Career upgrade: Learn practical AI skills for better jobs and higher pay.
Level up
All Practice Exams

100+ Free ISO 27001 Foundation Practice Questions

Pass your PECB ISO/IEC 27001 Foundation exam on the first try — instant access, no signup required.

✓ No registration✓ No credit card✓ No hidden fees✓ Start practicing immediately
100+ Questions
100% Free
1 / 100
Question 1
Score: 0/0

Which standard provides guidelines for information security incident management?

A
B
C
D
to track
2026 Statistics

Key Facts: ISO 27001 Foundation Exam

70%

Passing Score

PECB

~80

Exam Questions

60 minutes

$300

Exam Fee (USD)

PECB KCP

93

Annex A Controls (2022)

ISO/IEC 27001:2022

4

Annex A Themes

Organizational, People, Physical, Technological

3 years

Certification Validity

PECB

PECB ISO/IEC 27001 Foundation is a 1-hour exam with approximately 80 multiple-choice questions, requiring 70% to pass at a cost of $300 USD (KCP delivered). It is the entry-level credential in the PECB ISO 27001 path, designed to validate fundamental knowledge of information security and ISO/IEC 27001:2022. Coverage spans the CIA triad and related properties (authenticity, non-repudiation, accountability, reliability), ISMS basics, ISO/IEC 27001:2022 Clauses 4-10, the PDCA cycle, 93 Annex A controls across 4 themes (Organizational, People, Physical, Technological), risk management fundamentals, Statement of Applicability, and the broader ISO/IEC 27000 family. No prerequisites — ideal for IT/security professionals beginning their ISMS journey before pursuing Lead Implementer or Lead Auditor.

Sample ISO 27001 Foundation Practice Questions

Try these sample questions to test your ISO 27001 Foundation exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.

1What does the 'CIA triad' stand for in information security?
A.Control, Identity, and Authentication
B.Confidentiality, Integrity, and Availability
C.Compliance, Investigation, and Audit
D.Certification, Implementation, and Assessment
Explanation: The CIA triad — Confidentiality, Integrity, and Availability — is the foundational model of information security referenced throughout ISO/IEC 27000. Confidentiality means information is not disclosed to unauthorized parties, integrity means information is accurate and unaltered, and availability means authorized users can access information when needed.
2Which standard contains the auditable requirements that an organization can be certified against?
A.ISO/IEC 27000
B.ISO/IEC 27001
C.ISO/IEC 27002
D.ISO/IEC 27005
Explanation: ISO/IEC 27001 specifies the requirements for establishing, implementing, maintaining, and continually improving an ISMS — and it is the standard organizations are certified to. ISO/IEC 27000 is the vocabulary, ISO/IEC 27002 is implementation guidance for controls, and ISO/IEC 27005 covers information security risk management.
3What does ISMS stand for?
A.Information Security Management System
B.International Security Monitoring Standard
C.Integrated Security Maintenance Service
D.ISO Security Management Specification
Explanation: ISMS stands for Information Security Management System — a systematic approach for managing sensitive company information so that it remains secure. ISO/IEC 27001 specifies the requirements for an ISMS.
4How many controls does Annex A of ISO/IEC 27001:2022 contain?
A.114
B.133
C.93
D.75
Explanation: ISO/IEC 27001:2022 Annex A contains 93 controls organized into 4 themes. The previous 2013 version had 114 controls in 14 categories — the 2022 revision consolidated duplicates and added 11 new controls, resulting in 93.
5Into how many themes are Annex A controls organized in ISO/IEC 27001:2022?
A.4
B.11
C.14
D.7
Explanation: ISO/IEC 27001:2022 organizes Annex A into 4 themes: Organizational (37 controls), People (8 controls), Physical (14 controls), and Technological (34 controls). The 2013 version used 14 categories; the 2022 revision simplified this structure.
6Which clauses of ISO/IEC 27001:2022 contain the mandatory ISMS requirements?
A.Clauses 1-3
B.Clauses 4-10
C.Annex A only
D.Clauses 5-8
Explanation: Clauses 4 through 10 contain the auditable ISMS requirements: Context (4), Leadership (5), Planning (6), Support (7), Operation (8), Performance Evaluation (9), and Improvement (10). Clauses 0-3 are introductory (scope, normative references, and terms).
7What does the PDCA cycle stand for in the context of an ISMS?
A.Plan, Develop, Certify, Audit
B.Plan, Do, Check, Act
C.Prepare, Design, Control, Approve
D.Policy, Document, Comply, Assess
Explanation: PDCA stands for Plan-Do-Check-Act — a four-step iterative model for continual improvement applied to the ISMS. Plan establishes objectives and processes, Do implements them, Check monitors and measures, and Act takes action to improve performance.
8Which property of information ensures that it is not disclosed to unauthorized individuals?
A.Integrity
B.Availability
C.Confidentiality
D.Authenticity
Explanation: Confidentiality is the property that information is not made available or disclosed to unauthorized individuals, entities, or processes. Integrity ensures accuracy and completeness, availability ensures accessibility when required, and authenticity ensures an entity is who it claims to be.
9Which property ensures that information is accurate and has not been altered in an unauthorized manner?
A.Confidentiality
B.Integrity
C.Availability
D.Reliability
Explanation: Integrity is the property of accuracy and completeness — information has not been altered or destroyed in an unauthorized manner. Controls such as hashing, digital signatures, and change management protect integrity.
10Which property ensures that information is accessible and usable upon demand by an authorized entity?
A.Confidentiality
B.Integrity
C.Availability
D.Non-repudiation
Explanation: Availability is the property of being accessible and usable on demand by an authorized entity. Backups, redundancy, capacity management, and incident response support availability.

