The six exams, one by one
| Exam | Format | Questions |
|---|---|---|
| 1 | Domain training | 50 |
| 2 | Domain training | 50 |
| 3 | Domain training | 50 |
| 4 | Domain training | 50 |
| 5 | Timed simulation | 80 |
| 6 | Timed simulation | 80 |
The report you get at the end
Not a percentage: a diagnosis. We tell you whether it is worth sitting the exam, which domains to reinforce and how many answers you got right while unsure.
The domains assessed
Actual distribution of this product questions.
Ten sample exam questions
One per competency domain, exactly as they appear in the simulator.
-
D1 Fundamental principles and concepts
According to ISO/IEC 27000:2018 and in a manner harmonized with ISO 31000:2018, how is risk defined in normative terms?
- Risk is the effect of uncertainty on the achievement of objectives, whether they are information security, compliance or business continuity objectives.
- Risk is the combination of the probability of occurrence of an event and the consequence that may result for the organization's objectives.
- Risk is the measured difference between the observed value of a security metric and its target value expected by management.
- Risk is an event resulting from the exploitation of a vulnerability by an identified threat and characterized by an operational actor.
-
D3 Information security risk assessment
Which activities does clause 7 of ISO/IEC 27005:2022, titled information security risk assessment, group within its sub-clauses?
- The identification, analysis and evaluation of information security risks.
- The treatment options, the determination of necessary controls and the development of the treatment plan.
- The internal and external context, the assessment criteria and the methodological approach chosen for the organization.
- Communication, risk monitoring and continual improvement of the management process.
-
D4 Information security risk treatment
MetroCity is deciding on the treatment options applicable to a cyber risk on its citizen online services. Which normative nomenclature of the four treatment options must the Lead Risk Manager cite according to clause 8.2 of ISO/IEC 27005:2022?
- Share (share), transfer (transfer), retain (retain) and reject (reject) according to the map of available controls.
- Accept (accept), transfer (transfer), mitigate (mitigate) and ignore (ignore) the risk according to the risk owner's decision.
- Modify (modify), accept (accept), transfer (transfer) and reduce (reduce) on the basis of the risk criteria retained.
- Modify (reduce the risk), share (share the risk), avoid (avoid the risk) and retain (retain the risk).
-
D6 Risk assessment methodologies
To structure the risk assessment of a sector-specific ISMS project, the Lead Risk Manager compares several recognized national methods. Which statement correctly describes the institutional origin of MEHARI, CRAMM, NIST SP 800-30 and Harmonized TRA?
- MEHARI, CRAMM, NIST SP 800-30 and Harmonized TRA all refer to a single reference method adopted by IEC 31010:2019, their acronyms being local variants of the same methodological framework.
- MEHARI was withdrawn by CLUSIF in 2020, CRAMM has no longer been maintained since 2010, NIST SP 800-30 became obsolete when ISO/IEC 27005:2018 was released, and Harmonized TRA was never officially published.
- MEHARI is published by CLUSIF (France), CRAMM by the UK Government (CCTA), NIST SP 800-30 by NIST (United States), and Harmonized TRA by the Canadian authorities (CSE and RCMP).
- MEHARI is published by ANSSI in France, CRAMM by NIST in the United States, NIST SP 800-30 by the UK Government, and Harmonized TRA by ENISA for the European Union.
-
D5 Communication, monitoring, improvement
What is the role of the trigger criteria introduced by ISO/IEC 27005:2022 in steering the risk management process?
- The trigger criteria are mandatory requirements applicable only to clause 6 establishing the context, with no transversality across the other clauses.
- The trigger criteria were removed by the 2022 revision and no longer appear in the normative body of the current edition of ISO/IEC 27005.
- The trigger criteria set a strictly calendar-based periodicity (annual or quarterly), excluding unplanned events and organizational changes.
- The trigger criteria identify the events or changes that trigger a reassessment of the process or of the risks, transversally across the clauses of the programme.
-
D2 Implementation of the programme
MetroCity structures its three-year programme by articulating ISO/IEC 27001:2022 and ISO/IEC 27005:2022. Which statement correctly describes the distinct role of each of the two standards in the programme?
- ISO/IEC 27005:2022 is mandatory for ISO/IEC 27001 certification, and non-compliance with it automatically leads to rejection of the certification application.
- ISO/IEC 27001:2022 and ISO/IEC 27005:2022 both impose certifiable, auditable requirements, and gaps between the two reference standards may generate distinct nonconformity findings during the certification audit.
- ISO/IEC 27001:2022 sets the requirements of the ISMS, whereas ISO/IEC 27005:2022 provides the risk management method.
