Exam Mode

DORA Lead Manager

Digital operational resilience in finance

The six exams, one by one

ExamFormatQuestions
1Domain training50
2Domain training50
3Domain training50
4Domain training50
5Timed simulation80
6Timed simulation80

The report you get at the end

Not a percentage: a diagnosis. We tell you whether it is worth sitting the exam, which domains to reinforce and how many answers you got right while unsure.

Sample reportYou would pass, but with no margin
Domain 4: Testing and third-party risk78%
Domain 3: Incident management64%
Domain 2: Preparing and planning55%
Domain 5: Review and improvement82%
Domain 1: Fundamental concepts70%

The domains assessed

Actual distribution of this product questions.

Domain 4: Testing and third-party risk105
Domain 3: Incident management100
Domain 2: Preparing and planning56
Domain 5: Review and improvement52
Domain 1: Fundamental concepts47

Ten sample exam questions

One per competency domain, exactly as they appear in the simulator.

  1. Domain 2: Preparing and planning

    Scenario: Asteria Bank (bank) is preparing for DORA compliance. Two critical/important functions are in scope: (1) online customer access and (2) payment processing. Both rely on a single cloud platform provider. Documentation is fragmented: the application inventory is incomplete, contract owners are unclear, and there is no evidence index. Senior management requests a risk-based, proportionate plan with clear ownership and milestones. Question: Based on the scenario, what is the MOST appropriate first action to establish effective programme control?

    1. Immediately execute an advanced Threat-Led Penetration Test (TLPT) to identify cloud vulnerabilities
    2. Immediately renegotiate the cloud platform provider contract to include DORA clauses
    3. Commission an independent external audit to benchmark compliance maturity against peer institutions before defining any governance or scope
    4. Define governance (roles/decision rights) and agree on a scoped roadmap linked to critical functions
  2. Domain 1: Fundamental concepts

    Scenario: Asteria Bank (bank) is preparing for DORA compliance. Two critical/important functions are in scope: (1) online customer access and (2) payment processing. Both rely on a single cloud platform provider. Documentation is fragmented: the application inventory is incomplete, contract owners are unclear, and there is no evidence index. Senior management requests a risk-based, proportionate plan with clear ownership and milestones. Question: Which statement best reflects a proportionate approach in the scenario?

    1. Outsource the proportionality assessment entirely to an external auditor and adopt their recommendations without internal review
    2. Apply the exact same level of rigorous security testing and oversight to all third-party vendors without adjusting for the services provided
    3. Exempt the cloud platform provider from oversight since they already hold international security certifications like ISO 27001
    4. Tailor control depth and testing frequency based on critical function impact and risk, while meeting minimum obligations
  3. Domain 4: Testing and third-party risk

    Scenario: Asteria Bank (bank) is preparing for DORA compliance. Two critical/important functions are in scope: (1) online customer access and (2) payment processing. Both rely on a single cloud platform provider. Documentation is fragmented: the application inventory is incomplete, contract owners are unclear, and there is no evidence index. Senior management requests a risk-based, proportionate plan with clear ownership and milestones. Question: Which contractual element is MOST important to confirm early for a critical provider relationship?

    1. A guaranteed fixed pricing clause with annual cost reductions over the contract term
    2. Audit/inspection and access rights, including governance for subcontractors where relevant
    3. A clause transferring all regulatory accountability and financial liability for downtime to the cloud provider
    4. A strict commitment that the provider will never use subcontractors for any part of the service
  4. Domain 5: Review and improvement

    Scenario: Asteria Bank (bank) is preparing for DORA compliance. Two critical/important functions are in scope: (1) online customer access and (2) payment processing. Both rely on a single cloud platform provider. Documentation is fragmented: the application inventory is incomplete, contract owners are unclear, and there is no evidence index. Senior management requests a risk-based, proportionate plan with clear ownership and milestones. Question: Which practice would best support continual improvement of the programme over time?

    1. Regularly review monitoring, incident, and test results and drive corrective actions through governance
    2. Waiting for the competent authority to perform an audit and using their findings as the sole driver for improvements
    3. Relying exclusively on automated continuous monitoring dashboards without human governance oversight or decision-making
    4. Conducting a one-off gap assessment against DORA and archiving the results once the compliance deadline is met
  5. Domain 3: Incident management

    Scenario: During peak hours, Asteria Bank experiences a prolonged outage affecting payment processing. Investigation indicates a provider deployment introduced a misconfiguration. Monitoring detected the issue, but escalation was slow because incident classification thresholds are not consistently understood. Management wants to improve incident handling, strengthen provider oversight, and validate resilience through testing. Question: What is the MOST appropriate immediate action once the disruption is detected and impacts a critical/important function?

