All Practice Exams

Free Practice Questions for ISO 27001 Transition

Exam-style questions and explanations by OpenExamPrep.

✓ No registration✓ No credit card
100+ Questions
100% Free

Loading practice questions...

Exam Review

Key Facts: ISO 27001 Transition Exam

40Q, 1 hour

Exam Format

PECB

70%

Passing Score

PECB

USD 500 exam-only

Exam Fee

PECB

PECB ISO/IEC 27001:2022 Transition Exam certification exam evaluates candidates on official PECB domains and standards. Note: this practice set is an English-language MCQ study adaptation.

Sample ISO 27001 Transition Practice Questions

Try these sample questions to review concepts for the ISO 27001 Transition exam. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.

1What is the official title of ISO/IEC 27001:2022?
A.Information technology — Security techniques — Information security management systems — Requirements
B.Information security, cybersecurity and privacy protection — Information security management systems — Requirements
C.Cybersecurity and privacy protection — Information security controls — Requirements
D.Information security management — Requirements for certifiable security management systems
Explanation: The 2022 edition retitled the standard to 'Information security, cybersecurity and privacy protection — Information security management systems — Requirements'. The new title reflects the standard's broader coverage of cybersecurity and privacy protection beyond traditional IT security.
2Where are the most significant differences between ISO/IEC 27001:2013 and ISO/IEC 27001:2022 found?
A.In the definition of documented information
B.In the high-level structure of clauses 4 to 10
C.In the information security controls of Annex A
D.In the requirement to establish an information security policy
Explanation: PECB states that the major changes between the 2013 and 2022 editions are in the Annex A information security controls, which were restructured from 114 controls in 14 clauses to 93 controls in 4 themes. Only minor changes were made to the main clauses of the standard.
3Which statement best describes the changes made to clauses 4 to 10 in ISO/IEC 27001:2022?
A.The clauses were completely rewritten around a new management system structure
B.Two new mandatory clauses on cybersecurity were added
C.The existing clause structure was retained, with minor edits and a new subclause 6.3 on planning of changes
D.Clause 8 on operation was removed and its content moved to Annex A
Explanation: The 2022 edition kept the harmonized clause structure (4–10) intact. Changes were limited to minor rewording, restructuring of a few subclauses (9.1, 9.2, 10), and one notable addition: subclause 6.3 'Planning of changes', requiring ISMS changes to be carried out in a planned manner.
4What does the new clause 6.3 of ISO/IEC 27001:2022, 'Planning of changes', require?
A.Annual penetration testing of all critical systems
B.Risk treatment plans to be re-approved every six months
C.All Annex A controls to be implemented before certification
D.Changes to the ISMS to be carried out in a planned manner
Explanation: Clause 6.3 is entirely new in the 2022 edition. It states that when the organization determines the need for changes to the ISMS, the changes shall be carried out in a planned manner, bringing the ISMS in line with other management system standards that already had this requirement.
5ISO/IEC 27001:2022 was published in alignment with which revised supporting standard?
A.ISO/IEC 27005 on information security risk management
B.ISO/IEC 27003 on ISMS implementation guidance
C.ISO/IEC 27002 on information security controls
D.ISO 19011 on guidelines for auditing management systems
Explanation: ISO/IEC 27001:2022 is aligned with ISO/IEC 27002:2022, which was published in February 2022 and provides implementation guidance for the restructured controls. The Annex A reference controls in ISO/IEC 27001:2022 correspond to the controls detailed in ISO/IEC 27002:2022.
6How did clause 9.1 (Monitoring, measurement, analysis and evaluation) change in the 2022 edition?
A.It was deleted and its content merged into clause 9.3
B.It was split into separate clauses for monitoring and for measurement
C.Subclauses 9.1.1 and 9.1.2 were merged into a single clause with restructured requirements
D.It now requires quarterly measurement of every Annex A control
Explanation: In ISO/IEC 27001:2013, clause 9.1 had two subclauses (9.1.1 General and 9.1.2 Information security performance evaluation). The 2022 edition merged them into a single 9.1 clause and restructured the requirements, including explicitly assigning who monitors, measures, analyses and evaluates.
7What changed in the ordering of clause 10 (Improvement) in ISO/IEC 27001:2022?
A.Nonconformity and corrective action now precedes continual improvement
B.Continual improvement (10.1) now precedes nonconformity and corrective action (10.2)
C.Clause 10 was removed entirely from the standard
D.Improvement requirements were moved into clause 6 on planning
Explanation: The 2013 edition ordered clause 10 as 10.1 Nonconformity and corrective action followed by 10.2 Continual improvement. The 2022 edition reversed this: 10.1 Continual improvement now comes first, followed by 10.2 Nonconformity and corrective action, matching the order used in other harmonized management system standards.
8How was clause 7.4 (Communication) simplified in ISO/IEC 27001:2022?
A.It removed the requirement to determine what will be communicated
B.It introduced mandatory communication plans approved by top management
C.It merged 'with whom to communicate' and 'the processes by which communication shall be effected' into 'how to communicate'
D.It requires all communications to be retained as documented information
Explanation: The 2013 edition listed five items to determine for communication (what, when, with whom, who shall communicate, and the processes by which communication shall be effected). The 2022 edition streamlined this to four items, folding the process requirement into 'how to communicate'.
9Is a Statement of Applicability (SoA) still required by ISO/IEC 27001:2022?
A.Only for organizations with more than 100 employees
B.No, the SoA was replaced by the risk register
C.Yes, clause 6.1.3 d) requires the organization to produce a Statement of Applicability
D.Only when Annex A controls are excluded
Explanation: The Statement of Applicability remains mandatory under clause 6.1.3 d). It must list the necessary controls, justify their inclusion, state whether they are implemented, and justify any exclusions of Annex A controls. During transition to the 2022 edition, the SoA must be updated to reference the restructured Annex A.
10Which new element was added to clause 8.1 (Operational planning and control) in the 2022 edition?
A.A requirement to certify all operational processes against sector standards
B.Establishing criteria for processes and implementing control of the processes in accordance with those criteria
C.A requirement to outsource all non-core operational processes
D.A monthly review of operational procedures by internal audit
Explanation: Clause 8.1 in the 2022 edition now explicitly requires the organization to establish criteria for the processes needed to meet information security requirements and to implement control of the processes in accordance with those criteria. Documented information must be available to the extent necessary to have confidence the processes were carried out as planned.

