116+ Free ISO 27001 Foundation Practice Questions
Prepare for the PECB Certificate Holder in ISO/IEC 27001:2022 Foundation exam with instant access — no signup required.
Loading practice questions...
Explore More PECB Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
Key Facts: ISO 27001 Foundation Exam
70%
Passing Score
PECB
40
Exam Questions
60 minutes
$500
Exam Fee (USD)
PECB standalone list price
93
Annex A Controls (2022)
ISO/IEC 27001:2022
4
Annex A Themes
Organizational, People, Physical, Technological
No expiration
Certification Validity
PECB
PECB ISO/IEC 27001:2022 Foundation is a 1-hour exam with 40 multiple-choice questions and a 70% passing score. PECB lists a $500 standalone exam fee and $200 certificate application fee; candidates completing the required course through a PECB Partner have the first attempt, first retake, and certificate application included in the training price. The entry-level certificate program covers 2 domains weighted 50/50: Fundamental Principles and Concepts of Information Security Management, and the Information Security Management System (ISMS). Coverage spans the CIA triad, ISO/IEC 27001:2022 Clauses 4-10, PDCA, 93 Annex A controls, risk management, and the Statement of Applicability. There is no professional-experience prerequisite, but candidates must complete the Foundation training course, pass the exam, apply for the certificate, and sign the PECB Code of Ethics. The Foundation certificate does not expire.
Sample ISO 27001 Foundation Practice Questions
Try these sample questions to test your ISO 27001 Foundation exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 116+ question experience with AI tutoring.
1What does the 'CIA triad' stand for in information security?
2Which standard contains the auditable requirements that an organization can be certified against?
3What does ISMS stand for?
4How many controls does Annex A of ISO/IEC 27001:2022 contain?
5Into how many themes are Annex A controls organized in ISO/IEC 27001:2022?
6Which clauses of ISO/IEC 27001:2022 contain the mandatory ISMS requirements?
7What does the PDCA cycle stand for in the context of an ISMS?
8Which property of information ensures that it is not disclosed to unauthorized individuals?
9Which property ensures that information is accurate and has not been altered in an unauthorized manner?
10Which property ensures that information is accessible and usable upon demand by an authorized entity?
About the ISO 27001 Foundation Exam
The PECB ISO/IEC 27001 Foundation certification validates fundamental knowledge of information security concepts and the ISO/IEC 27001:2022 standard. It is the entry-level credential in the PECB ISO 27001 path, sitting below Lead Implementer and Lead Auditor. The exam covers the CIA triad, ISMS fundamentals, Clauses 4-10, Annex A (93 controls in 4 themes), risk management basics, PDCA cycle, Statement of Applicability, and the ISO/IEC 27000 family of standards.
Questions
40 scored questions
Time Limit
60 minutes
Passing Score
70%
Exam Fee
$500 USD standalone exam + $200 USD certificate application; included with partner training (PECB)
ISO 27001 Foundation Exam Content Outline
Fundamental Principles and Concepts of Information Security Management
CIA triad, authenticity, non-repudiation, accountability, reliability; PECB ISMS terminology; assets, threats, vulnerabilities, controls; risk identification, analysis, evaluation, and four risk treatment options (modify, retain, avoid, share); the broader ISO/IEC 27000 family of standards
Information Security Management System (ISMS)
ISMS purpose, ISO/IEC 27001:2022 Clauses 4-10, PDCA cycle, top management responsibilities, continual improvement; Annex A controls and Statement of Applicability (93 controls across 4 themes: 37 Organizational, 8 People, 14 Physical, 34 Technological); Stage 1/Stage 2 certification audits
How to Pass the ISO 27001 Foundation Exam
What You Need to Know
- Passing score: 70%
- Exam length: 40 questions
- Time limit: 60 minutes
- Exam fee: $500 USD standalone exam + $200 USD certificate application; included with partner training
Keys to Passing
- Complete 500+ practice questions
- Score 80%+ consistently before scheduling
- Focus on highest-weighted sections
- Use our AI tutor for tough concepts
ISO 27001 Foundation Study Tips from Top Performers
Frequently Asked Questions
What is the PECB ISO/IEC 27001 Foundation exam?
It is a 1-hour, 40-question multiple-choice exam across 2 domains weighted 50/50. The passing score is 70%. PECB lists a $500 standalone exam fee and $200 certificate application fee, while PECB Partner training packages include the first attempt, first retake, and certificate application. The exam can be online or paper-based through the training partner. The Foundation certificate does not expire.
What is the difference between ISO/IEC 27001 Foundation, Lead Implementer, and Lead Auditor?
Foundation is the entry-level certificate program that validates fundamental understanding of ISO/IEC 27001 concepts. It has no professional-experience prerequisite, but the PECB Foundation training course is required. Lead Implementer is for professionals responsible for designing, implementing, and managing an ISMS; Lead Auditor is for professionals who plan and conduct ISMS audits.
How is Annex A structured in ISO/IEC 27001:2022?
ISO/IEC 27001:2022 organizes Annex A into 93 controls across 4 themes: Organizational (37 controls, A.5.x), People (8 controls, A.6.x), Physical (14 controls, A.7.x), and Technological (34 controls, A.8.x). This replaces the 2013 version's 114 controls in 14 categories. The 2022 revision also added 11 new controls including Threat Intelligence, Data Masking, Data Leakage Prevention, and Secure Coding.
What are the four risk treatment options in ISO/IEC 27001?
ISO/IEC 27001 recognizes four risk treatment options: modify (apply controls to reduce likelihood or impact), retain (accept the risk if below acceptance criteria), avoid (decide not to start or continue the risk-causing activity), and share (transfer through insurance, outsourcing, or contracts). These options are documented in the risk treatment plan and Statement of Applicability.
What is the Statement of Applicability (SoA)?
The SoA is a mandatory document required by Clause 6.1.3 d) of ISO/IEC 27001:2022. It identifies the controls determined as necessary, justifies their inclusion or exclusion compared to Annex A, and indicates implementation status. The SoA is one of the most scrutinized documents during certification audits because it directly evidences risk treatment decisions and connects the risk assessment to Annex A.
What career paths follow ISO 27001 Foundation?
Foundation typically leads to PECB ISO/IEC 27001 Lead Implementer or Lead Auditor. Implementers move into ISMS Manager, Information Security Officer, or GRC Analyst roles ($65-95K). Auditors progress toward ISMS Lead Auditor at certification bodies, Internal Audit Manager, or Compliance Consultant ($75-130K). Many candidates also pair Foundation with broader credentials like CISSP, CISA, or CISM for career advancement.