseen security expenditures not included in the base budget
A contingency reserve is set aside specifically to address unexpected security costs that were not anticipated during the budget planning cycle.
Question 27: What is the purpose of the Ship Security Alert System (SSAS)?
- To broadcast a mayday signal on all VHF channels
- To silently transmit a distress alert to authorities without alerting attackers (Correct answer)
- To sound an audible alarm to warn crew of a security threat
- To lock all ship doors automatically during an attack
Correct answer: To silently transmit a distress alert to authorities without alerting attackers
The SSAS sends a covert alert to the flag state or competent authority without notifying those on board who may be the threat.
Question 28: How is 'risk' most accurately defined in maritime security?
- The number of security vulnerabilities identified in an assessment
- The combination of the likelihood of a threat and its potential consequences (Correct answer)
- The probability that a security incident will occur
- The severity of damage caused by a security breach
Correct answer: The combination of the likelihood of a threat and its potential consequences
Risk in maritime security is defined as the combination of the probability of a threat occurring and the severity of the consequences if it does.
Question 29: Which item is part of standard security equipment for perimeter checks?
- Weather vane
- Handheld flashlight (Correct answer)
- Electronic radar
- Compass
Correct answer: Handheld flashlight
A handheld flashlight is a fundamental piece of equipment for conducting effective perimeter checks, especially during hours of darkness or in dimly lit areas. It allows security personnel to illuminate blind spots, identify potential intruders, and inspect the ship's boundaries thoroughly. This simple tool is crucial for ensuring comprehensive visual surveillance of the vessel's exterior.
Question 30: What type of training is mandatory for all crew members regarding security?
- Security awareness training (Correct answer)
- Medical first aid
- Navigation chart plotting
- Cargo loading
Correct answer: Security awareness training
International maritime regulations, such as the ISPS Code, mandate that all shipboard personnel receive appropriate security awareness training. This training ensures that every crew member understands their role in maintaining ship security, recognizing security threats, and knowing how to respond. It fosters a collective security culture, making the ship less vulnerable to security incidents.
Question 31: When must a Ship Security Assessment be conducted?
- Before creating the Ship Security Plan (Correct answer)
- After flag state inspection
- Before crew change
- Before cargo is loaded
Correct answer: Before creating the Ship Security Plan
The Ship Security Assessment (SSA) must be conducted before the Ship Security Plan (SSP) can be developed. The SSA identifies the specific security threats and vulnerabilities unique to that ship, providing the necessary information to create a tailored and effective SSP. Without the assessment, the plan would lack a proper foundation for addressing the ship's actual security needs.
Question 32: When conducting a post-incident review of CCTV footage related to a security breach, what is the SSO's primary obligation regarding that footage?
- Share the footage publicly to warn other vessels
- Preserve and secure the footage as potential evidence for authorities (Correct answer)
- Overwrite the footage with the next 24 hours of recording as normal
- Delete the footage after reviewing it to protect crew privacy
Correct answer: Preserve and secure the footage as potential evidence for authorities
CCTV footage of a security incident must be preserved and secured immediately because it constitutes potential evidence required by port state authorities and investigators.
Question 33: The ISPS Code requires that records of security activities be kept for a minimum of how long?
- 3 years (Correct answer)
- 1 year
- 10 years
- 5 years
Correct answer: 3 years
The ISPS Code requires security records to be retained for a minimum of 3 years to support audits, investigations, and port state control inspections.
Question 34: A long-range acoustic device (LRAD) used as a maritime security measure operates primarily by:
- Firing rubber projectiles at boarding parties
- Jamming communications signals from approaching craft
- Creating a visible laser barrier around the ship's perimeter
- Emitting a high-intensity sound beam that can deter and disorient approaching threats (Correct answer)
Correct answer: Emitting a high-intensity sound beam that can deter and disorient approaching threats
An LRAD projects a focused, high-decibel sound beam that causes discomfort and disorientation, serving as a non-lethal deterrent against approaching threats.
Question 35: Which parties may request a Declaration of Security?
- Only the ship's Master
- Only the port facility
- Either the ship or the port facility (Correct answer)
- Only the Contracting Government
Correct answer: Either the ship or the port facility
Either the ship or the port facility may request a Declaration of Security when they believe their interface presents a security risk requiring formal documented agreement.
