Exam Mode

ISO/IEC 27005 Foundation

The fundamentals of information security risk management

ISO/IEC 27005
Foundation
6 exams · 240 questions · 2 domains

The six exams, one by one

ExamFormatQuestions
1Domain training40
2Domain training40
3Domain training40
4Domain training40
5Timed simulation40
6Timed simulation40

The report you get at the end

Not a percentage: a diagnosis. We tell you whether it is worth sitting the exam, which domains to reinforce and how many answers you got right while unsure.

Sample reportYou would pass, but with no margin
Domain 1: Fundamental information security risk concepts78%
Domain 2: Information security risk process and approaches64%

The domains assessed

Actual distribution of this product questions.

Domain 1: Fundamental information security risk concepts120
Domain 2: Information security risk process and approaches120

Ten sample exam questions

One per competency domain, exactly as they appear in the simulator.

  1. Domain 1: Fundamental information security risk concepts

    ISO/IEC 27005:2022 is made up of 10 clauses and one annex. Which description matches each part of the document with what that part provides?

    1. Clauses 1 to 4 set the risk criteria, clause 5 covers the risk treatment options, clauses 6 to 10 give the general information, and Annex A lists the controls to be implemented by the organization.
    2. Clauses 1 to 4 give general information, clause 5 introduces the risk management process with its cycles, clauses 6 to 10 develop the management activities, and Annex A gives examples of techniques.
    3. Clauses 1 to 4 define the terms used, clause 5 states the certification requirements, clauses 6 to 10 give the general information, and Annex A introduces the risk management cycles in detail.
    4. Clauses 1 to 5 give the general information, clauses 6 to 7 introduce the process together with its cycles, clauses 8 to 10 set the risk acceptance criteria, and Annex A covers the treatment options.
  2. Domain 2: Information security risk process and approaches

    A bank is listing the requirements that affect its information security risk management program. A code of practice for its industry sector that the bank adopted voluntarily has been filed under market requirements, and the delivery times that customers expect although no signed contract mentions them have been filed under internal policies. How should this filing be evaluated?

    1. The two items are misfiled, because a voluntarily adopted code of practice belongs to standards and an implicit expectation belongs to the market.
    2. Only the code of practice is misfiled, because an implicit trading expectation is set inside the organization and belongs to internal policies.
    3. Both items are filed correctly, because every voluntary requirement belongs to the market and every unwritten expectation belongs to internal policies.
    4. Both items belong to the laws and regulations source, because either one can expose business executives to prosecution at a criminal level.
  3. Domain 1: Fundamental information security risk concepts

    ISO/IEC 27005:2022 defines risk as the effect of uncertainty on objectives and attaches four notes to that definition. Which statement reproduces what those notes establish?

    1. Uncertainty is the complete absence of information about an event, and risk is usually expressed in terms of the assets affected, their monetary value, and the controls already in place.
    2. Uncertainty is a disagreement between analysts about an event, and risk is usually expressed in terms of the audit findings recorded, their severity, and the corrective actions pending.
    3. Uncertainty is the margin of error of a measuring instrument, and risk is usually expressed in terms of the controls selected, their annual cost, and the residual level finally accepted.
    4. Uncertainty is the state of deficiency of information about an event, and risk is usually expressed in terms of risk sources, potential events, their consequences and their likelihood.
  4. Domain 2: Information security risk process and approaches

    While establishing the context for a logistics company, a risk manager reviews a junior analyst's worksheet. The shortage of trained system administrators has been recorded as an opportunity, and the entry of a new competitor into the market has been recorded as a weakness. Which evaluation of the terminology used in that worksheet is accurate?

    1. The two entries are correctly labelled, because the weaknesses and opportunities of a SWOT analysis both cover external issues.
    2. Both entries should be swapped, because a PEST analysis covers the internal issues and a SWOT analysis covers the external ones.
    3. Both entries are wrongly labelled, because the strengths and weaknesses of a SWOT analysis cover internal issues of an organization.
    4. Only the competitor entry is wrongly labelled, because a staffing shortage counts as an opportunity and a competitor counts as a threat.
  5. Domain 1: Fundamental information security risk concepts

    Which wording reproduces the definition of an information security incident given in ISO/IEC 27005:2022?

    1. A single or a series of unwanted or unexpected information security events that have a significant probability of compromising business operations and threatening information security.
    2. A single or a series of weaknesses in an asset or a control that some existing threat must exploit before any damage or loss of essential services can occur in practice.
    3. A single or a series of risk-modifying measures, ranging from a policy or a documented procedure to an organizational structure of a managerial nature.
    4. A single or a series of terms of reference against which the significance of a risk is evaluated, derived from the objectives of an organization or from its applicable laws.
  6. Domain 2: Information security risk process and approaches

    A steering committee asks a risk manager to state, in exact terms, what ISO/IEC 27005 means by risk criteria and how that term relates to risk acceptance criteria. Which statement is accurate?

