The six exams, one by one
| Exam | Format | Questions |
|---|---|---|
| 1 | Domain training | 40 |
| 2 | Domain training | 40 |
| 3 | Domain training | 40 |
| 4 | Domain training | 40 |
| 5 | Timed simulation | 40 |
| 6 | Timed simulation | 40 |
The report you get at the end
Not a percentage: a diagnosis. We tell you whether it is worth sitting the exam, which domains to reinforce and how many answers you got right while unsure.
The domains assessed
Actual distribution of this product questions.
Ten sample exam questions
One per competency domain, exactly as they appear in the simulator.
-
D1 Fundamental principles and concepts of an ISMS
What is the relationship between ISO/IEC 27001 and ISO/IEC 27002?
- ISO/IEC 27002 replaces ISO/IEC 27001 for organizations that, once certified, have reached a sufficient level of maturity
- ISO/IEC 27001 contains the certifiable requirements, while ISO/IEC 27002 provides guidance on the implementation of controls
- ISO/IEC 27002 contains the auditable requirements, and ISO/IEC 27001 merely gathers the common vocabulary of the family
- Both standards contain certifiable requirements, and an organization has to declare conformity with both at once
-
D2 Information security management system (ISMS)
An organization sets "improve the security of the systems" as its information security objective, with no further detail, and assigns neither an owner nor a deadline. Which requirement of ISO/IEC 27001 is this organization failing to meet?
- No requirement is breached here: the wording of information security objectives and their follow-up over time are left to the discretion of each organization, whatever its size
- The one in clause 5.2, because the objectives, their indicators, their resources, their owners and their deadlines have to appear, in detail, within the text of the information security policy itself
- The requirement of clause 9.1, which makes the establishment of objectives conditional on a prior measurement and evaluation of the information security performance of the previous year
- The one in clause 6.2, which requires measurable objectives consistent with the policy, with resources, an owner and a deadline
-
D1 Fundamental principles and concepts of an ISMS
How does a management system based on ISO/IEC 27001 help an organization to meet its legal obligations?
- By replacing the applicable legislation with the requirements of the standard, which are treated as equivalent for the purposes of legal compliance
- By transferring responsibility for legal compliance, in its entirety, to the body that issues the certificate, which would then answer to the authorities, the customers and the third parties concerned
- By exempting the organization from its sector obligations, in the areas covered by the audit, for as long as the certificate remains valid
- By requiring the applicable legal and contractual requirements to be identified and the approach adopted for meeting them to be defined, with follow-up
-
D2 Information security management system (ISMS)
The management committee of a company records in its context analysis the evolution of the sector, the regulatory changes and the arrival of new competitors, but leaves out its own organizational structure, its resources and its culture. What should be made of that analysis?
- It is correct, because clause 4.1 covers the issues that lie beyond the control of the organization, such as the market or the regulatory environment
- It is correct, because internal issues are dealt with later on, when the requirements of the interested parties are determined
- It is incomplete, because clause 4.1 requires the external issues but also the internal issues to be determined
- It is incomplete for an organization that intends to be certified by a third party, whereas an analysis of the external environment suffices in other cases
-
D1 Fundamental principles and concepts of an ISMS
According to the definition common to management system standards, what is a management system?
- A set of interrelated or interacting elements of an organization, used to establish policies and objectives, and processes to achieve those objectives
- The set of software applications, including document management applications, with which an organization administers its records and automates its workflows and its approval routes
- The organization chart, together with the description of the jobs and the reporting lines of each department
- The set of documents approved by top management, in which the work instructions that the personnel have to follow are recorded
-
D2 Information security management system (ISMS)
While a management system is being set up, the security manager draws up the list of interested parties and includes only the customers. What else has to be taken into account according to ISO/IEC 27001?
- Nothing, as long as the customers have formalized their security requirements in the signed contracts and their annexes
- The other relevant interested parties, together with their applicable requirements
- The suppliers with access to the systems, whether direct or through subcontractors; the risk analysis already covers the other interested parties
- The competent authorities and their legal requirements, leaving the other interested parties as a matter of voluntary inclusion
-
D1 Fundamental principles and concepts of an ISMS
How is the ISO/IEC 27001:2022 standard structured?
- In ten clauses of requirements, all of them auditable, followed by three informative annexes containing implementation examples and checklists
- In four introductory clauses and six chapters of technical controls, with no requirement relating to the management system
- In clauses 1 to 3 of an introductory nature, clauses 4 to 10 containing the requirements of the management system, and an Annex A with the reference controls
- In one part of requirements and one part of guidance, both of them mandatory in order to obtain certification and then to keep the certificate at the surveillance audits
-
D2 Information security management system (ISMS)
During an audit it is found that top management approved the information security policy but has not allocated resources, has not communicated the importance of the system and does not take part in the management review. What conclusion follows?
- There is a nonconformity with clause 5.1, because leadership and commitment require a set of actions that go well beyond approving the policy
- There is no nonconformity, because approving the policy is the only action that the standard requires of top management
- There is a nonconformity with clause 7.5, because the problem is that the policy is not properly documented and distributed
- There is no nonconformity, as long as there is an information security manager with authority expressly delegated in writing by top management
-
D1 Fundamental principles and concepts of an ISMS
Within the ISO/IEC 27000 family of standards, which standard brings together the terms and definitions as well as the overview of the series?
- ISO/IEC 27003, which develops the guidance for setting up the management system, together with the terms and definitions specific to that guidance within the family of standards
- ISO/IEC 27005, the guidance standard for information security risk management within the family
- ISO/IEC 27000, which provides the overview of the family and the vocabulary common to all its standards
- ISO/IEC 27004, which deals with monitoring, measurement, analysis and evaluation
-
D2 Information security management system (ISMS)
An organization has a general information security policy and wants to complete its internal body of policies. Which policy structure matches the practice reflected in ISO/IEC 27001?
- A high-level general policy, supported by high-level specific policies and by topic-specific policies that develop concrete subjects
- A single general policy covering the internal body of documents: multiplying normative documents harms their understanding, their distribution and their effective control by the personnel
- One policy for each Annex A control declared applicable, so that the body of policies mirrors the Statement of Applicability
- One policy per department, drafted and approved autonomously by the manager of each area
About the official exam: its format, duration and number of questions are set by the certification body and may change, so confirm them in its documentation before you sit it. This material trains the standard, not one body's exam, so it is just as useful if you certify elsewhere.
How to use it
- Start in guided practice: every answer is marked and explained right away.
- Move to timed exam mode once you know the material.
- Repeat until you clear 90 %, the threshold we recommend before sitting the real exam.
- Work on the domains flagged in red before trying again.
Frequently asked questions
Is this the official exam?
No. It is our own preparation material, with original questions. It is neither affiliated with nor endorsed by any certification body.
How long do I have access?
Twelve months from purchase, the same validity as the official retake.
Can I try it first?
Yes, in three steps. Answer 10 questions from exam 1 with no sign up, with an explanation for every option. Leaving your email opens the whole of exam 1. All six exams are activated with the purchase.
Which languages?
Shown on each product. This one is available in the languages listed above.
The training for this certification
If beyond practising you want the full material, the exam and the certificate, this is the ISO/IEC 27001 Foundation training.
Exam Mode is preparation material produced by RRSG. It is not an official examination and it is neither affiliated with nor endorsed by any certification body. Questions are original, written from the standard and from publicly available programme information, and do not reproduce the real exam.