Exam Mode

ISO/IEC 27001 Lead Implementer

Implement and run the ISMS

The six exams, one by one

ExamFormatQuestions
1Domain training50
2Domain training50
3Domain training50
4Domain training50
5Timed simulation80
6Timed simulation80

The report you get at the end

Not a percentage: a diagnosis. We tell you whether it is worth sitting the exam, which domains to reinforce and how many answers you got right while unsure.

Sample reportYou would pass, but with no margin
D3 Planning of an ISMS implementation78%
D1 Fundamental principles and concepts of an ISMS64%
D4 Implementation of an ISMS55%
D2 ISMS requirements82%
D5 Monitoring and measurement of an ISMS70%
D6 Continual improvement of an ISMS61%
D7 Preparing for an ISMS certification audit74%

The domains assessed

Actual distribution of this product questions.

D3 Planning of an ISMS implementation81
D1 Fundamental principles and concepts of an ISMS68
D4 Implementation of an ISMS63
D2 ISMS requirements54
D5 Monitoring and measurement of an ISMS45
D6 Continual improvement of an ISMS27
D7 Preparing for an ISMS certification audit22

Ten sample exam questions

One per competency domain, exactly as they appear in the simulator.

  1. D1 Fundamental principles and concepts of an ISMS

    In ISO terminology, how should an audit procedure and the audit reports it generates be classified?

    1. The audit procedure is a document and the reports that it generates are records
    2. The audit procedure is a record and the audit reports are documents that support it
    3. Both are records, because both are produced by the audit process
    4. Both are documents, since a record is a subtype of document
  2. D2 ISMS requirements

    According to the course material, what does a good security architecture consist of?

    1. A hierarchy of policies, topic-specific policies and procedures approved by top management and reviewed at planned intervals by the ISMS manager
    2. An inventory of information assets with an owner assigned to each of them
    3. A schedule of technical tests, penetration tests and vulnerability scans covering every system that the organization runs in production
    4. A set of security services ensuring the safety of multiple processes, systems and applications
  3. D3 Planning of an ISMS implementation

    During the planning of an ISMS, a consultant tells the client that every good practice contained in the ISO guidelines used by the methodology must be adopted to obtain certification. How should this statement be evaluated?

    1. It is wrong, because a good practice is a recommendation and not a requirement, and each organization is free to use it as a reference
    2. It is correct, since the good practices of the ISO guidelines become mandatory requirements as soon as the organization decides to seek certification
    3. It is correct, because good practices are generally recognized by specialists and are therefore binding on every organization that applies the methodology
    4. It is wrong only for small organizations, which may skip the good practices that exceed their resources
  4. D4 Implementation of an ISMS

    An implementer is defining the header of the ISMS document template. Which pair of choices is recommended by the material?

    1. Identify the author and the approving body by the personal name of the individuals concerned, and use the format DD/MM/YY for every date appearing in the document and in its file name
    2. Identify the author and the approving body by role rather than by name, and use the format YYYY-MM-DD for dates so that files sort by date and are easier to search
    3. Omit any attribution of authorship, and date each version by the number of days elapsed since the ISMS was established
    4. Identify only the external consultant who reviewed the document, and date it with the calendar week number
  5. D5 Monitoring and measurement of an ISMS

    How is a nonconformity defined?

    1. A temporary interruption of services caused by scheduled maintenance activities that were planned and communicated to the users in advance
    2. The non-fulfilment of a requirement, be it a requirement of a standard, of an internal policy, of a law or of a contract
    3. A failure to communicate with the stakeholders of the organization effectively about the security of the information entrusted to it
    4. Any deviation from good practice that the auditee refuses to accept during the closing meeting of an internal or a certification audit
  6. D6 Continual improvement of an ISMS

    During the annual planning meeting, the ISMS manager of a logistics firm lists the change factors that must be monitored continually so the ISMS stays current. Which of the following items does NOT belong on that list?

    1. Technological changes
    2. External changes
    3. Product reviews
    4. Organizational changes
  7. D7 Preparing for an ISMS certification audit

    A national authority accredits the certification bodies operating in its country and has to be able to prove that it is competent and reliable in offering accreditation services. With which standard must it comply in order to prove it?

    1. ISO/IEC 17021-1, because it is the standard that governs bodies providing audit and certification of management systems
    2. ISO/IEC 17065, because it applies to bodies certifying products, processes and services offered to the public
    3. ISO/IEC 17011, because it lays down the general requirements for bodies that assess and accredit certification bodies
    4. ISO/IEC 17024, because it applies to the certification of persons against a defined certification scheme
  8. D1 Fundamental principles and concepts of an ISMS

    An organization wants to know exactly what it is obliged to do in order to claim conformity with an information security management system standard. Which statement correctly describes what ISO/IEC 27001 delivers?

    1. It specifies the requirements for establishing, implementing, maintaining and continually improving an ISMS, and for assessing and treating information security risks
    2. It provides the overview of the ISMS together with the terms and definitions used across the family
    3. It provides a reference set of generic controls accompanied by implementation guidance
    4. It provides guidelines for managing information security risk in any organization
  9. D2 ISMS requirements

    Why does the material recommend that employees holding important information security responsibilities take part in drafting, reviewing and validating the content of information security procedures and policies?

    1. Because ISO/IEC 27001 explicitly requires those employees to draft and approve the documented information of the management system
    2. Because it motivates them to contribute to the implementation of the controls
    3. Because it saves time and resources by cutting down the number of review cycles that the documents have to go through
    4. Because it transfers ownership of the residual risk from the risk owner to the persons who authored the procedure
  10. D3 Planning of an ISMS implementation

    How do the definitions of a policy and of a guideline differ?

    1. A policy is non-mandatory information leading to a compliant solution, whereas a guideline expresses the intentions and direction of an organization
    2. A policy is a type of guideline that provides guidance on different topics, and both are equally optional for the organization
    3. The two terms are interchangeable within the ISMS documentation set, since both simply describe how something should be done
    4. A policy expresses the intentions and direction of an organization as formally expressed by its top management, whereas a guideline is non-mandatory information leading to a compliant solution for the related requirement

Answer these same ten questions in the simulator and see the explanation of every option, including the wrong ones. It opens with no sign-up →

About the official exam: its format, duration and number of questions are set by the certification body and may change, so confirm them in its documentation before you sit it. This material trains the standard, not one body's exam, so it is just as useful if you certify elsewhere.

How to use it

  1. Start in guided practice: every answer is marked and explained right away.
  2. Move to timed exam mode once you know the material.
  3. Repeat until you clear 90 %, the threshold we recommend before sitting the real exam.
  4. Work on the domains flagged in red before trying again.

Frequently asked questions

Is this the official exam?

No. It is our own preparation material, with original questions. It is neither affiliated with nor endorsed by any certification body.

How long do I have access?

Twelve months from purchase, the same validity as the official retake.

Can I try it first?

Yes, in three steps. Answer 10 questions from exam 1 with no sign up, with an explanation for every option. Leaving your email opens the whole of exam 1. All six exams are activated with the purchase.

Which languages?

Shown on each product. This one is available in the languages listed above.

The training for this certification

If beyond practising you want the full material, the exam and the certificate, this is the ISO/IEC 27001 Lead Implementer training.

See the training

All exams