All Practice Exams

100+ Free PECB ISO 28000 Transition Practice Questions

Prepare for the PECB Certified ISO 28000:2022 Transition exam with instant access — no signup required.

✓ No registration✓ No credit card✓ No hidden fees✓ Start practicing immediately
Not published Pass Rate
100+ Questions
100% Free

Loading practice questions...

2026 Statistics

Key Facts: PECB ISO 28000 Transition Exam

70%

Passing Score

PECB

40 MCQ

Exam Questions

PECB Exams platform / training providers

60 minutes

Exam Duration

PECB Transition exam format

2 Domains

Competency Domains

Domain 1: Differences / Domain 2: Implementation

15 Mar 2022

ISO 28000:2022 Publication

ISO

Closed Book

Exam Delivery Mode

PECB Transition exams (MCQ)

PECB Certified ISO 28000:2022 Transition is the official PECB credential for professionals updating Security Management Systems from ISO 28000:2007 to ISO 28000:2022. The 60-minute closed-book exam consists of 40 multiple-choice questions with a 70% passing threshold. Content is divided between Domain 1 (main clause differences between 2007 and 2022) and Domain 2 (interpret and plan implementation of the 2022 changes).

Sample PECB ISO 28000 Transition Practice Questions

Try these sample questions to test your PECB ISO 28000 Transition exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.

1What is the official title of ISO 28000:2022?
A.Specification for security management systems for the supply chain
B.Security and resilience — Security management systems — Requirements
C.Information security management systems — Requirements
D.Business continuity management systems — Requirements
Explanation: ISO 28000:2022 is titled 'Security and resilience — Security management systems — Requirements'. The title change emphasizes that the standard applies to security management broadly, not only supply-chain logistics security as the 2007 title implied.
2When was ISO 28000:2022 published, cancelling and replacing ISO 28000:2007?
A.15 March 2022
B.15 March 2007
C.1 January 2015
D.31 December 2025
Explanation: ISO 28000:2022 was published on 15 March 2022 as the second edition. It cancels and replaces ISO 28000:2007 in its entirety as a technical revision.
3Which ISO technical committee is responsible for ISO 28000:2022?
A.ISO/TC 8 Ships and marine technology
B.ISO/TC 292 Security and resilience
C.ISO/IEC JTC 1/SC 27 Information security
D.ISO/TC 176 Quality management
Explanation: Responsibility for the ISO 28000 series moved to ISO/TC 292 (Security and resilience). The original 2007 standard was developed under ISO/TC 8 (Ships and marine technology).
4What structural framework did ISO 28000:2022 adopt to align with other modern ISO management system standards?
A.A proprietary maritime security clause model unique to ports
B.The ISO Harmonized Structure (formerly Annex SL / High-Level Structure)
C.The COBIT governance framework as its mandatory control set
D.The NIST Cybersecurity Framework as its sole clause structure
Explanation: ISO 28000:2022 adopts the ISO Harmonized Structure (HLS), formerly known as Annex SL / High-Level Structure. Requirements appear in Clauses 4–10, enabling integration with standards such as ISO 9001, ISO 14001, ISO 22301, and ISO/IEC 27001.
5How did the scope of ISO 28000 change from the 2007 edition to the 2022 edition?
A.It narrowed to only seaports and container terminals
B.It expanded from supply-chain-focused security to security management for organizations of any type, size, or industry, including supply-chain aspects
C.It limited applicability to organizations with more than 500 employees
D.It became mandatory only for customs authorities
Explanation: ISO 28000:2007 focused on security management systems for the supply chain. ISO 28000:2022 broadened applicability so any organization can apply the SeMS requirements, while still covering supply-chain security aspects where relevant.
6Which clauses of ISO 28000:2022 contain the auditable requirements for a security management system?
A.Clauses 1 to 3 only
B.Clauses 4 to 10
C.Annex A controls 1 to 93
D.Clauses 11 to 15
Explanation: Consistent with the Harmonized Structure, Clauses 1–3 are introductory (scope, references, terms). Auditable requirements for the SeMS are in Clauses 4 through 10.
7According to the ISO 28000:2022 foreword, which two primary technical additions support better consistency with ISO 22301?
A.Mandatory encryption algorithms and key-rotation schedules
B.Security strategies, procedures, processes and treatments; and security plans
C.Financial audit sampling rules and materiality thresholds
D.Product carbon-footprint calculation methods
Explanation: The ISO 28000:2022 foreword states that recommendations were added in Clause 8 for better consistency with ISO 22301, specifically covering security strategies, procedures, processes and treatments, and security plans.
8What did ISO 28000:2022 add in Clause 4 to improve coordination with ISO 31000?
A.A mandatory list of 114 Annex A security controls
B.Recommendations on principles for security management
C.A requirement to outsource all risk assessments
D.A ban on qualitative risk methods
Explanation: The foreword of ISO 28000:2022 notes that recommendations on principles were added in Clause 4 to give better coordination with ISO 31000 (risk management guidelines). Public summaries commonly describe eight security management principles aligned with ISO 31000 thinking.
9Which abbreviation is commonly used for the management system specified by ISO 28000:2022?
A.QMS (Quality Management System)
B.SeMS (Security Management System)
C.EMS (Environmental Management System)
D.ITSM (IT Service Management)
Explanation: ISO 28000:2022 specifies requirements for a Security Management System, commonly abbreviated SeMS (or SMS in some guidance). PECB transition materials emphasize SeMS terminology reflecting the expanded security-and-resilience framing.
10What was the title of ISO 28000:2007?
A.Security and resilience — Security management systems — Requirements
B.Specification for security management systems for the supply chain
C.Risk management — Guidelines
D.Guidelines for auditing management systems
Explanation: ISO 28000:2007 was titled 'Specification for security management systems for the supply chain', reflecting its original supply-chain-centric focus developed under maritime/supply-chain security work.

