All Practice Exams

100+ Free ISO/IEC 27002 Manager Practice Questions

Prepare for the PECB Certified ISO/IEC 27002 Manager exam with instant access — no signup required.

✓ No registration✓ No credit card✓ No hidden fees✓ Start practicing immediately
Not published Pass Rate
100+ Questions
100% Free

Loading practice questions...

2026 Statistics

Key Facts: ISO/IEC 27002 Manager Exam

60 MCQ, 2h

Exam Format

PECB Candidate Handbook

70%

Passing Score

PECB Candidate Handbook

Open-book

Exam Type

PECB Candidate Handbook

93 controls, 4 themes

ISO/IEC 27002:2022 Structure

ISO/IEC 27002:2022

USD 700

Exam-Only Fee (Manager level)

PECB Candidate Handbook

3 years

Credential Validity

PECB

PECB Certified ISO/IEC 27002 Manager is an open-book, 60-question, 2-hour MCQ exam (pass mark 70%) covering information security fundamentals and the 93 controls of ISO/IEC 27002:2022. It targets managers, consultants, and ISMS team members responsible for implementing controls, and is offered online via the PECB Exams app or paper-based at partner venues. Note: official PECB MCQs have three options; this free practice bank uses four-option questions as a study adaptation.

Sample ISO/IEC 27002 Manager Practice Questions

Try these sample questions to test your ISO/IEC 27002 Manager exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.

1Which combination of properties does information security, as defined in the ISO/IEC 27000 family, primarily aim to preserve?
A.Confidentiality, integrity, and availability
B.Authenticity, accountability, and scalability
C.Performance, usability, and compliance
D.Privacy, portability, and interoperability
Explanation: Information security is defined in the ISO/IEC 27000 family as the preservation of confidentiality, integrity, and availability of information. Confidentiality means information is not made available to unauthorized entities, integrity means accuracy and completeness are protected, and availability means information is accessible when needed by authorized users.
2What is the primary purpose of ISO/IEC 27002 in relation to an ISMS based on ISO/IEC 27001?
A.It specifies certifiable requirements that an ISMS must fulfill
B.It provides guidelines for selecting and implementing information security controls, including those referenced in Annex A of ISO/IEC 27001
C.It defines the audit criteria for ISMS certification bodies
D.It replaces ISO/IEC 27001 as the requirements standard for conformity assessment
Explanation: ISO/IEC 27002 is a code of practice that provides guidance and implementation advice for information security controls, including the controls listed in Annex A of ISO/IEC 27001. ISO/IEC 27001 remains the requirements standard against which an ISMS is certified, while ISO/IEC 27002 explains how the controls can be applied.
3How is 'cybersecurity' most accurately distinguished from 'information security' in the ISO/IEC 27002 context?
A.Cybersecurity is a subset focused on protecting information only when stored in cloud services
B.Cybersecurity applies only to government networks while information security applies to private organizations
C.Cybersecurity addresses the protection of cyberspace itself (networks, systems, and services) to preserve security of information in cyberspace, whereas information security covers information in all forms and locations
D.The two terms are exact synonyms with no difference in scope
Explanation: Information security applies to information in any form and location, including paper records and verbal communication. Cybersecurity is concerned with the protection of cyberspace — the interconnected environment of networks, systems, and services — and the information processed within it. The two disciplines overlap heavily but are not identical in scope.
4In the ISO/IEC 27000 family vocabulary, how is 'privacy' most appropriately characterized for an ISO/IEC 27002 implementation?
A.The process of encrypting all personal data at rest
B.A legal term that has no relationship to information security controls
C.The deletion of all personally identifiable information after one year
D.The right of individuals to control or influence what information related to them is collected, processed, and disclosed
Explanation: Privacy relates to the rights and expectations of individuals regarding their personally identifiable information (PII), including control over its collection, processing, storage, and disclosure. ISO/IEC 27002 includes controls (such as 5.34 on privacy and protection of PII) that help organizations meet privacy obligations, but privacy is a broader concept than any single technical measure.
5Which of the following is a correct description of the relationship between a threat, a vulnerability, and an information security risk?
A.A threat is a potential cause of an incident; a vulnerability is a weakness that can be exploited by a threat; risk is the potential effect on objectives resulting from threats exploiting vulnerabilities
B.A risk exists only when a vulnerability is patched
C.A vulnerability is an external attacker and a threat is an internal weakness
D.Risk, threat, and vulnerability are interchangeable terms in ISO/IEC 27002
Explanation: In ISO risk management terminology, a threat is a potential cause of an unwanted incident, a vulnerability is a weakness of an asset or control that can be exploited by threats, and information security risk is the potential that threats will exploit vulnerabilities of assets, causing harm to the organization. Understanding this relationship underpins risk assessment and control selection.
6According to ISO/IEC 27001 risk treatment principles reflected in ISO/IEC 27002 guidance, which of the following is NOT one of the four typical risk treatment options?
A.Modifying the risk by applying controls
B.Ignoring the risk without documentation
C.Sharing the risk, for example through insurance or outsourcing
D.Avoiding the risk by ceasing the activity that gives rise to it
Explanation: The four recognized risk treatment options are: modify (apply controls to reduce likelihood or impact), retain/accept (make an informed, documented decision to accept the risk), avoid (stop the activity causing the risk), and share (transfer some consequences via insurance, contracts, or outsourcing). Ignoring a risk without analysis and documented acceptance is not a legitimate treatment option.
7What is the Statement of Applicability (SoA) in the context of an ISMS?
A.A marketing document describing the organization's security products
B.A certificate issued by the accreditation body confirming the ISMS scope
C.A documented statement listing the information security controls the organization has determined are necessary, with justifications for inclusion and exclusion, and their implementation status
D.An internal memo assigning staff to the information security team
Explanation: The Statement of Applicability is a mandatory ISMS document required by ISO/IEC 27001. It records which Annex A controls (and any additional controls) the organization has determined necessary, the justification for each inclusion or exclusion, and whether each control is implemented. It links the risk assessment and risk treatment decisions to the actual control environment.
8How are the information security controls organized in ISO/IEC 27002:2022?
A.Into 14 clauses mirroring the structure of the 2013 edition
B.Into three categories: preventive, detective, and corrective
C.Into two parts: mandatory controls and optional controls
D.Into four themes: organizational, people, physical, and technological
Explanation: ISO/IEC 27002:2022 reorganized the controls into four themes: organizational controls (clause 5), people controls (clause 6), physical controls (clause 7), and technological controls (clause 8). The 2022 edition contains 93 controls, replacing the 14-domain structure of the 2013 edition.
9ISO/IEC 27002:2022 assigns attributes to each control to help organizations view them from different perspectives. Which set correctly identifies the five attribute types introduced in the 2022 edition?
A.Control type; information security properties; cybersecurity concepts; operational capabilities; security domains
B.Cost; complexity; maturity; ownership; criticality
C.Clause number; annex reference; audit frequency; risk rating; reviewer
D.Confidentiality; integrity; availability; authenticity; non-repudiation
Explanation: Each ISO/IEC 27002:2022 control carries five attribute types: control type (preventive, detective, corrective), information security properties (confidentiality, integrity, availability), cybersecurity concepts aligned with NIST functions (identify, protect, detect, respond, recover), operational capabilities (15 capability groups), and security domains (governance and ecosystem, protection, defence, resilience). Organizations can use these hashtags to filter and map controls to their own frameworks.
10An organization decides to accept a residual risk after implementing controls. Whose approval is required for this decision to be valid within the ISMS?
A.The external certification auditor
B.The risk owners, in line with the organization's established risk acceptance criteria
C.The information security officer alone, without any documented criteria
D.The IT help desk manager
Explanation: Risk acceptance decisions must be made by the designated risk owners against the organization's documented risk acceptance criteria, which are established as part of the risk management process. This ensures acceptance is an informed, accountable decision rather than an oversight, and the decision is recorded for traceability.