About the ISO 27001 Transition Exam

The PECB ISO/IEC 27001:2022 Transition Exam certification evaluates professional competence in governance, implementation, auditing, and management according to PECB standards.

Exam sponsor: PECB (Professional Evaluation and Certification Board). The requirements and fees below concern the certification or admission exam, separate from our free practice resources.

Questions

40 questions

Time Limit

1 hour

Passing Score

70%

Exam / Certification Fees

USD 500 exam-only

Exam sponsor website

Reported exam pass rate: Not published. PECB does not publish official exam-level pass rates. Exam sponsor website

Fees, eligibility, and exam policies can change. Confirm them with the exam sponsor before applying or paying.

Our practice resources: topics covered

We aim to reflect publicly available exam outlines and topic information in our study resources. Coverage, format, and difficulty may differ from the actual exam, and we cannot guarantee that every detail is accurate or current. Confirm exam requirements, fees, and policies with the official exam sponsor.

~25%

Overview & Context of ISO/IEC 27001:2022 Revisions

Rationale for the 2022 update, structural alignment with Annex SL, changes in Clauses 4-10, and transition timeline.

~30%

Updated Annex A Control Structure (4 Themes)

Reorganization into Organizational (37), People (8), Physical (14), and Technological (34) control categories.

~25%

New & Modified Information Security Controls

Understanding the 11 new controls (threat intelligence, cloud security, ICT readiness for BC, physical security monitoring, data masking, data leakage prevention, web filtering, secure coding).

~20%

Transitioning an ISMS & Audit Considerations

Updating Statement of Applicability (SoA), risk treatment plan adjustments, internal audit of 2022 controls, and certification body surveillance transition.

Preparing for the ISO 27001 Transition Exam

What You Need to Know

  • Passing score: 70%
  • Exam length: 40 questions
  • Time limit: 1 hour
  • Exam / certification fees: USD 500 exam-only Official sources

Using Our Practice Resources

  • Work through all 100 available questions
  • Review every answer and explanation
  • Track weak areas and revisit them
  • Use our AI tutor for tough concepts

ISO 27001 Transition: Suggested Study Strategy

1Review the official PECB candidate handbook
2Practice scenario-based questions across all domains
3Pace yourself to answer all questions within the time limit

Frequently Asked Questions

What is the format of the PECB ISO 27001:2022 Transition exam?

The official exam consists of 40 questions over 1 hour. This practice set provides 100 English-language MCQs as a study aid.

Is this practice test free?

Yes, 100% free with detailed explanations.