About the PECB ISO 28000 Transition Exam

The PECB Certified ISO 28000:2022 Transition certification validates professional expertise in understanding the differences between ISO 28000:2007 and ISO 28000:2022 and in planning implementation of the revised Security Management System (SeMS) requirements. The exam tests comparative knowledge of the title and scope expansion, Harmonized Structure (Annex SL) Clauses 4–10, security management principles aligned with ISO 31000, strengthened risk-based thinking, Clause 8 security strategies/treatments and security plans aligned with ISO 22301, terminology updates (SeMS), gap analysis, transition roadmaps, leadership commitment, competence, internal audit updates, and management review for conformity to ISO 28000:2022.

Questions

40 scored questions

Time Limit

60 minutes

Passing Score

70%

Exam Fee

Included with training course (PECB)

PECB ISO 28000 Transition Exam Content Outline

50%

Domain 1: Differences between main clauses of ISO 28000:2022 and ISO 28000:2007

Title/scope change to security and resilience SeMS, HLS Clauses 4–10, principles for ISO 31000 coordination, Clause 8 strategies and security plans for ISO 22301 consistency, risk-based approach, and continuity of core requirements

50%

Domain 2: Understand, interpret, and plan the implementation of ISO 28000:2022 changes

Gap analysis, transition roadmap, leadership and resources, risk assessment refresh, strategies and security plans, documented information, training, internal audit, management review, and certification readiness

How to Pass the PECB ISO 28000 Transition Exam

What You Need to Know

  • Passing score: 70%
  • Exam length: 40 questions
  • Time limit: 60 minutes
  • Exam fee: Included with training course

Keys to Passing

  • Complete 500+ practice questions
  • Score 80%+ consistently before scheduling
  • Focus on highest-weighted sections
  • Use our AI tutor for tough concepts

PECB ISO 28000 Transition Study Tips from Top Performers

1Memorize the official title change: 2007 supply-chain security management systems specification vs 2022 security-and-resilience SeMS requirements.
2Map the Harmonized Structure Clauses 4–10 and practice remapping older policy/risk/implementation/checking/review elements into HLS locations.
3Know the ISO foreword main changes: principles recommendations (ISO 31000 coordination) and Clause 8 strategies/plans (ISO 22301 consistency).
4Distinguish risk-based control selection from ISO/IEC 27001-style Annex A catalogues—ISO 28000 does not use a mandatory Annex A control list.
5Practice gap analysis outputs: clause map, gap register, owners, dates, residual risk notes, and transition roadmap milestones.
6Drill scenarios on false conformity (renumbering only), multi-site rollout, contractor scope expansion, IMS integration, and unexercised security plans.

Frequently Asked Questions

What is the PECB ISO 28000 Transition exam format?

The PECB ISO 28000 Transition exam consists of 40 multiple-choice questions to be completed in 60 minutes. The closed-book exam is delivered online via the proctored PECB Exams platform and requires a 70% score to pass.

What are the major changes in ISO 28000:2022 compared to ISO 28000:2007?

Key updates include a title change to 'Security and resilience — Security management systems — Requirements', expanded applicability beyond supply-chain-only framing, adoption of the ISO Harmonized Structure (Clauses 4–10), principles recommendations in Clause 4 for better coordination with ISO 31000, Clause 8 recommendations on security strategies/treatments and security plans for consistency with ISO 22301, a strengthened risk-based approach, and continuity of core 2007 requirements within a technical revision published 15 March 2022.

Who should earn the PECB Certified ISO 28000 Transition credential?

This credential is designed for security managers, supply chain and logistics leaders, consultants, auditors, trainers, and other professionals responsible for updating or maintaining a Security Management System from ISO 28000:2007 to ISO 28000:2022, or who need to stay current with the revised requirements.

Are there prerequisites for taking the PECB ISO 28000 Transition exam?

There are no formal professional experience requirements for the Transition credential. Participants need a general understanding of security concepts and ISO 28000 requirements to benefit from the training. Completing the official PECB ISO 28000 Transition course is the typical path and includes the exam attempt.

What domains are tested on the ISO 28000 Transition exam?

Domain 1 covers differences between the main clauses of ISO 28000:2022 and ISO 28000:2007. Domain 2 covers understanding, interpreting, and planning implementation of the ISO 28000:2022 changes (gap analysis, roadmap, and SeMS update activities).

What is the retake policy for the PECB ISO 28000 Transition exam?

Candidates who completed the training course but failed the exam are eligible to retake once for free within 12 months of the initial exam date. A mandatory 15-day waiting period typically applies between attempts under PECB exam rules.