- ISO/IEC 27005:2022 sets the certifiable requirements of the management system, and ISO/IEC 27001:2022 is merely an optional application guide for the programme.
-
D1 Fundamental principles and concepts
In the terminology of ISO/IEC 27000:2018 and ISO/IEC 27005:2022, how does likelihood differ from probability when characterizing the possibility that a risk event will occur?
- Probability is used for financial risks, whereas likelihood applies exclusively to operational and cybersecurity risks.
- Likelihood is a generic term encompassing quantified probability and qualified frequency, applicable both to numerical estimates and to expert judgements.
- Probability refers only to estimates derived from historical data, whereas likelihood is limited to expert estimates formulated in a workshop.
- The distinction between likelihood and probability was introduced by ISO 31000:2018 and then abandoned by ISO/IEC 27000:2018, which now retains only the term probability.
-
D3 Information security risk assessment
BankSecure Europe is building its cyber risk identification approach for its card payment scope. The Lead Risk Manager must choose between the event-based and asset-based approaches of ISO/IEC 27005:2022. Which statement correctly describes their normative articulation?
- The asset-based approach came first in practice and the event-based approach is its generalization, with clauses 7.3.1 describing two successive moments of a single identification approach.
- The event-based and asset-based approaches form a symmetrical inversion of each other, their results being expected to be identical apart from a change of entry point.
- The event-based approach follows a top-down logic (scenarios with strong strategic impact) whereas the asset-based approach follows a bottom-up logic (inventory of assets, threats, vulnerabilities).
- The event-based approach is an optional approach reserved for large enterprises that have an in-house threat intelligence unit and a mature TLPT programme.
-
D4 Information security risk treatment
How do clause 6.1.3.d of ISO/IEC 27001:2022 (Statement of Applicability) and clause 8.5 of ISO/IEC 27005:2022 fit together in the production of the SoA?
- The SoA is an optional output for the ISMS seeking certification, exempted by the 2022 revision of ISO/IEC 27001 for organizations in the initial phase.
- ISO/IEC 27001:2022 requires the production of an SoA listing the applicable controls with justification, fed methodologically by ISO/IEC 27005:2022.
- The SoA is a mechanical copy of Annex A of ISO/IEC 27001:2022, taking up the 93 controls without selection or contextual justification.
- The SoA is a simple direct consequence of the 27005 risk assessment, produced mechanically at the end of the process without formal intervention by the organization.
-
D6 Risk assessment methodologies
Within the portfolio of risk assessment methods, the Lead Risk Manager encounters the OCTAVE and OCTAVE Allegro variants published by the Software Engineering Institute (SEI). Which statement correctly describes their institutional origin and their internal articulation?
- OCTAVE is issued by NIST as part of the SP 800 programme, whereas OCTAVE Allegro remains a proprietary variant published separately by Carnegie Mellon, with no articulation between the two versions.
- OCTAVE and OCTAVE Allegro refer to the same method in two linguistic variants (English and Latin for Allegro), their two acronyms being strictly interchangeable in the professional literature.
- OCTAVE Allegro was replaced in 2018 by a merger with FAIR, giving rise to a single method combining the SEI's asset-vulnerability approach and the FAIR Institute's monetary quantification.
- OCTAVE and OCTAVE Allegro are published by the Software Engineering Institute (SEI) of Carnegie Mellon, Allegro being a simplified variant centred on critical information assets.
About the official exam: its format, duration and number of questions are set by the certification body and may change, so confirm them in its documentation before you sit it. This material trains the standard, not one body's exam, so it is just as useful if you certify elsewhere.
How to use it
- Start in guided practice: every answer is marked and explained right away.
- Move to timed exam mode once you know the material.
- Repeat until you clear 90 %, the threshold we recommend before sitting the real exam.
- Work on the domains flagged in red before trying again.
Frequently asked questions
Is this the official exam?
No. It is our own preparation material, with original questions. It is neither affiliated with nor endorsed by any certification body.
How long do I have access?
Twelve months from purchase, the same validity as the official retake.
Can I try it first?
Yes, in three steps. Answer 10 questions from exam 1 with no sign up, with an explanation for every option. Leaving your email opens the whole of exam 1. All six exams are activated with the purchase.
Which languages?
Shown on each product. This one is available in the languages listed above.
The training for this certification
If beyond practising you want the full material, the exam and the certificate, this is the ISO/IEC 27005 Lead Risk Manager training.
Exam Mode is preparation material produced by RRSG. It is not an official examination and it is neither affiliated with nor endorsed by any certification body. Questions are original, written from the standard and from publicly available programme information, and do not reproduce the real exam.