    1. Risk criteria are the terms of reference used to choose a treatment option, and risk acceptance criteria set the level at which treatment stops.
    2. Risk criteria are derived only from the organization's internal policies, and risk acceptance criteria come only from external legal requirements.
    3. Risk criteria are the categories used to describe consequences, and risk acceptance criteria are the categories used to describe likelihood.
    4. Risk criteria are the terms of reference against which the significance of a risk is evaluated, and risk acceptance criteria are one of the basic criteria.
  7. Domain 1: Fundamental information security risk concepts

    A technical scan reveals several weaknesses in an organization's systems, yet no loss has been recorded. Which statement explains, in the vocabulary of ISO/IEC 27005:2022, why those weaknesses have caused no damage on their own?

    1. A weakness produces no damage while classified as extrinsic, because external factors remain outside the boundaries the organization has defined for its own assets.
    2. A weakness produces no damage while it is recorded as a positive characteristic, because certain weaknesses are accepted for the sake of the outcomes associated with them.
    3. A weakness produces no damage by itself, because a threat has to exist and then exploit that weakness before the organization suffers any actual loss.
    4. A weakness produces no damage while it stays below the consequence criteria, because those criteria decide which events are significant enough to count as damage or as a loss.
  8. Domain 2: Information security risk process and approaches

    An organization with no previous experience of formal risk assessment intends to apply the information security risk management process to its procurement process at the headquarters only. A team member objects that a scope narrower than the whole organization cannot be used and that the boundaries do not need to be stated. How should this situation be evaluated?

    1. The narrow scope is acceptable, but the boundaries can be left unstated because they matter only for assets and technologies.
    2. The narrow scope is acceptable, and the boundaries still have to be identified because risks can arise through those boundaries.
    3. The narrow scope is unacceptable, and the boundaries have to be identified because every relevant asset must sit inside them.
    4. The narrow scope is unacceptable, and the boundaries can be left unstated because a first assessment covers the whole organization.
  9. Domain 1: Fundamental information security risk concepts

    An organization records two weaknesses affecting the same server: the building housing it is prone to seasonal flooding, and the machine itself is unable to process the volume of data it receives. How does the vocabulary of ISO/IEC 27005:2022 classify each of them?

    1. The flooding-prone location is an intrinsic vulnerability and the processing limit is an extrinsic one, because a site cannot be altered while performance can be improved.
    2. The flooding-prone location is an extrinsic vulnerability and the processing limit is an intrinsic one, because the first comes from external factors while the second is inherent.
    3. The flooding-prone location is an environmental threat and the processing limit is an accidental one, because both of them are risk sources able to act on that server.
    4. The flooding-prone location is a risk scenario and the processing limit is a consequence, because each describes an effect that the organization has already measured.
  10. Domain 2: Information security risk process and approaches

    Two candidate risk assessment methods are being compared. The first guarantees that a different analyst working from the same data reaches the same result, and the second guarantees that the process repeated over time produces consistent results. A manager claims that the two guarantees describe one and the same property. How should that claim be evaluated?

    1. The claim is correct, and both guarantees describe the repeatability that a method has to show before it can be selected for use.
    2. The claim is correct, and both guarantees describe the consistency of measurement that the consequence criteria impose.
    3. The claim is wrong, but only the second guarantee counts, because a method is picked for the treatment options it offers.
    4. The claim is wrong, since the two guarantees are separate questions: one about reproducibility, the other about repeatability.

Answer these same ten questions in the simulator and see the explanation of every option, including the wrong ones. It opens with no sign-up →

About the official exam: its format, duration and number of questions are set by the certification body and may change, so confirm them in its documentation before you sit it. This material trains the standard, not one body's exam, so it is just as useful if you certify elsewhere.

How to use it

  1. Start in guided practice: every answer is marked and explained right away.
  2. Move to timed exam mode once you know the material.
  3. Repeat until you clear 90 %, the threshold we recommend before sitting the real exam.
  4. Work on the domains flagged in red before trying again.

Frequently asked questions

Is this the official exam?

No. It is our own preparation material, with original questions. It is neither affiliated with nor endorsed by any certification body.

How long do I have access?

Twelve months from purchase, the same validity as the official retake.

Can I try it first?

Yes, in three steps. Answer 10 questions from exam 1 with no sign up, with an explanation for every option. Leaving your email opens the whole of exam 1. All six exams are activated with the purchase.

Which languages?

Shown on each product. This one is available in the languages listed above.

The training for this certification

If beyond practising you want the full material, the exam and the certificate, this is the ISO/IEC 27005 Foundation training.

See the training

All exams