All Practice Exams

100+ Free ISO 27001 Transition Practice Questions

Prepare for the PECB ISO/IEC 27001:2022 Transition Exam exam with instant access — no signup required.

✓ No registration✓ No credit card✓ No hidden fees✓ Start practicing immediately
Not published Pass Rate
100+ Questions
100% Free

Loading practice questions...

2026 Statistics

Key Facts: ISO 27001 Transition Exam

40Q, 1 hour

Exam Format

PECB

70%

Passing Score

PECB

USD 500 exam-only

Exam Fee

PECB

PECB ISO/IEC 27001:2022 Transition Exam certification exam evaluates candidates on official PECB domains and standards. Note: this practice set is an English-language MCQ study adaptation.

Sample ISO 27001 Transition Practice Questions

Try these sample questions to test your ISO 27001 Transition exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.

1What is the official title of ISO/IEC 27001:2022?
A.Information technology — Security techniques — Information security management systems — Requirements
B.Information security, cybersecurity and privacy protection — Information security management systems — Requirements
C.Cybersecurity and privacy protection — Information security controls — Requirements
D.Information security management — Requirements for certifiable security management systems
Explanation: The 2022 edition retitled the standard to 'Information security, cybersecurity and privacy protection — Information security management systems — Requirements'. The new title reflects the standard's broader coverage of cybersecurity and privacy protection beyond traditional IT security.
2Where are the most significant differences between ISO/IEC 27001:2013 and ISO/IEC 27001:2022 found?
A.In the definition of documented information
B.In the high-level structure of clauses 4 to 10
C.In the information security controls of Annex A
D.In the requirement to establish an information security policy
Explanation: PECB states that the major changes between the 2013 and 2022 editions are in the Annex A information security controls, which were restructured from 114 controls in 14 clauses to 93 controls in 4 themes. Only minor changes were made to the main clauses of the standard.
3Which statement best describes the changes made to clauses 4 to 10 in ISO/IEC 27001:2022?
A.The clauses were completely rewritten around a new management system structure
B.Two new mandatory clauses on cybersecurity were added
C.The existing clause structure was retained, with minor edits and a new subclause 6.3 on planning of changes
D.Clause 8 on operation was removed and its content moved to Annex A
Explanation: The 2022 edition kept the harmonized clause structure (4–10) intact. Changes were limited to minor rewording, restructuring of a few subclauses (9.1, 9.2, 10), and one notable addition: subclause 6.3 'Planning of changes', requiring ISMS changes to be carried out in a planned manner.
4What does the new clause 6.3 of ISO/IEC 27001:2022, 'Planning of changes', require?
A.Annual penetration testing of all critical systems
B.Risk treatment plans to be re-approved every six months
C.All Annex A controls to be implemented before certification
D.Changes to the ISMS to be carried out in a planned manner
Explanation: Clause 6.3 is entirely new in the 2022 edition. It states that when the organization determines the need for changes to the ISMS, the changes shall be carried out in a planned manner, bringing the ISMS in line with other management system standards that already had this requirement.
5ISO/IEC 27001:2022 was published in alignment with which revised supporting standard?
A.ISO/IEC 27005 on information security risk management
B.ISO/IEC 27003 on ISMS implementation guidance
C.ISO/IEC 27002 on information security controls
D.ISO 19011 on guidelines for auditing management systems
Explanation: ISO/IEC 27001:2022 is aligned with ISO/IEC 27002:2022, which was published in February 2022 and provides implementation guidance for the restructured controls. The Annex A reference controls in ISO/IEC 27001:2022 correspond to the controls detailed in ISO/IEC 27002:2022.
6How did clause 9.1 (Monitoring, measurement, analysis and evaluation) change in the 2022 edition?
A.It was deleted and its content merged into clause 9.3
B.It was split into separate clauses for monitoring and for measurement
C.Subclauses 9.1.1 and 9.1.2 were merged into a single clause with restructured requirements
D.It now requires quarterly measurement of every Annex A control
Explanation: In ISO/IEC 27001:2013, clause 9.1 had two subclauses (9.1.1 General and 9.1.2 Information security performance evaluation). The 2022 edition merged them into a single 9.1 clause and restructured the requirements, including explicitly assigning who monitors, measures, analyses and evaluates.
7What changed in the ordering of clause 10 (Improvement) in ISO/IEC 27001:2022?
A.Nonconformity and corrective action now precedes continual improvement
B.Continual improvement (10.1) now precedes nonconformity and corrective action (10.2)
C.Clause 10 was removed entirely from the standard
D.Improvement requirements were moved into clause 6 on planning
Explanation: The 2013 edition ordered clause 10 as 10.1 Nonconformity and corrective action followed by 10.2 Continual improvement. The 2022 edition reversed this: 10.1 Continual improvement now comes first, followed by 10.2 Nonconformity and corrective action, matching the order used in other harmonized management system standards.
8How was clause 7.4 (Communication) simplified in ISO/IEC 27001:2022?
A.It removed the requirement to determine what will be communicated
B.It introduced mandatory communication plans approved by top management
C.It merged 'with whom to communicate' and 'the processes by which communication shall be effected' into 'how to communicate'
D.It requires all communications to be retained as documented information
Explanation: The 2013 edition listed five items to determine for communication (what, when, with whom, who shall communicate, and the processes by which communication shall be effected). The 2022 edition streamlined this to four items, folding the process requirement into 'how to communicate'.
9Is a Statement of Applicability (SoA) still required by ISO/IEC 27001:2022?
A.Only for organizations with more than 100 employees
B.No, the SoA was replaced by the risk register
C.Yes, clause 6.1.3 d) requires the organization to produce a Statement of Applicability
D.Only when Annex A controls are excluded
Explanation: The Statement of Applicability remains mandatory under clause 6.1.3 d). It must list the necessary controls, justify their inclusion, state whether they are implemented, and justify any exclusions of Annex A controls. During transition to the 2022 edition, the SoA must be updated to reference the restructured Annex A.
10Which new element was added to clause 8.1 (Operational planning and control) in the 2022 edition?
A.A requirement to certify all operational processes against sector standards
B.Establishing criteria for processes and implementing control of the processes in accordance with those criteria
C.A requirement to outsource all non-core operational processes
D.A monthly review of operational procedures by internal audit
Explanation: Clause 8.1 in the 2022 edition now explicitly requires the organization to establish criteria for the processes needed to meet information security requirements and to implement control of the processes in accordance with those criteria. Documented information must be available to the extent necessary to have confidence the processes were carried out as planned.

