The six exams, one by one
| Exam | Format | Questions |
|---|---|---|
| 1 | Domain training | 50 |
| 2 | Domain training | 50 |
| 3 | Domain training | 50 |
| 4 | Domain training | 50 |
| 5 | Timed simulation | 80 |
| 6 | Timed simulation | 80 |
The report you get at the end
Not a percentage: a diagnosis. We tell you whether it is worth sitting the exam, which domains to reinforce and how many answers you got right while unsure.
The domains assessed
Actual distribution of this product questions.
Ten sample exam questions
One per competency domain, exactly as they appear in the simulator.
-
Domain 2: Preparing and planning
Scenario: Asteria Bank (bank) is preparing for DORA compliance. Two critical/important functions are in scope: (1) online customer access and (2) payment processing. Both rely on a single cloud platform provider. Documentation is fragmented: the application inventory is incomplete, contract owners are unclear, and there is no evidence index. Senior management requests a risk-based, proportionate plan with clear ownership and milestones. Question: Based on the scenario, what is the MOST appropriate first action to establish effective programme control?
- Immediately execute an advanced Threat-Led Penetration Test (TLPT) to identify cloud vulnerabilities
- Immediately renegotiate the cloud platform provider contract to include DORA clauses
- Commission an independent external audit to benchmark compliance maturity against peer institutions before defining any governance or scope
- Define governance (roles/decision rights) and agree on a scoped roadmap linked to critical functions
-
Domain 1: Fundamental concepts
Scenario: Asteria Bank (bank) is preparing for DORA compliance. Two critical/important functions are in scope: (1) online customer access and (2) payment processing. Both rely on a single cloud platform provider. Documentation is fragmented: the application inventory is incomplete, contract owners are unclear, and there is no evidence index. Senior management requests a risk-based, proportionate plan with clear ownership and milestones. Question: Which statement best reflects a proportionate approach in the scenario?
- Outsource the proportionality assessment entirely to an external auditor and adopt their recommendations without internal review
- Apply the exact same level of rigorous security testing and oversight to all third-party vendors without adjusting for the services provided
- Exempt the cloud platform provider from oversight since they already hold international security certifications like ISO 27001
- Tailor control depth and testing frequency based on critical function impact and risk, while meeting minimum obligations
-
Domain 4: Testing and third-party risk
Scenario: Asteria Bank (bank) is preparing for DORA compliance. Two critical/important functions are in scope: (1) online customer access and (2) payment processing. Both rely on a single cloud platform provider. Documentation is fragmented: the application inventory is incomplete, contract owners are unclear, and there is no evidence index. Senior management requests a risk-based, proportionate plan with clear ownership and milestones. Question: Which contractual element is MOST important to confirm early for a critical provider relationship?
- A guaranteed fixed pricing clause with annual cost reductions over the contract term
- Audit/inspection and access rights, including governance for subcontractors where relevant
- A clause transferring all regulatory accountability and financial liability for downtime to the cloud provider
- A strict commitment that the provider will never use subcontractors for any part of the service
-
Domain 5: Review and improvement
Scenario: Asteria Bank (bank) is preparing for DORA compliance. Two critical/important functions are in scope: (1) online customer access and (2) payment processing. Both rely on a single cloud platform provider. Documentation is fragmented: the application inventory is incomplete, contract owners are unclear, and there is no evidence index. Senior management requests a risk-based, proportionate plan with clear ownership and milestones. Question: Which practice would best support continual improvement of the programme over time?
- Regularly review monitoring, incident, and test results and drive corrective actions through governance
- Waiting for the competent authority to perform an audit and using their findings as the sole driver for improvements
- Relying exclusively on automated continuous monitoring dashboards without human governance oversight or decision-making
- Conducting a one-off gap assessment against DORA and archiving the results once the compliance deadline is met
-
Domain 3: Incident management
Scenario: During peak hours, Asteria Bank experiences a prolonged outage affecting payment processing. Investigation indicates a provider deployment introduced a misconfiguration. Monitoring detected the issue, but escalation was slow because incident classification thresholds are not consistently understood. Management wants to improve incident handling, strengthen provider oversight, and validate resilience through testing. Question: What is the MOST appropriate immediate action once the disruption is detected and impacts a critical/important function?
