Exam Mode

ISO/IEC 27005 Lead Risk Manager

Lead the risk management programme

The six exams, one by one

ExamFormatQuestions
1Domain training50
2Domain training50
3Domain training50
4Domain training50
5Timed simulation80
6Timed simulation80

The report you get at the end

Not a percentage: a diagnosis. We tell you whether it is worth sitting the exam, which domains to reinforce and how many answers you got right while unsure.

Sample reportYou would pass, but with no margin
D3 Information security risk assessment78%
D1 Fundamental principles and concepts64%
D4 Information security risk treatment55%
D2 Implementation of the programme82%
D6 Risk assessment methodologies70%
D5 Communication, monitoring, improvement61%

The domains assessed

Actual distribution of this product questions.

D3 Information security risk assessment84
D1 Fundamental principles and concepts63
D4 Information security risk treatment59
D2 Implementation of the programme55
D6 Risk assessment methodologies53
D5 Communication, monitoring, improvement46

Ten sample exam questions

One per competency domain, exactly as they appear in the simulator.

  1. D1 Fundamental principles and concepts

    According to ISO/IEC 27000:2018 and in a manner harmonized with ISO 31000:2018, how is risk defined in normative terms?

    1. Risk is the effect of uncertainty on the achievement of objectives, whether they are information security, compliance or business continuity objectives.
    2. Risk is the combination of the probability of occurrence of an event and the consequence that may result for the organization's objectives.
    3. Risk is the measured difference between the observed value of a security metric and its target value expected by management.
    4. Risk is an event resulting from the exploitation of a vulnerability by an identified threat and characterized by an operational actor.
  2. D3 Information security risk assessment

    Which activities does clause 7 of ISO/IEC 27005:2022, titled information security risk assessment, group within its sub-clauses?

    1. The identification, analysis and evaluation of information security risks.
    2. The treatment options, the determination of necessary controls and the development of the treatment plan.
    3. The internal and external context, the assessment criteria and the methodological approach chosen for the organization.
    4. Communication, risk monitoring and continual improvement of the management process.
  3. D4 Information security risk treatment

    MetroCity is deciding on the treatment options applicable to a cyber risk on its citizen online services. Which normative nomenclature of the four treatment options must the Lead Risk Manager cite according to clause 8.2 of ISO/IEC 27005:2022?

    1. Share (share), transfer (transfer), retain (retain) and reject (reject) according to the map of available controls.
    2. Accept (accept), transfer (transfer), mitigate (mitigate) and ignore (ignore) the risk according to the risk owner's decision.
    3. Modify (modify), accept (accept), transfer (transfer) and reduce (reduce) on the basis of the risk criteria retained.
    4. Modify (reduce the risk), share (share the risk), avoid (avoid the risk) and retain (retain the risk).
  4. D6 Risk assessment methodologies

    To structure the risk assessment of a sector-specific ISMS project, the Lead Risk Manager compares several recognized national methods. Which statement correctly describes the institutional origin of MEHARI, CRAMM, NIST SP 800-30 and Harmonized TRA?

    1. MEHARI, CRAMM, NIST SP 800-30 and Harmonized TRA all refer to a single reference method adopted by IEC 31010:2019, their acronyms being local variants of the same methodological framework.
    2. MEHARI was withdrawn by CLUSIF in 2020, CRAMM has no longer been maintained since 2010, NIST SP 800-30 became obsolete when ISO/IEC 27005:2018 was released, and Harmonized TRA was never officially published.
    3. MEHARI is published by CLUSIF (France), CRAMM by the UK Government (CCTA), NIST SP 800-30 by NIST (United States), and Harmonized TRA by the Canadian authorities (CSE and RCMP).
    4. MEHARI is published by ANSSI in France, CRAMM by NIST in the United States, NIST SP 800-30 by the UK Government, and Harmonized TRA by ENISA for the European Union.
  5. D5 Communication, monitoring, improvement

    What is the role of the trigger criteria introduced by ISO/IEC 27005:2022 in steering the risk management process?

    1. The trigger criteria are mandatory requirements applicable only to clause 6 establishing the context, with no transversality across the other clauses.
    2. The trigger criteria were removed by the 2022 revision and no longer appear in the normative body of the current edition of ISO/IEC 27005.
    3. The trigger criteria set a strictly calendar-based periodicity (annual or quarterly), excluding unplanned events and organizational changes.
    4. The trigger criteria identify the events or changes that trigger a reassessment of the process or of the risks, transversally across the clauses of the programme.
  6. D2 Implementation of the programme

    MetroCity structures its three-year programme by articulating ISO/IEC 27001:2022 and ISO/IEC 27005:2022. Which statement correctly describes the distinct role of each of the two standards in the programme?