About the ISO/IEC 27002 Manager Exam

The PECB Certified ISO/IEC 27002 Manager certification validates the competence to support an organization in selecting, implementing, and managing information security controls based on ISO/IEC 27002:2022, particularly within an ISMS based on ISO/IEC 27001. It covers fundamental concepts of information security, cybersecurity, and privacy, plus the full set of 93 controls across the organizational, people, physical, and technological themes. This question bank is an English-language MCQ study adaptation with four answer options per question; the official PECB multiple-choice exam presents three options per question.

Questions

60 scored questions

Time Limit

2 hours

Passing Score

70%

Exam Fee

USD 700 exam-only (Manager level); included when taken with PECB partner training (PECB (Professional Evaluation and Certification Board))

ISO/IEC 27002 Manager Exam Content Outline

~30% (estimated; PECB does not publish per-domain weightings)

Fundamental Principles and Concepts of Information Security, Cybersecurity, and Privacy

CIA properties and additional security properties; information security vs cybersecurity vs privacy; asset, threat, vulnerability, and risk terminology; risk assessment criteria and the four risk treatment options; the ISO/IEC 27000 family (27000, 27001, 27002, 27004, 27005); ISMS context, interested parties, and top-management leadership; Statement of Applicability; ISO/IEC 27002:2022 structure with four themes and five control attribute types; governance, policy hierarchy, and continual improvement (PDCA)

~70% (estimated; PECB does not publish per-domain weightings)