Question 36: A water cannon (fire hose used as a security measure) is best employed against which type of threat?
- Stowaways already aboard
- Smuggling of contraband in cargo containers
- Cyber intrusions targeting the ship's IT systems
- Small craft attempting to come alongside or board (Correct answer)
Correct answer: Small craft attempting to come alongside or board
Water cannons create a physical deterrent against small craft approaching the vessel and can repel boarding attempts without lethal force.
Question 37: Which type of training exercise involves all relevant ship and shore-based personnel responding to a simulated security scenario in real time without advance notice of the scenario content?
- Scheduled drill
- Orientation briefing
- Unannounced full-scale security exercise (Correct answer)
- Tabletop exercise
Correct answer: Unannounced full-scale security exercise
An unannounced full-scale exercise tests genuine readiness by preventing advance preparation, revealing true competence levels and system reliability.
Question 38: Which of the following is considered a primary threat category in maritime security risk assessment?
- Navigational hazards
- Equipment maintenance failures
- Cargo weight imbalance
- Acts of terrorism or piracy (Correct answer)
Correct answer: Acts of terrorism or piracy
Acts of terrorism, piracy, and armed robbery against ships are the primary threat categories addressed in maritime security risk assessments.
Question 39: What is the purpose of a Ship Security Drill?
- To rehearse response to security threats (Correct answer)
- To assess cargo handling efficiency
- To evaluate meal service during crises
- To clean restricted areas
Correct answer: To rehearse response to security threats
Ship Security Drills are mandatory exercises designed to ensure that the crew is proficient in responding to various security threats, such as piracy, terrorism, or unauthorized access. These drills allow the crew to practice their roles and responsibilities outlined in the Ship Security Plan. Regular rehearsals improve coordination, communication, and overall preparedness, enhancing the ship's ability to effectively mitigate security incidents.
Question 40: Under Security Level 3, which action is most appropriate for the Ship Security Officer?
- Implementing all measures specified in the Ship Security Plan for Level 3 (Correct answer)
- Reducing crew access to secure areas only
- Maintaining normal security watch rotations
- Requesting a Declaration of Security from the nearest port
Correct answer: Implementing all measures specified in the Ship Security Plan for Level 3
At Security Level 3, the SSO must implement all specific security measures identified in the SSP for that level, as an imminent attack is probable or has occurred.
Question 41: Ship Security Alert System (SSAS) requirements are specified in which SOLAS regulation?
- SOLAS XI-2/6 (Correct answer)
- SOLAS XI-2/9
- SOLAS XI-1/5
- SOLAS V/19
Correct answer: SOLAS XI-2/6
SOLAS Regulation XI-2/6 mandates that ships be fitted with a Ship Security Alert System to transmit a covert distress signal.
Question 42: Which of the following best describes the purpose of conducting a security equipment inventory audit as part of the Ship Security Plan?
- To verify that all required security equipment is present, serviceable, and accounted for against the plan's specifications (Correct answer)
- To satisfy cargo insurance underwriters who require an annual equipment count
- To determine the resale value of aging security equipment for budget planning
- To compare the vessel's equipment inventory against competitor ships in the same fleet
Correct answer: To verify that all required security equipment is present, serviceable, and accounted for against the plan's specifications
An inventory audit confirms that every piece of security equipment listed in the Ship Security Plan is physically present and in working condition, ensuring plan compliance.
Question 43: What is the function of an 'anti-piracy citadel' on a vessel?
- A secure cargo hold designed to prevent theft of high-value goods
- A gun turret for defensive fire against pirates
- A reinforced room where crew can shelter and maintain communications with authorities during a piracy attack (Correct answer)
- A raised observation platform for security watch-keeping
Correct answer: A reinforced room where crew can shelter and maintain communications with authorities during a piracy attack
A citadel is a designated, hardened compartment where crew can shelter during a piracy attack, with independent communications to alert authorities while the vessel is boarded.
Question 44: Why is security equipment calibration and testing documentation important during a Port State Control (PSC) inspection?
