The six exams, one by one
| Exam | Format | Questions |
|---|---|---|
| 1 | Domain training | 40 |
| 2 | Domain training | 40 |
| 3 | Domain training | 40 |
| 4 | Domain training | 40 |
| 5 | Timed simulation | 40 |
| 6 | Timed simulation | 40 |
The report you get at the end
Not a percentage: a diagnosis. We tell you whether it is worth sitting the exam, which domains to reinforce and how many answers you got right while unsure.
The domains assessed
Actual distribution of this product questions.
Ten sample exam questions
One per competency domain, exactly as they appear in the simulator.
-
Domain 2: DORA requirements for an ICT risk framework
What is the register of information that financial entities must maintain, and at which levels is it kept?
- A record of all contractual arrangements on the use of ICT services, kept at entity, sub-consolidated and consolidated levels.
- A record of the ICT assets classified as critical, kept by each business unit, consolidated yearly, and given to the auditor.
- A record of the incidents reported during the year, kept at entity level, and filed with the annual financial statements.
- A record of the vulnerabilities detected during testing, kept by the tester, and shared with the competent authority.
-
Domain 1: Fundamental concepts of ICT risk and resilience
A financial entity is identified as an essential entity under the national rules transposing Directive (EU) 2022/2555. How does DORA position itself in relation to that Directive?
- DORA suspends the whole of the Directive for the financial sector, so none of the obligations arising from it can reach the entity.
- DORA counts as a sector-specific Union legal act for the purposes of Article 4 of that Directive, so its rules apply instead.
- DORA applies where the entity has no obligation under the Directive, which the competent authority then assesses case by case.
- DORA and the Directive apply cumulatively in full, so the entity has to run two separate frameworks and two incident channels.
-
Domain 2: DORA requirements for an ICT risk framework
For which ICT services must a financial entity put exit strategies in place, and what must those strategies allow?
- For services supporting critical or important functions, allowing the entity to leave without disrupting its business or harming clients.
- For each service contracted with a provider that is established outside the Union, allowing full repatriation of the data within thirty days.
- For services whose annual cost exceeds the threshold set in the procurement policy, allowing the price to be renegotiated.
- For services provided by an intra-group provider, allowing the group to reallocate the function to another of its subsidiaries.
-
Domain 1: Fundamental concepts of ICT risk and resilience
Chapter II of DORA is not applied in identical terms by every financial entity. Which factors govern how demanding its implementation is for a given entity?
- The annual turnover of the entity, its balance sheet total and its headcount, measured against the thresholds for microenterprises.
- The size and overall risk profile of the entity, and the nature, scale and complexity of its services, activities and operations.
- The number of ICT third-party service providers under contract, their location and their size, which drive the exposure of an entity.
- The supervisory category assigned by the competent authority, which grades every entity as low, medium or high risk each year.
-
Domain 2: DORA requirements for an ICT risk framework
Why does Article 24(1) require certain financial entities to establish, maintain and review a testing programme as part of their framework?
- To assess preparedness for handling incidents, identify weaknesses and gaps, and implement corrective measures promptly.
- To obtain an attestation from the competent authority, presented to its clients, its counterparts and its auditors.
- To demonstrate to the provider that its services meet the levels agreed, as set out in the contractual arrangement.
- To replace the internal audit of the framework, which becomes unnecessary once the programme is in operation.
-
Domain 1: Fundamental concepts of ICT risk and resilience
During a large scale outage of one data centre, a bank keeps its payment service running and then returns to normal operation. Which concept of the Regulation does that behaviour illustrate?
- Security of network and information systems, understood as the protection of those systems against unauthorised access.
- ICT concentration risk, understood as the dependency created by relying on one provider for a critical service.
- Business impact analysis, understood as the assessment in advance of the effects of severe business disruptions.
- Digital operational resilience, understood as the ability to keep delivering services throughout disruptions.
-
Domain 2: DORA requirements for an ICT risk framework
The ICT risk management framework must include a digital operational resilience strategy. What is that strategy required to set out?
- The inventory of ICT assets classified as critical, the supplier that operates each of them, and the class given to each one.
- The remuneration policy for ICT staff, aligned with the measured performance of the systems that they administer.
- The templates used to report major incidents, the deadlines that apply to each report, and the channel used to send them.
- How the framework is to be implemented, including the risk tolerance level and clear information security objectives.
-
Domain 1: Fundamental concepts of ICT risk and resilience
A security team receives intelligence that a criminal group is preparing a campaign against institutions of its type, although nothing has happened yet. How does the Regulation classify that situation?
- As an ICT-related incident, since the information reached the entity and had to be logged as one.
- As a major ICT-related incident, since a campaign aimed at the sector would have a high adverse impact.
- As a cyber threat, since it describes a potential circumstance that has not yet materialised anywhere.
- As an operational or security payment-related incident, since payment services are the likely target.
-
Domain 2: DORA requirements for an ICT risk framework
When a financial entity restores backup data using its own systems, what does DORA require of the systems used for that restoration?
- That they be operated by a provider in the Union, under a written contract, and with full rights of audit and access.
- That they be located in a different Member State, so that a national disruption cannot affect the two sites at once.
- That they be physically and logically segregated from the source system, and protected from unauthorised access.
- That they be certified by an accreditation body, tested in advance, and kept under the access rules of the live data.
-
Domain 1: Fundamental concepts of ICT risk and resilience
An entity records that an unpatched remote access gateway could be used by a criminal group to reach its customer database. In risk terms, what is the unpatched gateway?
- The vulnerability, because it is the weakness that would have to be exploited.
- The threat, because it is what could cause harm to the operations of the entity.
- The asset, because it is the item of value that the entity is trying to protect.
- The impact, because it is the consequence that the entity would have to absorb.
About the official exam: its format, duration and number of questions are set by the certification body and may change, so confirm them in its documentation before you sit it. This material trains the standard, not one body's exam, so it is just as useful if you certify elsewhere.
How to use it
- Start in guided practice: every answer is marked and explained right away.
- Move to timed exam mode once you know the material.
- Repeat until you clear 90 %, the threshold we recommend before sitting the real exam.
- Work on the domains flagged in red before trying again.
Frequently asked questions
Is this the official exam?
No. It is our own preparation material, with original questions. It is neither affiliated with nor endorsed by any certification body.
How long do I have access?
Twelve months from purchase, the same validity as the official retake.
Can I try it first?
Yes, in three steps. Answer 10 questions from exam 1 with no sign up, with an explanation for every option. Leaving your email opens the whole of exam 1. All six exams are activated with the purchase.
Which languages?
Shown on each product. This one is available in the languages listed above.
The training for this certification
If beyond practising you want the full material, the exam and the certificate, this is the DORA Foundation training.
Exam Mode is preparation material produced by RRSG. It is not an official examination and it is neither affiliated with nor endorsed by any certification body. Questions are original, written from the standard and from publicly available programme information, and do not reproduce the real exam.