Exam Mode

ISO/IEC 27001 Lead Auditor

Audit an information security management system

The six exams, one by one

ExamFormatQuestions
1Domain training50
2Domain training50
3Domain training50
4Domain training50
5Timed simulation80
6Timed simulation80

The report you get at the end

Not a percentage: a diagnosis. We tell you whether it is worth sitting the exam, which domains to reinforce and how many answers you got right while unsure.

Sample reportYou would pass, but with no margin
Fundamental principles and concepts of an ISMS78%
Conducting an ISO/IEC 27001 audit64%
Information security management system (ISMS)55%
Fundamental audit concepts and principles82%
Preparing an ISO/IEC 27001 audit70%
Managing an ISO/IEC 27001 audit programme61%
Closing an ISO/IEC 27001 audit74%

The domains assessed

Actual distribution of this product questions.

Fundamental principles and concepts of an ISMS78
Conducting an ISO/IEC 27001 audit76
Information security management system (ISMS)50
Fundamental audit concepts and principles50
Preparing an ISO/IEC 27001 audit38
Managing an ISO/IEC 27001 audit programme36
Closing an ISO/IEC 27001 audit32

Ten sample exam questions

One per competency domain, exactly as they appear in the simulator.

  1. Fundamental principles and concepts of an ISMS

    The audit focuses on the security property that provides assurance that a message or transaction genuinely originates from the claimed source, and not from a third party impersonating it. Which fundamental property is this?

    1. Availability, the property of being accessible and usable on demand by an authorized entity.
    2. Integrity, the property of accuracy and completeness of information and assets.
    3. Confidentiality, the property that information is not made available or disclosed to unauthorized entities.
    4. Authenticity, the property that guarantees an entity - a user, a process or a source - is indeed the one whose identity is claimed.
  2. Information security management system (ISMS)

    In ISO/IEC 27001:2022, which clauses carry the certifiable ISMS requirements that an audit verifies?

    1. Clauses 1 to 3, which carry the certifiable ISMS requirements, normative references and definitions included.
    2. Clauses 4 to 10, from context through improvement, which make up the certifiable requirements of the ISMS.
    3. Annex A, whose controls constitute the requirements verified at certification, on the same footing as the standard's management system clauses.
    4. Clauses 4 to 8, since continual improvement is treated as a recommendation.
  3. Fundamental audit concepts and principles

    Three concepts from ISO 19011:2018 structure every audit: audit evidence, audit findings and audit criteria. How do these three concepts differ from one another?

    1. Audit evidence refers to the result obtained once the facts gathered have been compared against the criteria; it therefore merges with the audit findings.
    2. Audit evidence brings together the verifiable facts collected; the findings result from comparing that material against the criteria; the audit criteria provide the reference for this comparison.
    3. Audit criteria are records or verifiable facts gathered in the field, in other words audit evidence, which the team logs over the course of the interviews and site walkthroughs conducted at the auditee's premises.
    4. An audit finding is the set of requirements and policies serving as the reference for the audit, in other words the benchmark.
  4. Preparing an ISO/IEC 27001 audit

    The audit scope and the scope of the information security management system (ISMS) are two notions an auditor must carefully distinguish. Which statement correctly establishes the difference between them?

    1. The audit scope always coincides with the scope of the ISMS, because an audit necessarily addresses the full extent of the management system operated by the organization across all of its sites and units.
    2. The audit scope refers to the extent and boundaries of the audit in question, whereas the scope of the ISMS delimits what the organization has decided to cover with its management system.
    3. The scope of the ISMS is the set of requirements and policies serving as the reference against which the audit compares the evidence.
    4. The audit scope merges with the audit plan: it corresponds to the schedule and the resources allocated to the engagement, together with the division of work among the members of the team deployed.
  5. Fundamental principles and concepts of an ISMS

    While examining logs, an auditor focuses on the property that makes it possible to attribute an action or event unambiguously to the entity that performed it. Which information security property corresponds precisely to this requirement for traceability of actions?

    1. Availability: information is accessible and usable on demand by an authorized entity, including during periods of heavy demand on the systems.
    2. Confidentiality: information is not made available or disclosed to unauthorized entities.
    3. Accountability, the property that guarantees traceability: it links an action or event without ambiguity to the entity that performed it.
    4. Integrity: the property of accuracy and completeness, guaranteeing that information is not altered without authorization during its processing or storage.
  6. Information security management system (ISMS)

    How do ISO/IEC 27001:2022 and ISO/IEC 27002:2022 differ from each other in status?

