All Practice Exams

116+ Free ISO 27001 Foundation Practice Questions

Prepare for the PECB Certificate Holder in ISO/IEC 27001:2022 Foundation exam with instant access — no signup required.

✓ No registration✓ No credit card✓ No hidden fees✓ Start practicing immediately
116+ Questions
100% Free

Loading practice questions...

2026 Statistics

Key Facts: ISO 27001 Foundation Exam

70%

Passing Score

PECB

40

Exam Questions

60 minutes

$500

Exam Fee (USD)

PECB standalone list price

93

Annex A Controls (2022)

ISO/IEC 27001:2022

4

Annex A Themes

Organizational, People, Physical, Technological

No expiration

Certification Validity

PECB

PECB ISO/IEC 27001:2022 Foundation is a 1-hour exam with 40 multiple-choice questions and a 70% passing score. PECB lists a $500 standalone exam fee and $200 certificate application fee; candidates completing the required course through a PECB Partner have the first attempt, first retake, and certificate application included in the training price. The entry-level certificate program covers 2 domains weighted 50/50: Fundamental Principles and Concepts of Information Security Management, and the Information Security Management System (ISMS). Coverage spans the CIA triad, ISO/IEC 27001:2022 Clauses 4-10, PDCA, 93 Annex A controls, risk management, and the Statement of Applicability. There is no professional-experience prerequisite, but candidates must complete the Foundation training course, pass the exam, apply for the certificate, and sign the PECB Code of Ethics. The Foundation certificate does not expire.

Sample ISO 27001 Foundation Practice Questions

Try these sample questions to test your ISO 27001 Foundation exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 116+ question experience with AI tutoring.

1What does the 'CIA triad' stand for in information security?
A.Control, Identity, and Authentication
B.Confidentiality, Integrity, and Availability
C.Compliance, Investigation, and Audit
D.Certification, Implementation, and Assessment
Explanation: The CIA triad — Confidentiality, Integrity, and Availability — is the foundational model of information security used throughout PECB Foundation materials. Confidentiality means information is not disclosed to unauthorized parties, integrity means information is accurate and unaltered, and availability means authorized users can access information when needed.
2Which standard contains the auditable requirements that an organization can be certified against?
A.ISO/IEC 27000
B.ISO/IEC 27001
C.ISO/IEC 27002
D.ISO/IEC 27005
Explanation: ISO/IEC 27001 specifies the requirements for establishing, implementing, maintaining, and continually improving an ISMS — and it is the standard organizations are certified to. The current ISO/IEC 27000:2026 is the ISMS-family overview, ISO/IEC 27002 is implementation guidance for controls, and ISO/IEC 27005 covers information security risk management.
3What does ISMS stand for?
A.Information Security Management System
B.International Security Monitoring Standard
C.Integrated Security Maintenance Service
D.ISO Security Management Specification
Explanation: ISMS stands for Information Security Management System — a systematic approach for managing sensitive company information so that it remains secure. ISO/IEC 27001 specifies the requirements for an ISMS.
4How many controls does Annex A of ISO/IEC 27001:2022 contain?
A.114
B.133
C.93
D.75
Explanation: ISO/IEC 27001:2022 Annex A contains 93 controls organized into 4 themes. The previous 2013 version had 114 controls in 14 categories — the 2022 revision consolidated duplicates and added 11 new controls, resulting in 93.
5Into how many themes are Annex A controls organized in ISO/IEC 27001:2022?
A.4
B.11
C.14
D.7
Explanation: ISO/IEC 27001:2022 organizes Annex A into 4 themes: Organizational (37 controls), People (8 controls), Physical (14 controls), and Technological (34 controls). The 2013 version used 14 categories; the 2022 revision simplified this structure.
6Which clauses of ISO/IEC 27001:2022 contain the mandatory ISMS requirements?
A.Clauses 1-3
B.Clauses 4-10
C.Annex A only
D.Clauses 5-8
Explanation: Clauses 4 through 10 contain the auditable ISMS requirements: Context (4), Leadership (5), Planning (6), Support (7), Operation (8), Performance Evaluation (9), and Improvement (10). Clauses 0-3 are introductory (scope, normative references, and terms).
7What does the PDCA cycle stand for in the context of an ISMS?
A.Plan, Develop, Certify, Audit
B.Plan, Do, Check, Act
C.Prepare, Design, Control, Approve
D.Policy, Document, Comply, Assess
Explanation: PDCA stands for Plan-Do-Check-Act — a four-step iterative model for continual improvement applied to the ISMS. Plan establishes objectives and processes, Do implements them, Check monitors and measures, and Act takes action to improve performance.
8Which property of information ensures that it is not disclosed to unauthorized individuals?
A.Integrity
B.Availability
C.Confidentiality
D.Authenticity
Explanation: Confidentiality is the property that information is not made available or disclosed to unauthorized individuals, entities, or processes. Integrity ensures accuracy and completeness, availability ensures accessibility when required, and authenticity ensures an entity is who it claims to be.
9Which property ensures that information is accurate and has not been altered in an unauthorized manner?
A.Confidentiality
B.Integrity
C.Availability
D.Reliability
Explanation: Integrity is the property of accuracy and completeness — information has not been altered or destroyed in an unauthorized manner. Controls such as hashing, digital signatures, and change management protect integrity.
10Which property ensures that information is accessible and usable upon demand by an authorized entity?
A.Confidentiality
B.Integrity
C.Availability
D.Non-repudiation
Explanation: Availability is the property of being accessible and usable on demand by an authorized entity. Backups, redundancy, capacity management, and incident response support availability.