- It is required only for vessels carrying dangerous goods
- It demonstrates to inspectors that equipment is maintained in operational condition and deficiencies are being tracked (Correct answer)
- PSC officers use calibration data to calculate the vessel's cargo capacity
- Calibration certificates replace the need for a current Ship Security Certificate
Correct answer: It demonstrates to inspectors that equipment is maintained in operational condition and deficiencies are being tracked
PSC inspectors review maintenance and testing records to verify that security equipment is operationally ready and that the ship is managing deficiencies in compliance with the ISPS Code.
Question 45: The ISPS Code defines a 'security incident' as:
- Any fire or flooding on board
- Any stowaway discovery
- Any suspicious act or circumstance threatening ship, port, or person security (Correct answer)
- Any crew injury during cargo operations
Correct answer: Any suspicious act or circumstance threatening ship, port, or person security
A security incident is any suspicious act or circumstance threatening the security of a ship, port facility, or any person therein.
Question 46: Which document proves a ship's compliance with the ISPS Code?
- Cargo Manifest
- International Ship Security Certificate (Correct answer)
- Ship Registry Certificate
- Classification Certificate
Correct answer: International Ship Security Certificate
The International Ship Security Certificate (ISSC) is issued to a ship after it has been verified to comply with the requirements of the International Ship and Port Facility Security (ISPS) Code. This certificate serves as official proof that the ship's security arrangements, including its Ship Security Plan, meet international standards.
Question 47: Which document contains the specific security procedures and measures a ship must follow at each security level?
- Ship Security Plan (SSP) (Correct answer)
- Maritime Declaration of Health
- International Safety Management (ISM) Code Certificate
- Continuous Synopsis Record
Correct answer: Ship Security Plan (SSP)
The Ship Security Plan (SSP) contains all security procedures, measures, and actions the ship must implement at Security Levels 1, 2, and 3.
Question 48: If a ship arrives at a port without having communicated its security information as required, what measure can the port state take?
- Require the Master to resubmit the DoS
- Automatically grant entry with enhanced inspection
- Deny entry or detain the ship (Correct answer)
- Issue a provisional ISSC
Correct answer: Deny entry or detain the ship
Port states may deny entry or detain a ship that has not provided the required pre-arrival security information under SOLAS XI-2/9.
Question 49: What should a Ship Security Officer do immediately upon receiving credible information about a specific threat to the vessel?
- Notify the Master and Company Security Officer and implement appropriate security measures (Correct answer)
- Dismiss the information if the ship is already at Security Level 1
- Independently investigate the threat before reporting it
- Wait until arriving at the next port before reporting
Correct answer: Notify the Master and Company Security Officer and implement appropriate security measures
The SSO must immediately notify the Master and CSO upon receiving credible threat information so that appropriate security level measures can be implemented without delay.
Question 50: In maritime contract law, what does the term 'indemnity' mean in the context of letters of indemnity (LOI)?
- A warranty of seaworthiness provided by the shipowner
- A guarantee that cargo arrives undamaged
- Insurance coverage arranged by the charterer
- A promise by one party to compensate another for losses arising from a specific action, such as releasing cargo without the original bill of lading (Correct answer)
Correct answer: A promise by one party to compensate another for losses arising from a specific action, such as releasing cargo without the original bill of lading
An LOI is a contractual promise to hold the carrier harmless from any resulting liability when cargo is released without presentation of the original bill of lading.
Question 51: When conducting a threat assessment, the SSO should consider which combination of factors?
- The ship type, cargo, trading routes, and regional threat intelligence (Correct answer)
- Only incidents that have previously occurred on the vessel itself
- The ship's profitability and commercial routes only
- The personal security history of each crew member only
Correct answer: The ship type, cargo, trading routes, and regional threat intelligence
A comprehensive threat assessment combines ship-specific factors such as type, cargo, and routes with available intelligence about threats in the regions the ship will transit.
Question 52: Who has the primary authority to set the security level for a ship operating within a port?
- The Master of the ship
- The Contracting Government of the port state (Correct answer)
- The Ship Security Officer
- The Company Security Officer
Correct answer: The Contracting Government of the port state
The Contracting Government (port state) sets the security level for ships operating in its waters and ports.
Ship Security Officer (SSO) Certification Exam
This certification is for individuals designated to ensure the security of a ship, including implementing and maintaining the ship security plan, conducting security inspections, and coordinating with port facility security officers.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds