Exam Mode

ISO 22301 Foundation

The fundamentals of business continuity

ISO 22301
Foundation
6 exams · 240 questions · 2 domains

The six exams, one by one

ExamFormatQuestions
1Domain training40
2Domain training40
3Domain training40
4Domain training40
5Timed simulation40
6Timed simulation40

The report you get at the end

Not a percentage: a diagnosis. We tell you whether it is worth sitting the exam, which domains to reinforce and how many answers you got right while unsure.

Sample reportYou would pass, but with no margin
D2 ISO 22301 requirements - Clauses 4 to 1078%
D1 Fundamental principles and concepts of a BCMS64%

The domains assessed

Actual distribution of this product questions.

D2 ISO 22301 requirements - Clauses 4 to 10180
D1 Fundamental principles and concepts of a BCMS60

Ten sample exam questions

One per competency domain, exactly as they appear in the simulator.

  1. D2 ISO 22301 requirements - Clauses 4 to 10

    Brantford Foods holds an ISO 22301 certificate, receives a surveillance audit from its certification body every year and is audited every two years by two large customers under a right of audit written into their supply contracts. On that basis the BCMS manager has stopped running the company's own audit programme, arguing that the BCMS is already audited twice over. How should that decision be judged against clause 9.2?

    1. Not acceptable: clause 9.2 asks the organisation to conduct internal audits of its own BCMS at planned intervals, and both of the audits described are external ones.
    2. Acceptable while the customer reports and the surveillance findings are tabled at the management review and the resulting actions are tracked to closure.
    3. Covered for the year in question: a surveillance audit examines the same BCMS against the same standard, so it discharges clause 9.2 for Brantford.
    4. Unacceptable, though for another reason: an audit by a customer is not independent of the commercial relationship, and the surveillance audits alone would have sufficed.
  2. D1 Fundamental principles and concepts of a BCMS

    How does ISO 22313 relate to ISO 22301?

    1. It adds a further set of requirements that an organisation certified to ISO 22301 has to satisfy at its next audit.
    2. It offers guidance on applying the requirements of ISO 22301, so nothing in it can be audited as a requirement in its own right.
    3. It supersedes ISO 22301 as the certifiable standard of the ISO 22300 family, which ISO 22301 now supports as its glossary.
    4. It supplies the vocabulary that ISO 22301 refers to normatively, so its definitions govern any disputed term.
  3. D2 ISO 22301 requirements - Clauses 4 to 10

    Kestrel Pharma has outsourced the cold chain distribution of its vaccines, a prioritised activity, to a logistics provider that holds an ISO 22301 certificate. Kestrel's continuity committee wants assurance that the provider can restore deliveries within the time frame set by Kestrel's own business impact analysis. Which course of action fits what ISO 22301 requires?

    1. Audit the provider itself under the right of audit in its contract, since the certificate was granted against the provider's own scope and not against Kestrel's recovery time frames.
    2. Add the provider to the internal audit programme required by clause 9.2 and record the visit as an internal audit, on the ground that the outsourced activity sits inside the scope of Kestrel's BCMS.
    3. Rely on the certification body that audits the provider and file a copy of the certificate, because a third party audit is more searching than anything Kestrel could organise.
    4. Ask the provider to assess itself against Kestrel's recovery requirements and to send the report, since clause 9.2 requires an internal audit and nothing more.
  4. D1 Fundamental principles and concepts of a BCMS

    An organisation certified to ISO/IEC 27001 is considering a BCMS based on ISO 22301. Which statement describes the relationship between the two standards?

    1. They are separate management system standards on the same harmonised structure: ISO/IEC 27001 addresses information security, ISO 22301 the continuity of products and services.
    2. Certification to ISO/IEC 27001 is a prerequisite for certification to ISO 22301, because a BCMS depends on an information security management system.
    3. ISO 22301 is an extension of ISO/IEC 27001 devoted to the availability of information, so its requirements are already met by existing security controls.
    4. The two overlap so far that an organisation conforming to one is presumed to conform to the other, and a single audit against either standard is accepted as evidence for both.
  5. D2 ISO 22301 requirements - Clauses 4 to 10

    A hospital group identified the laws and regulations applicable to the continuity of its services when it implemented its BCMS three years ago and filed the list. Nobody has revisited it since. What does clause 4.2 require of the organisation?

    1. To copy the full text of the applicable laws, regulations and codes into the BCMS documented information, so that staff can find and consult them.
    2. To revisit the list of legal, regulatory and contractual requirements once an incident, a complaint or an audit has revealed a breach.
    3. To operate a process that identifies, gives access to and assesses the applicable requirements, and to keep that documented information up to date.
    4. To transfer responsibility for legal and regulatory requirements to the legal department, which sits outside the boundaries of the BCMS.
  6. D1 Fundamental principles and concepts of a BCMS

    Which statement best reflects what business continuity means in ISO 22301?

    1. The capability of an organisation to continue delivering products and services within acceptable time frames at predefined capacity during a disruption.
    2. The set of technical measures that keeps the organisation's information systems available and its data backed up to a second data centre.
    3. The absence of any disruption, achieved by removing in advance every cause that could interrupt the organisation's prioritised activities.
    4. The process of returning the organisation to the exact state that it held before the incident, with the same staffing and capacity.
  7. D2 ISO 22301 requirements - Clauses 4 to 10

    During the design of a BCMS, a manager argues that every expectation voiced by any interested party has to become a requirement of the system. How should this be assessed against clause 4.2?

    1. The claim is too broad: clause 4.2 asks the organisation to determine which interested parties are relevant and which of their requirements are relevant to the BCMS.
    2. The manager is right: once an expectation has been recorded by the organisation, clause 4.2 turns it into a requirement of the BCMS.
    3. The view is too narrow: clause 4.2 recognises customers, regulators and shareholders, whose expectations bind the organisation, but not those of suppliers or employees.
    4. The question is premature: the requirements of interested parties are determined by the business impact analysis, which has not been carried out at this stage.
  8. D1 Fundamental principles and concepts of a BCMS

    Which description matches what ISO 22301 expects of a business continuity plan?

    1. Documented information that guides the organisation in responding to a disruption and in resuming and recovering its products and services.
    2. A risk treatment plan listing the controls chosen, their owners and their deadlines, to reduce the likelihood of disruption.
    3. A technical recovery procedure for restoring the IT systems and their data to the state they held before the disruption.
    4. A statement of the organisation's business continuity commitments, approved by top management and made available to interested parties.
  9. D2 ISO 22301 requirements - Clauses 4 to 10

    A utility company wants to leave one of its four service centres out of the scope of its BCMS because that centre is due to close in two years. What does ISO 22301 allow?

    1. It is allowed if the exclusion is documented and explained and does not affect the organisation's capability and responsibility to provide continuity of its products and services.
    2. It is not permitted: once an organisation seeks conformity with ISO 22301, the sites, activities and functions it operates have to sit inside the scope of the BCMS until they actually cease to operate.
    3. No formality is needed, because clause 4.3 leaves the boundaries, the applicability and the exclusions of the BCMS to the commercial judgement of the organisation.
    4. The exclusion is valid provided the centre is covered by a separate arrangement, agreed with its customers, its regulator and the local authorities, and reviewed yearly.
  10. D1 Fundamental principles and concepts of a BCMS

    Which outcome is produced by the business impact analysis (BIA) rather than by the risk assessment?

    1. A prioritised list of the threats that could interrupt the activities, with their likelihood and their possible causes.
    2. A decision on the risk treatment options that the organisation will apply to the threats it considers unacceptable.
    3. An evaluation of whether the existing protective controls hold the likelihood of a disruption at a tolerable level.
    4. The identification of the prioritised activities and of the time frames within which each of them has to be resumed.

Answer these same ten questions in the simulator and see the explanation of every option, including the wrong ones. It opens with no sign-up →

About the official exam: its format, duration and number of questions are set by the certification body and may change, so confirm them in its documentation before you sit it. This material trains the standard, not one body's exam, so it is just as useful if you certify elsewhere.

How to use it

  1. Start in guided practice: every answer is marked and explained right away.
  2. Move to timed exam mode once you know the material.
  3. Repeat until you clear 90 %, the threshold we recommend before sitting the real exam.
  4. Work on the domains flagged in red before trying again.

Frequently asked questions

Is this the official exam?

No. It is our own preparation material, with original questions. It is neither affiliated with nor endorsed by any certification body.

How long do I have access?

Twelve months from purchase, the same validity as the official retake.

Can I try it first?

Yes, in three steps. Answer 10 questions from exam 1 with no sign up, with an explanation for every option. Leaving your email opens the whole of exam 1. All six exams are activated with the purchase.

Which languages?

Shown on each product. This one is available in the languages listed above.

The training for this certification

If beyond practising you want the full material, the exam and the certificate, this is the ISO 22301 Foundation training.

See the training

All exams