All Practice Exams

100+ Free PECB ISO 28000 Foundation Practice Questions

Prepare for the PECB Certified ISO 28000 Foundation exam with instant access — no signup required.

✓ No registration✓ No credit card✓ No hidden fees✓ Start practicing immediately
Not published Pass Rate
100+ Questions
100% Free

Loading practice questions...

2026 Statistics

Key Facts: PECB ISO 28000 Foundation Exam

40 Questions

Exam Format

PECB ISO 28000 Foundation Exam Specifications

60 Minutes

Exam Time Limit

PECB Exams Platform

70%

Passing Score

PECB Certification Rules

Clauses 4–10

ISO 28000 Requirements Scope

ISO 28000 Standard Structure

ISO 28001 & 28004

Key Guidance Standards

ISO TC 8 / SC 11 Supply Chain Security Standards

Closed Book

Exam Delivery Mode

PECB Exam Rules

PECB ISO 28000 Foundation is PECB's entry-level credential for supply chain security management systems based on ISO 28000. The exam consists of 40 multiple-choice questions in 60 minutes with a 70% passing score, testing core concepts of supply chain security management, security risk evaluation, operational safeguards, and the Plan-Do-Check-Act (PDCA) clause structure of ISO 28000.

Sample PECB ISO 28000 Foundation Practice Questions

Try these sample questions to test your PECB ISO 28000 Foundation exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.

1What is the primary objective of the ISO 28000 standard?
A.To specify requirements for a Security Management System for the Supply Chain (SCSMS)
B.To establish international accounting guidelines for supply chain logistics providers
C.To replace customs declaration forms with automated digital manifests across global borders
D.To standardise environmental management practices for maritime freight transport
Explanation: ISO 28000 specifies requirements for establishing, implementing, maintaining, and improving a Security Management System for the Supply Chain (SCSMS). It helps organisations manage security risks, protect cargo and assets, and build resilience throughout supply chain operations.
2Which standard in the ISO 28000 family provides guidance and best practices on implementing an ISO 28000 Security Management System?
A.ISO 28004
B.ISO 28001
C.ISO 28003
D.ISO 28005
Explanation: ISO 28004 provides general guidelines for the implementation of ISO 28000. It offers guidance on understanding, implementing, and improving a supply chain security management system.
3In the context of ISO 28000, how is a 'supply chain' defined?
A.A linked set of resources and processes that begins with the sourcing of raw materials and extends through the delivery of products or services to the end user
B.Only the physical movement of finished goods from a warehouse to a retail store
C.The financial clearing network used by international freight forwarders to process payments
D.The software applications responsible for enterprise resource planning (ERP) in manufacturing
Explanation: In ISO 28000, supply chain is broadly defined as a linked set of resources and processes that begins with the sourcing of raw materials and extends through the delivery of products or services to the end user across all modes of transport and facilities.
4Which standard within the ISO 28000 family sets out specific requirements for certification bodies auditing SCSMS organisations?
A.ISO 28003
B.ISO 28000
C.ISO 28001
D.ISO 28002
Explanation: ISO 28003 establishes requirements for audit and certification bodies that provide audit and certification of security management systems for the supply chain under ISO 28000.
5ISO 28000 is structured around which management framework methodology?
A.Plan-Do-Check-Act (PDCA)
B.Six Sigma DMAIC
C.Agile Scrum Sprint Cycle
D.ITIL Service Lifecycle
Explanation: ISO 28000 follows the Plan-Do-Check-Act (PDCA) continual improvement cycle, consistent with other ISO management system standards such as ISO 9001 and ISO 27001.
6What is the primary focus of ISO 28001 standard within supply chain management?
A.Best practices for implementing supply chain security, security assessments, and developing security plans
B.Establishing legal penalties for cargo theft across international waters
C.Defining technical specifications for RFID tags used on cargo containers
D.Managing occupational health and safety conditions for port dockworkers
Explanation: ISO 28001 provides requirements and guidance for organisations in international supply chains to conduct security assessments and develop security plans to mitigate identified risks.
7Which of the following is considered an intentional security threat to a supply chain, as opposed to an operational safety hazard?
A.Cargo theft and contraband smuggling
B.Accidental engine failure during transit
C.Adverse weather causing delivery delays
D.Equipment wear and tear from routine use
Explanation: Security management under ISO 28000 focuses specifically on intentional human acts such as theft, terrorism, sabotage, piracy, and smuggling, whereas accidents and weather are safety or operational risks.
8How does ISO 28000 integrate with existing management systems like ISO 9001 or ISO 27001?
A.It shares the ISO High-Level Structure (Harmonized Structure), allowing seamless alignment of risk management, policies, and audits
B.It requires organisations to completely dismantle ISO 9001 procedures and implement standalone SCSMS files
C.It can only be integrated if the organisation operates exclusively in maritime shipping
D.It prohibits shared management reviews or joint internal audits across standards
Explanation: ISO 28000 (especially the updated 2022 edition) adopts the Harmonized Structure common to ISO management system standards. This enables organisations to integrate SCSMS with quality (ISO 9001), environmental (ISO 14001), or information security (ISO 27001) management systems.
9An organisation wants to demonstrate to international customs authorities that its supply chain processes are secure. Which standard serves as the certifiable requirements baseline?
A.ISO 28000
B.ISO 28004-1
C.ISO 31000
D.ISO 19011
Explanation: ISO 28000 is the normative standard containing requirements against which an organisation can be formally audited and certified by an accredited certification body.
10What role does top management play during the 'Plan' phase of the PDCA cycle in an ISO 28000 SCSMS?
A.Establishing the security policy, ensuring security objectives are set, and allocating necessary resources
B.Performing daily physical security inspections at cargo loading docks
C.Writing technical code for firewalls protecting logistics databases
D.Conducting third-party certification audits on competing suppliers
Explanation: During the 'Plan' phase, top management demonstrates leadership by defining the security policy, ensuring security objectives align with strategic direction, and committing required resources for the SCSMS.