    1. ISO/IEC 27001 provides guidance for implementation while ISO/IEC 27002 carries the certifiable requirements.
    2. ISO/IEC 27001 carries the certifiable requirements, while ISO/IEC 27002 provides implementation guidance that is complementary but not a basis for certification in isolation.
    3. Both standards carry complementary certifiable requirements, with the certification audit verifying the organization's conformity to ISO/IEC 27001 and to ISO/IEC 27002 alike.
    4. ISO/IEC 27002 constitutes, in its own right, a certification standard for organizations.
  7. Fundamental audit concepts and principles

    FabriTech, a multi-site manufacturing group, is audited in turn by its own teams, by a major customer and by a certification body. How are these three audits classified under ISO 19011:2018?

    1. The first-party audit would be the one performed by an independent certification body, under what is known as the third-party route.
    2. The second-party audit would be the internal audit FabriTech conducts on itself with its own auditors, as part of the oversight the organization exercises over its own management system.
    3. The first-party audit is internal, the second-party audit is conducted by an interested party such as a customer, and the third-party audit by an independent certification body.
    4. The third-party audit would be the one a customer carries out at its supplier's site to verify contractual commitments.
  8. Preparing an ISO/IEC 27001 audit

    MetroCounty, a multi-site local authority, is putting in place a multi-year audit programme and is preparing, for each site, a document specific to the audit concerned. How do the audit programme and the audit plan differ?

    1. The audit programme and the audit plan designate the same document, describing the conduct of a given audit.
    2. The audit plan encompasses the audit programme: it covers the full set of audits for the period, each programme being one local offshoot of it, in a reversal of their true hierarchical relationship.
    3. The audit programme covers the full set of audits planned for a given period, while the audit plan describes the conduct of one specific audit.
    4. The audit programme is the set of requirements and procedures serving as the reference for the audits of the period.
  9. Fundamental principles and concepts of an ISMS

    An organization wants to be able to prove that an event actually took place and that a party will not be able to deny its occurrence later. Which information security property meets this precise need, as distinct from the mere verification of the identity an entity claims?

    1. Reliability: the property of consistent intended behaviour and results over time in a system or process.
    2. Authenticity: the property that guarantees an entity is indeed the one whose identity is claimed, without, however, making it possible to prove that a given act was performed.
    3. Availability: the property of being accessible when needed by an authorized entity, through keeping services in operational condition.
    4. Non-repudiation: the ability to prove the occurrence of an event or action so that it cannot subsequently be disputed.
  10. Information security management system (ISMS)

    What role does Annex A of ISO/IEC 27001:2022 play in the ISMS approach?

    1. To provide a reference set of information security controls, aligned with ISO/IEC 27002, drawn upon at clause 6.1.3 to determine the necessary controls.
    2. To impose every one of its controls as mandatory for any organization pursuing certification.
    3. To serve as an indicative catalogue, separate from the Statement of Applicability, each organization being free to build its list of controls from other recognized frameworks.
    4. To constitute the ISMS requirement clauses, on the same footing as context or leadership.

Answer these same ten questions in the simulator and see the explanation of every option, including the wrong ones. It opens with no sign-up →

About the official exam: its format, duration and number of questions are set by the certification body and may change, so confirm them in its documentation before you sit it. This material trains the standard, not one body's exam, so it is just as useful if you certify elsewhere.

How to use it

  1. Start in guided practice: every answer is marked and explained right away.
  2. Move to timed exam mode once you know the material.
  3. Repeat until you clear 90 %, the threshold we recommend before sitting the real exam.
  4. Work on the domains flagged in red before trying again.

Frequently asked questions

Is this the official exam?

No. It is our own preparation material, with original questions. It is neither affiliated with nor endorsed by any certification body.

How long do I have access?

Twelve months from purchase, the same validity as the official retake.

Can I try it first?

Yes, in three steps. Answer 10 questions from exam 1 with no sign up, with an explanation for every option. Leaving your email opens the whole of exam 1. All six exams are activated with the purchase.

Which languages?

Shown on each product. This one is available in the languages listed above.

The training for this certification

If beyond practising you want the full material, the exam and the certificate, this is the ISO/IEC 27001 Lead Auditor training.

See the training

All exams