About the ISO 27001 Foundation Exam

The PECB ISO/IEC 27001 Foundation certification validates fundamental knowledge of information security concepts and the ISO/IEC 27001:2022 standard. It is the entry-level credential in the PECB ISO 27001 path, sitting below Lead Implementer and Lead Auditor. The exam covers the CIA triad, ISMS fundamentals, Clauses 4-10, Annex A (93 controls in 4 themes), risk management basics, PDCA cycle, Statement of Applicability, and the ISO/IEC 27000 family of standards.

Questions

40 scored questions

Time Limit

60 minutes

Passing Score

70%

Exam Fee

$500 USD standalone exam + $200 USD certificate application; included with partner training (PECB)

ISO 27001 Foundation Exam Content Outline

50%

Fundamental Principles and Concepts of Information Security Management

CIA triad, authenticity, non-repudiation, accountability, reliability; PECB ISMS terminology; assets, threats, vulnerabilities, controls; risk identification, analysis, evaluation, and four risk treatment options (modify, retain, avoid, share); the broader ISO/IEC 27000 family of standards

50%

Information Security Management System (ISMS)

ISMS purpose, ISO/IEC 27001:2022 Clauses 4-10, PDCA cycle, top management responsibilities, continual improvement; Annex A controls and Statement of Applicability (93 controls across 4 themes: 37 Organizational, 8 People, 14 Physical, 34 Technological); Stage 1/Stage 2 certification audits

How to Pass the ISO 27001 Foundation Exam

What You Need to Know

  • Passing score: 70%
  • Exam length: 40 questions
  • Time limit: 60 minutes
  • Exam fee: $500 USD standalone exam + $200 USD certificate application; included with partner training

Keys to Passing

  • Complete 500+ practice questions
  • Score 80%+ consistently before scheduling
  • Focus on highest-weighted sections
  • Use our AI tutor for tough concepts

ISO 27001 Foundation Study Tips from Top Performers

1Memorize the 4 Annex A themes and exact control counts: 37 Organizational, 8 People, 14 Physical, 34 Technological = 93 total — questions explicitly test these numbers
2Know the difference between ISO/IEC 27001 (requirements, certifiable) and ISO/IEC 27002 (controls guidance, not certifiable) — common distractor
3Master the four risk treatment options: modify, retain, avoid, share — and which option each scenario describes
4Memorize the Clauses 4-10 names: Context, Leadership, Planning, Support, Operation, Performance Evaluation, Improvement — many questions reference clauses by number
5Know the 11 new controls added in 2022 (Threat Intelligence, Cloud Services, ICT Readiness, Physical Monitoring, Configuration Management, Information Deletion, Data Masking, DLP, Web Filtering, Secure Coding, Monitoring Activities)
6Use our AI tutor to walk through risk treatment scenarios and Annex A control classification — Foundation distractors often confuse 27001 vs 27002 or theme assignments

Frequently Asked Questions

What is the PECB ISO/IEC 27001 Foundation exam?

It is a 1-hour, 40-question multiple-choice exam across 2 domains weighted 50/50. The passing score is 70%. PECB lists a $500 standalone exam fee and $200 certificate application fee, while PECB Partner training packages include the first attempt, first retake, and certificate application. The exam can be online or paper-based through the training partner. The Foundation certificate does not expire.

What is the difference between ISO/IEC 27001 Foundation, Lead Implementer, and Lead Auditor?

Foundation is the entry-level certificate program that validates fundamental understanding of ISO/IEC 27001 concepts. It has no professional-experience prerequisite, but the PECB Foundation training course is required. Lead Implementer is for professionals responsible for designing, implementing, and managing an ISMS; Lead Auditor is for professionals who plan and conduct ISMS audits.

How is Annex A structured in ISO/IEC 27001:2022?

ISO/IEC 27001:2022 organizes Annex A into 93 controls across 4 themes: Organizational (37 controls, A.5.x), People (8 controls, A.6.x), Physical (14 controls, A.7.x), and Technological (34 controls, A.8.x). This replaces the 2013 version's 114 controls in 14 categories. The 2022 revision also added 11 new controls including Threat Intelligence, Data Masking, Data Leakage Prevention, and Secure Coding.

What are the four risk treatment options in ISO/IEC 27001?

ISO/IEC 27001 recognizes four risk treatment options: modify (apply controls to reduce likelihood or impact), retain (accept the risk if below acceptance criteria), avoid (decide not to start or continue the risk-causing activity), and share (transfer through insurance, outsourcing, or contracts). These options are documented in the risk treatment plan and Statement of Applicability.

What is the Statement of Applicability (SoA)?

The SoA is a mandatory document required by Clause 6.1.3 d) of ISO/IEC 27001:2022. It identifies the controls determined as necessary, justifies their inclusion or exclusion compared to Annex A, and indicates implementation status. The SoA is one of the most scrutinized documents during certification audits because it directly evidences risk treatment decisions and connects the risk assessment to Annex A.

What career paths follow ISO 27001 Foundation?

Foundation typically leads to PECB ISO/IEC 27001 Lead Implementer or Lead Auditor. Implementers move into ISMS Manager, Information Security Officer, or GRC Analyst roles ($65-95K). Auditors progress toward ISMS Lead Auditor at certification bodies, Internal Audit Manager, or Compliance Consultant ($75-130K). Many candidates also pair Foundation with broader credentials like CISSP, CISA, or CISM for career advancement.