About the PECB ISO 28000 Foundation Exam

Entry-level certification validating knowledge of the ISO 28000 standard for Security Management Systems for the Supply Chain (SCSMS), including fundamental security management concepts, security risk assessment, operational security controls, legal and regulatory requirements, and ISO 28000 clause requirements (Clauses 4 through 10).

Questions

40 scored questions

Time Limit

60 minutes

Passing Score

70%

Exam Fee

Included with training course (PECB)

PECB ISO 28000 Foundation Exam Content Outline

~50%

Fundamental Concepts and Principles of Security Management and an SCSMS based on ISO 28000

Supply chain security concepts, ISO 28000 family standards overview (28000, 28001, 28004, 28002, 28003, 28005), security risk assessment, security policy, and legal/regulatory supply chain security frameworks (C-TPAT, AEO, ISPS Code, WCO SAFE)

~50%

ISO 28000 Requirements for a Security Management System (Clauses 4 to 10)

ISO 28000 clauses 4 through 10 requirements: context of the organization, leadership and security policy, planning and risk assessment, support and competence, operation and security controls, performance evaluation and audit, and continual improvement

How to Pass the PECB ISO 28000 Foundation Exam

What You Need to Know

  • Passing score: 70%
  • Exam length: 40 questions
  • Time limit: 60 minutes
  • Exam fee: Included with training course

Keys to Passing

  • Complete 500+ practice questions
  • Score 80%+ consistently before scheduling
  • Focus on highest-weighted sections
  • Use our AI tutor for tough concepts

PECB ISO 28000 Foundation Study Tips from Top Performers

1Memorise the high-level structure of ISO 28000: Clauses 4 to 10 (Context, Leadership, Planning, Support, Operation, Performance Evaluation, Improvement)
2Understand the difference between ISO 28000 (requirements standard), ISO 28001 (operational supply chain security practices), and ISO 28004 (guidance standard)
3Master the key steps in security risk assessment: threat identification, vulnerability assessment, likelihood & impact estimation, and security risk evaluation
4Learn the core global supply chain security initiatives: C-TPAT (Customs-Trade Partnership Against Terrorism), AEO (Authorized Economic Operator), ISPS Code, and WCO SAFE Framework
5Differentiate between security threats (intentional acts like theft, piracy, sabotage, terrorism) and operational safety risks
6Know top management obligations under ISO 28000 Clause 5: defining security policy, allocating resources, ensuring role assignment, and conducting management reviews

Frequently Asked Questions

What is the PECB ISO 28000 Foundation exam format?

The PECB ISO 28000 Foundation exam consists of 40 multiple-choice questions to be completed in 60 minutes. The exam is closed-book, proctored online via the PECB Exams platform, and requires a passing score of 70%.

What topics are covered on the PECB ISO 28000 Foundation exam?

The exam covers two main domains: Domain 1 focuses on fundamental concepts and principles of security management and supply chain security management systems (SCSMS). Domain 2 focuses on ISO 28000 requirements across Clauses 4 to 10 (Context, Leadership, Planning, Support, Operation, Performance Evaluation, and Improvement).

What is ISO 28000?

ISO 28000 is an international standard that specifies requirements for a Security Management System for the Supply Chain (SCSMS). It helps organizations identify security risks across their supply chains, implement controls to mitigate vulnerabilities, and protect goods, assets, information, and personnel from security threats like cargo theft, terrorism, smuggling, and cyber-physical disruptions.

What related standards belong to the ISO 28000 series?

The ISO 28000 series includes ISO 28000 (SCSMS requirements), ISO 28001 (best practices for implementing supply chain security, assessments, and plans), ISO 28004 (guidelines for implementing ISO 28000), ISO 28002 (resilience in the supply chain), ISO 28003 (requirements for audit and certification bodies), and ISO 28005 (electronic port clearance).

Are there prerequisites for taking the PECB ISO 28000 Foundation exam?

There are no formal education or work experience prerequisites. PECB recommends completing the 2-day PECB ISO 28000 Foundation training course or equivalent self-study prior to taking the exam.

What is the retake policy for PECB Foundation exams?

Candidates who fail the exam are allowed one free retake within 12 months of course activation. A mandatory 15-day waiting period applies between attempts.