About the ISO 27001 Foundation Exam

The PECB ISO/IEC 27001 Foundation certification validates fundamental knowledge of information security concepts and the ISO/IEC 27001:2022 standard. It is the entry-level credential in the PECB ISO 27001 path, sitting below Lead Implementer and Lead Auditor. The exam covers the CIA triad, ISMS fundamentals, Clauses 4-10, Annex A (93 controls in 4 themes), risk management basics, PDCA cycle, Statement of Applicability, and the ISO/IEC 27000 family of standards.

Questions

80 scored questions

Time Limit

60 minutes

Passing Score

70%

Exam Fee

$300 USD (PECB)

ISO 27001 Foundation Exam Content Outline

25%

Fundamental Principles and Concepts of Information Security

CIA triad, authenticity, non-repudiation, accountability, reliability; ISO/IEC 27000 vocabulary; assets, threats, vulnerabilities, controls

25%

Information Security Management System (ISMS)

ISMS purpose, ISO/IEC 27001:2022 Clauses 4-10, PDCA cycle, top management responsibilities, continual improvement

20%

Risk Management Fundamentals

Risk identification, analysis, evaluation, four risk treatment options (modify, retain, avoid, share), risk owners, and residual risk

20%

Annex A Controls and Statement of Applicability

93 controls across 4 themes (37 Organizational, 8 People, 14 Physical, 34 Technological); SoA purpose and contents

10%

ISO/IEC 27000 Family and Certification Process

Related standards (27000, 27002, 27003, 27005, 27017, 27018, 27701); Stage 1/Stage 2 audits; surveillance; 3-year certification cycle

How to Pass the ISO 27001 Foundation Exam

What You Need to Know

  • Passing score: 70%
  • Exam length: 80 questions
  • Time limit: 60 minutes
  • Exam fee: $300 USD

Keys to Passing

  • Complete 500+ practice questions
  • Score 80%+ consistently before scheduling
  • Focus on highest-weighted sections
  • Use our AI tutor for tough concepts

ISO 27001 Foundation Study Tips from Top Performers

1Memorize the 4 Annex A themes and exact control counts: 37 Organizational, 8 People, 14 Physical, 34 Technological = 93 total — questions explicitly test these numbers
2Know the difference between ISO/IEC 27001 (requirements, certifiable) and ISO/IEC 27002 (controls guidance, not certifiable) — common distractor
3Master the four risk treatment options: modify, retain, avoid, share — and which option each scenario describes
4Memorize the Clauses 4-10 names: Context, Leadership, Planning, Support, Operation, Performance Evaluation, Improvement — many questions reference clauses by number
5Know the 11 new controls added in 2022 (Threat Intelligence, Cloud Services, ICT Readiness, Physical Monitoring, Configuration Management, Information Deletion, Data Masking, DLP, Web Filtering, Secure Coding, Monitoring Activities)
6Use our AI tutor to walk through risk treatment scenarios and Annex A control classification — Foundation distractors often confuse 27001 vs 27002 or theme assignments

Frequently Asked Questions

What is the PECB ISO/IEC 27001 Foundation exam?

It is a 1-hour multiple-choice exam with approximately 80 questions, designed to validate fundamental knowledge of information security and the ISO/IEC 27001:2022 standard. The passing score is 70%. The exam costs $300 USD and is delivered through PECB's online Knowledge Certification Platform (KCP). It is the entry-level credential in the PECB ISO 27001 path, with Lead Implementer and Lead Auditor as the next progression.

What is the difference between ISO/IEC 27001 Foundation, Lead Implementer, and Lead Auditor?

Foundation is the entry-level credential that validates fundamental understanding of ISO/IEC 27001 concepts. Lead Implementer is for professionals responsible for designing, implementing, and managing an ISMS. Lead Auditor is for professionals who plan and conduct ISMS audits per ISO 19011 and ISO/IEC 17021-1. Foundation has no prerequisites; Lead exams are longer, harder, and target practitioners.

How is Annex A structured in ISO/IEC 27001:2022?

ISO/IEC 27001:2022 organizes Annex A into 93 controls across 4 themes: Organizational (37 controls, A.5.x), People (8 controls, A.6.x), Physical (14 controls, A.7.x), and Technological (34 controls, A.8.x). This replaces the 2013 version's 114 controls in 14 categories. The 2022 revision also added 11 new controls including Threat Intelligence, Data Masking, Data Leakage Prevention, and Secure Coding.

What are the four risk treatment options in ISO/IEC 27001?

ISO/IEC 27001 recognizes four risk treatment options: modify (apply controls to reduce likelihood or impact), retain (accept the risk if below acceptance criteria), avoid (decide not to start or continue the risk-causing activity), and share (transfer through insurance, outsourcing, or contracts). These options are documented in the risk treatment plan and Statement of Applicability.

What is the Statement of Applicability (SoA)?

The SoA is a mandatory document required by Clause 6.1.3 d) of ISO/IEC 27001:2022. It identifies the controls determined as necessary, justifies their inclusion or exclusion compared to Annex A, and indicates implementation status. The SoA is one of the most scrutinized documents during certification audits because it directly evidences risk treatment decisions and connects the risk assessment to Annex A.

What career paths follow ISO 27001 Foundation?

Foundation typically leads to PECB ISO/IEC 27001 Lead Implementer or Lead Auditor. Implementers move into ISMS Manager, Information Security Officer, or GRC Analyst roles ($65-95K). Auditors progress toward ISMS Lead Auditor at certification bodies, Internal Audit Manager, or Compliance Consultant ($75-130K). Many candidates also pair Foundation with broader credentials like CISSP, CISA, or CISM for career advancement.