    1. ISO/IEC 27005:2022 is mandatory for ISO/IEC 27001 certification, and non-compliance with it automatically leads to rejection of the certification application.
    2. ISO/IEC 27001:2022 and ISO/IEC 27005:2022 both impose certifiable, auditable requirements, and gaps between the two reference standards may generate distinct nonconformity findings during the certification audit.
    3. ISO/IEC 27001:2022 sets the requirements of the ISMS, whereas ISO/IEC 27005:2022 provides the risk management method.
    4. ISO/IEC 27005:2022 sets the certifiable requirements of the management system, and ISO/IEC 27001:2022 is merely an optional application guide for the programme.
  7. D1 Fundamental principles and concepts

    In the terminology of ISO/IEC 27000:2018 and ISO/IEC 27005:2022, how does likelihood differ from probability when characterizing the possibility that a risk event will occur?

    1. Probability is used for financial risks, whereas likelihood applies exclusively to operational and cybersecurity risks.
    2. Likelihood is a generic term encompassing quantified probability and qualified frequency, applicable both to numerical estimates and to expert judgements.
    3. Probability refers only to estimates derived from historical data, whereas likelihood is limited to expert estimates formulated in a workshop.
    4. The distinction between likelihood and probability was introduced by ISO 31000:2018 and then abandoned by ISO/IEC 27000:2018, which now retains only the term probability.
  8. D3 Information security risk assessment

    BankSecure Europe is building its cyber risk identification approach for its card payment scope. The Lead Risk Manager must choose between the event-based and asset-based approaches of ISO/IEC 27005:2022. Which statement correctly describes their normative articulation?

    1. The asset-based approach came first in practice and the event-based approach is its generalization, with clauses 7.3.1 describing two successive moments of a single identification approach.
    2. The event-based and asset-based approaches form a symmetrical inversion of each other, their results being expected to be identical apart from a change of entry point.
    3. The event-based approach follows a top-down logic (scenarios with strong strategic impact) whereas the asset-based approach follows a bottom-up logic (inventory of assets, threats, vulnerabilities).
    4. The event-based approach is an optional approach reserved for large enterprises that have an in-house threat intelligence unit and a mature TLPT programme.
  9. D4 Information security risk treatment

    How do clause 6.1.3.d of ISO/IEC 27001:2022 (Statement of Applicability) and clause 8.5 of ISO/IEC 27005:2022 fit together in the production of the SoA?

    1. The SoA is an optional output for the ISMS seeking certification, exempted by the 2022 revision of ISO/IEC 27001 for organizations in the initial phase.
    2. ISO/IEC 27001:2022 requires the production of an SoA listing the applicable controls with justification, fed methodologically by ISO/IEC 27005:2022.
    3. The SoA is a mechanical copy of Annex A of ISO/IEC 27001:2022, taking up the 93 controls without selection or contextual justification.
    4. The SoA is a simple direct consequence of the 27005 risk assessment, produced mechanically at the end of the process without formal intervention by the organization.
  10. D6 Risk assessment methodologies

    Within the portfolio of risk assessment methods, the Lead Risk Manager encounters the OCTAVE and OCTAVE Allegro variants published by the Software Engineering Institute (SEI). Which statement correctly describes their institutional origin and their internal articulation?

    1. OCTAVE is issued by NIST as part of the SP 800 programme, whereas OCTAVE Allegro remains a proprietary variant published separately by Carnegie Mellon, with no articulation between the two versions.
    2. OCTAVE and OCTAVE Allegro refer to the same method in two linguistic variants (English and Latin for Allegro), their two acronyms being strictly interchangeable in the professional literature.
    3. OCTAVE Allegro was replaced in 2018 by a merger with FAIR, giving rise to a single method combining the SEI's asset-vulnerability approach and the FAIR Institute's monetary quantification.
    4. OCTAVE and OCTAVE Allegro are published by the Software Engineering Institute (SEI) of Carnegie Mellon, Allegro being a simplified variant centred on critical information assets.

Answer these same ten questions in the simulator and see the explanation of every option, including the wrong ones. It opens with no sign-up →

About the official exam: its format, duration and number of questions are set by the certification body and may change, so confirm them in its documentation before you sit it. This material trains the standard, not one body's exam, so it is just as useful if you certify elsewhere.

How to use it

  1. Start in guided practice: every answer is marked and explained right away.
  2. Move to timed exam mode once you know the material.
  3. Repeat until you clear 90 %, the threshold we recommend before sitting the real exam.
  4. Work on the domains flagged in red before trying again.

Frequently asked questions

Is this the official exam?

No. It is our own preparation material, with original questions. It is neither affiliated with nor endorsed by any certification body.

How long do I have access?

Twelve months from purchase, the same validity as the official retake.

Can I try it first?

Yes, in three steps. Answer 10 questions from exam 1 with no sign up, with an explanation for every option. Leaving your email opens the whole of exam 1. All six exams are activated with the purchase.

Which languages?

Shown on each product. This one is available in the languages listed above.

The training for this certification

If beyond practising you want the full material, the exam and the certificate, this is the ISO/IEC 27005 Lead Risk Manager training.

See the training

All exams