- Disconnect the entire payment processing infrastructure from the internet to contain the issue
- Convene an emergency board meeting before taking any technical containment or classification measures
- Immediately draft the initial notification report for the competent authority before assessing the impact
- Activate incident response, classify the incident using defined criteria, and escalate according to the procedure
-
Domain 2: Preparing and planning
Scenario: Asteria Bank (bank) is preparing for DORA compliance. Two critical/important functions are in scope: (1) online customer access and (2) payment processing. Both rely on a single cloud platform provider. Documentation is fragmented: the application inventory is incomplete, contract owners are unclear, and there is no evidence index. Senior management requests a risk-based, proportionate plan with clear ownership and milestones. Question: Which deliverable would most directly improve traceability and evidence readiness in this scenario?
- A comprehensive vulnerability scanning report for the cloud platform
- An updated Information Security Policy document approved by the management body
- A compliance tracker that links requirements to evidence (policies, procedures, records) and owners
- A formal letter from the cloud provider certifying DORA-readiness of their platform
-
Domain 1: Fundamental concepts
Which statement best defines Risk?
- The effect of uncertainty on objectives, typically expressed via sources, events, consequences, and likelihood.
- The total number of unpatched vulnerabilities identified in the latest scan
- The certainty of financial loss due to a cybersecurity breach.
- The daily operational cost of maintaining legacy ICT systems.
-
Domain 4: Testing and third-party risk
Scenario: During peak hours, Asteria Bank experiences a prolonged outage affecting payment processing. Investigation indicates a provider deployment introduced a misconfiguration. Monitoring detected the issue, but escalation was slow because incident classification thresholds are not consistently understood. Management wants to improve incident handling, strengthen provider oversight, and validate resilience through testing. Question: Which testing activity is MOST appropriate to validate resilience after remediation of the scenario's weakness?
- Hiring a Red Team to perform an unannounced, full-scale attack on the cloud provider's production environment
- A targeted exercise/test focused on the affected service path and recovery procedures, with remediation tracking
- Reviewing the vendor's Service Level Agreement (SLA) reports from the previous year
- Immediately migrating the affected critical function to a new cloud provider before testing or analysing the root cause
-
Domain 5: Review and improvement
Scenario: During peak hours, Asteria Bank experiences a prolonged outage affecting payment processing. Investigation indicates a provider deployment introduced a misconfiguration. Monitoring detected the issue, but escalation was slow because incident classification thresholds are not consistently understood. Management wants to improve incident handling, strengthen provider oversight, and validate resilience through testing. Question: After restoration, which action best supports continual improvement?
- Filing the incident ticket as 'Closed' since the service was fully restored and no customer data was compromised
- Issuing a public press release detailing the technical vulnerabilities that caused the outage to demonstrate transparency
- Conduct a post-incident review, capture lessons learned, and implement verified corrective actions
- Immediately changing the cloud platform provider to a different vendor to prevent recurrence
-
Domain 3: Incident management
Scenario: During peak hours, Asteria Bank experiences a prolonged outage affecting payment processing. Investigation indicates a provider deployment introduced a misconfiguration. Monitoring detected the issue, but escalation was slow because incident classification thresholds are not consistently understood. Management wants to improve incident handling, strengthen provider oversight, and validate resilience through testing. Question: Which improvement would most directly reduce the escalation delays described in the scenario?
- Requiring the management body (board of directors) to personally authorise the classification of every single IT incident
- Clear thresholds and role-based training for incident classification and escalation decision-making
- Adopting an incident classification scheme from another financial entity without adaptation to internal systems and risk profile
- Implementing a fully automated AI tool to handle all incident reporting without human intervention
About the official exam: its format, duration and number of questions are set by the certification body and may change, so confirm them in its documentation before you sit it. This material trains the standard, not one body's exam, so it is just as useful if you certify elsewhere.
How to use it
- Start in guided practice: every answer is marked and explained right away.
- Move to timed exam mode once you know the material.
- Repeat until you clear 90 %, the threshold we recommend before sitting the real exam.
- Work on the domains flagged in red before trying again.
Frequently asked questions
Is this the official exam?
No. It is our own preparation material, with original questions. It is neither affiliated with nor endorsed by any certification body.
How long do I have access?
Twelve months from purchase, the same validity as the official retake.
Can I try it first?
Yes, in three steps. Answer 10 questions from exam 1 with no sign up, with an explanation for every option. Leaving your email opens the whole of exam 1. All six exams are activated with the purchase.
Which languages?
Shown on each product. This one is available in the languages listed above.
The training for this certification
If beyond practising you want the full material, the exam and the certificate, this is the DORA Lead Manager training.
Exam Mode is preparation material produced by RRSG. It is not an official examination and it is neither affiliated with nor endorsed by any certification body. Questions are original, written from the standard and from publicly available programme information, and do not reproduce the real exam.