Information Security Controls Based on ISO/IEC 27002

Implementation and management of the 93 controls of ISO/IEC 27002:2022: 37 organizational controls (5.1-5.37: policies, segregation of duties, threat intelligence, asset inventory, classification, information transfer, access control, identity and authentication information, access rights, supplier relationships and cloud services, incident management 5.24-5.28, disruption and ICT readiness 5.29-5.30, legal and compliance requirements, independent review, documented procedures); 8 people controls (6.1-6.8: screening, employment terms, awareness, disciplinary process, post-termination, NDAs, remote working, event reporting); 14 physical controls (7.1-7.14: perimeters, entry, facilities, monitoring, environmental threats, secure areas work, clear desk, siting, off-premises assets, storage media, utilities, cabling, maintenance, disposal); 34 technological controls (8.1-8.34: endpoints, privileged access, source code, secure authentication, capacity, malware, vulnerabilities, configuration, deletion, masking, DLP, backup, redundancy, logging, monitoring, clock sync, privileged utilities, software installation, networks 8.20-8.22, web filtering, cryptography, secure SDLC 8.25-8.28, security testing, outsourced development, environment separation, change management, test information, audit testing protection)

How to Pass the ISO/IEC 27002 Manager Exam

What You Need to Know

  • Passing score: 70%
  • Exam length: 60 questions
  • Time limit: 2 hours
  • Exam fee: USD 700 exam-only (Manager level); included when taken with PECB partner training

Keys to Passing

  • Complete 500+ practice questions
  • Score 80%+ consistently before scheduling
  • Focus on highest-weighted sections
  • Use our AI tutor for tough concepts

ISO/IEC 27002 Manager Study Tips from Top Performers

1Bring a tabbed hard copy of ISO/IEC 27002:2022 to the exam — it is open-book, and fast navigation by control number (5.x to 8.x) saves valuable minutes
2Learn the four-theme structure cold: 37 organizational, 8 people, 14 physical, and 34 technological controls, and which clause covers which theme
3Memorize the incident management sequence (5.24 planning, 5.25 assessment and decision, 5.26 response, 5.27 learning, 5.28 evidence) and the supplier chain (5.19-5.23)
4Practice distinguishing paired controls: identity management (5.16) vs authentication information (5.17), independent review (5.35) vs compliance with policies (5.36), masking (8.11) vs DLP (8.12)
5Work through scenario sets, not just definitions: the exam uses context-dependent scenario questions where you must apply controls to a described organization
6Understand the five control attribute types (control type, security properties, cybersecurity concepts, operational capabilities, security domains) introduced in the 2022 edition

Frequently Asked Questions

What is the PECB ISO/IEC 27002 Manager exam format?

The exam contains 60 multiple-choice questions to be completed in 2 hours, with a passing score of 70%. It is open-book: you may use a hard copy of the ISO/IEC 27002 standard, your training course materials, personal notes, and a printed dictionary. Questions include stand-alone items and scenario-based sets. The exam is taken online via the PECB Exams application or paper-based at authorised partner venues. Note that official PECB multiple-choice questions present three answer options.

Is this practice bank the same as the official PECB exam?

No. This is an independent English-language MCQ study adaptation, not an official PECB simulation. The official exam presents 60 questions with three answer options each in an open-book, proctored setting, while this bank uses 100 four-option questions for practice. It is designed to build the knowledge the official competency domains assess, but passing it does not guarantee passing the official exam, and it is not affiliated with or endorsed by PECB.

What is the difference between ISO/IEC 27001 and ISO/IEC 27002 for exam purposes?

ISO/IEC 27001 is the requirements standard: it specifies what an ISMS must do (clauses 4-10) and is the standard an organization is certified against. ISO/IEC 27002 is the guidance standard: it explains how to implement information security controls, including the 93 controls referenced in Annex A of ISO/IEC 27001. The PECB ISO/IEC 27002 Manager exam focuses on implementing and managing those controls, while expecting you to understand the ISMS context in which they operate.

How is ISO/IEC 27002:2022 structured?

The 2022 edition contains 93 controls organized into four themes: 37 organizational controls (clause 5), 8 people controls (clause 6), 14 physical controls (clause 7), and 34 technological controls (clause 8). Each control also carries attributes for control type (preventive, detective, corrective), security properties (confidentiality, integrity, availability), cybersecurity concepts aligned to the NIST functions (identify, protect, detect, respond, recover), operational capabilities, and security domains, allowing organizations to filter controls by different perspectives.

What are the requirements to become PECB Certified ISO/IEC 27002 Manager?

After passing the exam, the full Manager credential requires two years of professional experience (including one year in information security management), 200 hours of information security management activities such as drafting an ISMS implementation plan or selecting and implementing controls, and signing the PECB Code of Ethics. A Provisional Manager credential is available with no experience requirement, so passing the exam alone still yields a credential. Certifications are valid for three years, maintained with CPD hours and an annual maintenance fee.

What happens if I fail the exam?

You can retake the exam with no limit on the number of attempts, but you must wait 15 days after a failed first attempt. If you took the training course with a PECB partner, your fee includes one free retake within 12 months from the date the coupon code was received. Candidates who fail receive a list of the domains where they performed poorly to guide further study, and PECB recommends attending a training course if you fail the retake.