    1. Disconnect the entire payment processing infrastructure from the internet to contain the issue
    2. Convene an emergency board meeting before taking any technical containment or classification measures
    3. Immediately draft the initial notification report for the competent authority before assessing the impact
    4. Activate incident response, classify the incident using defined criteria, and escalate according to the procedure
  6. Domain 2: Preparing and planning

    Scenario: Asteria Bank (bank) is preparing for DORA compliance. Two critical/important functions are in scope: (1) online customer access and (2) payment processing. Both rely on a single cloud platform provider. Documentation is fragmented: the application inventory is incomplete, contract owners are unclear, and there is no evidence index. Senior management requests a risk-based, proportionate plan with clear ownership and milestones. Question: Which deliverable would most directly improve traceability and evidence readiness in this scenario?

    1. A comprehensive vulnerability scanning report for the cloud platform
    2. An updated Information Security Policy document approved by the management body
    3. A compliance tracker that links requirements to evidence (policies, procedures, records) and owners
    4. A formal letter from the cloud provider certifying DORA-readiness of their platform
  7. Domain 1: Fundamental concepts

    Which statement best defines Risk?

    1. The effect of uncertainty on objectives, typically expressed via sources, events, consequences, and likelihood.
    2. The total number of unpatched vulnerabilities identified in the latest scan
    3. The certainty of financial loss due to a cybersecurity breach.
    4. The daily operational cost of maintaining legacy ICT systems.
  8. Domain 4: Testing and third-party risk

    Scenario: During peak hours, Asteria Bank experiences a prolonged outage affecting payment processing. Investigation indicates a provider deployment introduced a misconfiguration. Monitoring detected the issue, but escalation was slow because incident classification thresholds are not consistently understood. Management wants to improve incident handling, strengthen provider oversight, and validate resilience through testing. Question: Which testing activity is MOST appropriate to validate resilience after remediation of the scenario's weakness?

    1. Hiring a Red Team to perform an unannounced, full-scale attack on the cloud provider's production environment
    2. A targeted exercise/test focused on the affected service path and recovery procedures, with remediation tracking
    3. Reviewing the vendor's Service Level Agreement (SLA) reports from the previous year
    4. Immediately migrating the affected critical function to a new cloud provider before testing or analysing the root cause
  9. Domain 5: Review and improvement

    Scenario: During peak hours, Asteria Bank experiences a prolonged outage affecting payment processing. Investigation indicates a provider deployment introduced a misconfiguration. Monitoring detected the issue, but escalation was slow because incident classification thresholds are not consistently understood. Management wants to improve incident handling, strengthen provider oversight, and validate resilience through testing. Question: After restoration, which action best supports continual improvement?

    1. Filing the incident ticket as 'Closed' since the service was fully restored and no customer data was compromised
    2. Issuing a public press release detailing the technical vulnerabilities that caused the outage to demonstrate transparency
    3. Conduct a post-incident review, capture lessons learned, and implement verified corrective actions
    4. Immediately changing the cloud platform provider to a different vendor to prevent recurrence
  10. Domain 3: Incident management

    Scenario: During peak hours, Asteria Bank experiences a prolonged outage affecting payment processing. Investigation indicates a provider deployment introduced a misconfiguration. Monitoring detected the issue, but escalation was slow because incident classification thresholds are not consistently understood. Management wants to improve incident handling, strengthen provider oversight, and validate resilience through testing. Question: Which improvement would most directly reduce the escalation delays described in the scenario?

    1. Requiring the management body (board of directors) to personally authorise the classification of every single IT incident
    2. Clear thresholds and role-based training for incident classification and escalation decision-making
    3. Adopting an incident classification scheme from another financial entity without adaptation to internal systems and risk profile
    4. Implementing a fully automated AI tool to handle all incident reporting without human intervention

Answer these same ten questions in the simulator and see the explanation of every option, including the wrong ones. It opens with no sign-up →

About the official exam: its format, duration and number of questions are set by the certification body and may change, so confirm them in its documentation before you sit it. This material trains the standard, not one body's exam, so it is just as useful if you certify elsewhere.

How to use it

  1. Start in guided practice: every answer is marked and explained right away.
  2. Move to timed exam mode once you know the material.
  3. Repeat until you clear 90 %, the threshold we recommend before sitting the real exam.
  4. Work on the domains flagged in red before trying again.

Frequently asked questions

Is this the official exam?

No. It is our own preparation material, with original questions. It is neither affiliated with nor endorsed by any certification body.

How long do I have access?

Twelve months from purchase, the same validity as the official retake.

Can I try it first?

Yes, in three steps. Answer 10 questions from exam 1 with no sign up, with an explanation for every option. Leaving your email opens the whole of exam 1. All six exams are activated with the purchase.

Which languages?

Shown on each product. This one is available in the languages listed above.

The training for this certification

If beyond practising you want the full material, the exam and the certificate, this is the DORA Lead Manager training.

See the training

All exams