100+ Free IBITGQ C-DORA Practice Questions
Prepare for the IBITGQ Certified DORA Foundation & Practitioner (C-DORA) exam with instant access — no signup required.
Loading practice questions...
Key Facts: IBITGQ C-DORA Exam
17 Jan 2025
DORA Application Date
EU Regulation 2022/2554
20+ types
In-Scope Financial Entity Types
DORA Article 2
4h / 24h
Initial Major Incident Notification
DORA RTS 2025/301
Every 3 years
TLPT Minimum Frequency
DORA Article 26
ISO 17024
Accreditation Standard
IBITGQ / GASQ
60 min
Foundation Exam Duration
IBITGQ / GASQ
The IBITGQ C-DORA Foundation is a 60-minute multiple-choice exam covering DORA's regulatory scope, ICT risk management lifecycle, incident reporting timelines, resilience testing requirements (including TLPT), ICT third-party risk management, and governance. The Practitioner level focuses on implementing DORA requirements and designing resilience programmes. Both exams are ISO 17024-accredited and delivered online via GASQ automated proctoring.
Sample IBITGQ C-DORA Practice Questions
Try these sample questions to test your IBITGQ C-DORA exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.
1On which date did EU Regulation 2022/2554 (DORA) become applicable to in-scope financial entities?
2Which EU regulation number codifies the Digital Operational Resilience Act?
3DORA applies to approximately how many different types of financial entities?
4Which of the following entities is explicitly in scope for DORA?
5The proportionality principle under DORA means that financial entities must implement DORA obligations taking into account what?
6Which three European Supervisory Authorities (ESAs) share joint oversight powers under DORA?
7Under DORA, who bears ultimate responsibility for defining, approving, and overseeing the ICT risk management framework?
8DORA requires financial entities to establish a dedicated ICT risk management function. Under Article 6(8), what key characteristic must this function have?
9Which phases does the DORA ICT risk management lifecycle require financial entities to cover?
10Under DORA, financial entities must maintain an ICT asset catalogue. What is the primary purpose of this requirement?
About the IBITGQ C-DORA Exam
The IBITGQ Certified DORA Foundation & Practitioner (C-DORA) is an ISO 17024-accredited qualification suite covering EU Regulation 2022/2554 (Digital Operational Resilience Act). It validates knowledge of DORA's scope, ICT risk management framework, ICT incident classification and reporting, digital operational resilience testing (including TLPT), ICT third-party risk management, and governance requirements for EU financial entities.
Assessment
Question count not published by the exam provider
Time Limit
60 minutes (Foundation); Practitioner duration varies — see GASQ
Passing Score
Not published by IBITGQ
Exam Fee
Varies by region and accredited provider; contact IT Governance or IBITGQ for current pricing (IBITGQ / GASQ)
IBITGQ C-DORA Exam Content Outline
DORA Regulatory Scope & Objectives
Legislative background, Regulation (EU) 2022/2554, application date (17 January 2025), in-scope financial entity types (20+), proportionality principle, and relationship to NIS2
ICT Risk Management Framework
Management body responsibilities, ICT risk lifecycle (identify, protect, detect, respond, recover, learn), asset catalogues, BCP/DR, backup and recovery, and communication policies (Articles 5-16)
ICT Incident Classification & Reporting
Classification criteria (clients, duration, geographic spread, data loss, economic impact, criticality), major vs significant cyber threats, initial notification (4h/24h), intermediate report (72h), final report (1 month)
Digital Operational Resilience Testing
Basic testing programme, Threat-Led Penetration Testing (TLPT), TIBER-EU framework, frequency (at least every 3 years for TLPT), tester qualification requirements, and critical function scoping
ICT Third-Party Risk & Critical Providers
Third-party risk management strategy, mandatory contract provisions, information register, critical ICT third-party provider (CTPP) designation, ESA oversight framework, JETs, and subcontracting
Implementation & Resilience Programme Design
Applying proportionality, gap analysis, ICT concentration risk, risk assessment methodology, and designing a digital operational resilience programme
Governance & Oversight
Management body approval and oversight, three lines of defence, ICT risk function independence, information-sharing arrangements (Article 45), penalties, and ESA supervisory powers
How to Pass the IBITGQ C-DORA Exam
What You Need to Know
- Passing score: Not published by IBITGQ
- Assessment: Question count not published by the exam provider
- Time limit: 60 minutes (Foundation); Practitioner duration varies — see GASQ
- Exam fee: Varies by region and accredited provider; contact IT Governance or IBITGQ for current pricing
Keys to Passing
- Work through all 100 available questions
- Review every answer and explanation
- Track weak areas and revisit them
- Use our AI tutor for tough concepts
IBITGQ C-DORA Study Tips from Top Performers
Frequently Asked Questions
What is the IBITGQ C-DORA certification?
The IBITGQ Certified DORA Foundation & Practitioner (C-DORA) is an ISO 17024-accredited qualification suite issued by the International Board for IT Governance Qualifications (IBITGQ) and delivered via GASQ automated proctoring. It covers EU Regulation 2022/2554 (Digital Operational Resilience Act) and validates knowledge of ICT risk management, incident reporting, resilience testing, and third-party risk for financial sector professionals.
What topics does the DORA Foundation exam cover?
The C-DORA Foundation covers DORA's regulatory scope and objectives, the ICT risk management framework (Articles 5-16), ICT incident classification and reporting timelines, digital operational resilience testing requirements including TLPT, ICT third-party risk management strategy, and governance responsibilities of the management body.
When did EU DORA enter into application?
EU Regulation 2022/2554 (DORA) entered into force on 16 January 2023 and became applicable from 17 January 2025. Financial entities in scope have been required to comply with all DORA obligations since that date. Penalties for non-compliance can reach EUR 5-10 million or 5-10% of annual global turnover.
What types of entities are in scope for DORA?
DORA applies to more than 20 types of financial entities operating in the EU, including credit institutions (banks), insurance and reinsurance undertakings, investment firms, payment institutions, e-money institutions, crypto-asset service providers, central securities depositories, credit rating agencies, trading venues, and more. Critical ICT third-party service providers supporting these entities can also be brought under direct ESA oversight.
What is TLPT under DORA and who must perform it?
Threat-Led Penetration Testing (TLPT) is an advanced form of operational resilience testing under DORA Article 26. Selected financial entities (principally G-SIIs and O-SIIs, plus payment and e-money institutions above defined thresholds) must conduct TLPT at least every three years against live production systems, including outsourced critical functions. TLPT uses bespoke threat intelligence and a red team approach aligned with the TIBER-EU framework.
What are the DORA major incident reporting timelines?
Under DORA and RTS 2025/301, the initial notification must be submitted within 4 hours of classifying the incident as major (and within 24 hours of detection). An intermediate report follows within 72 hours of the initial notification. A final report is due within 1 month of submitting the intermediate report. Reports go to the financial entity's lead competent authority.