About the ISO 27001 Transition Exam

The PECB ISO/IEC 27001:2022 Transition Exam certification evaluates professional competence in governance, implementation, auditing, and management according to PECB standards.

Questions

40 scored questions

Time Limit

1 hour

Passing Score

70%

Exam Fee

USD 500 exam-only (PECB (Professional Evaluation and Certification Board))

ISO 27001 Transition Exam Content Outline

~25%

Overview & Context of ISO/IEC 27001:2022 Revisions

Rationale for the 2022 update, structural alignment with Annex SL, changes in Clauses 4-10, and transition timeline.

~30%

Updated Annex A Control Structure (4 Themes)

Reorganization into Organizational (37), People (8), Physical (14), and Technological (34) control categories.

~25%

New & Modified Information Security Controls

Understanding the 11 new controls (threat intelligence, cloud security, ICT readiness for BC, physical security monitoring, data masking, data leakage prevention, web filtering, secure coding).

~20%

Transitioning an ISMS & Audit Considerations

Updating Statement of Applicability (SoA), risk treatment plan adjustments, internal audit of 2022 controls, and certification body surveillance transition.

How to Pass the ISO 27001 Transition Exam

What You Need to Know

  • Passing score: 70%
  • Exam length: 40 questions
  • Time limit: 1 hour
  • Exam fee: USD 500 exam-only

Keys to Passing

  • Complete 500+ practice questions
  • Score 80%+ consistently before scheduling
  • Focus on highest-weighted sections
  • Use our AI tutor for tough concepts

ISO 27001 Transition Study Tips from Top Performers

1Review the official PECB candidate handbook
2Practice scenario-based questions across all domains
3Pace yourself to answer all questions within the time limit

Frequently Asked Questions

What is the format of the PECB ISO 27001:2022 Transition exam?

The official exam consists of 40 questions over 1 hour. This practice set provides 100 English-language MCQs as a study aid.

Is this practice test free?

Yes, 100% free with detailed explanations.