All Practice Exams

100+ Free ISO/IEC 27005 Foundation Practice Questions

Prepare for the PECB ISO/IEC 27005 Foundation exam with instant access — no signup required.

✓ No registration✓ No credit card✓ No hidden fees✓ Start practicing immediately
Not published Pass Rate
100+ Questions
100% Free

Loading practice questions...

2026 Statistics

Key Facts: ISO/IEC 27005 Foundation Exam

40 MCQ, 1h

Exam Format

PECB Candidate Handbook / Training Course Catalog

70%

Passing Score

PECB Candidate Handbook

Closed-book

Exam Type

PECB Candidate Handbook

USD 500

Exam-Only Fee

PECB Candidate Handbook

2 domains, 50/50

Domain Weighting

PECB Candidate Handbook

3 options

Answers per Question

PECB Candidate Handbook

PECB ISO/IEC 27005 Foundation is a closed-book, 40-question, 1-hour MCQ exam (70% to pass) covering the two handbook domains at 50% each: fundamental concepts of information security risk management, and risk management approaches and processes. Official questions carry three response options; scenario-based items are included. Entry-level, no experience required.

Sample ISO/IEC 27005 Foundation Practice Questions

Try these sample questions to test your ISO/IEC 27005 Foundation exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.

1What does ISO/IEC 27005 provide?
A.Requirements for establishing and certifying an information security management system
B.Guidelines for managing information security risks
C.A catalogue of risk assessment techniques with worked examples
D.Mandatory controls that every organization must implement
Explanation: ISO/IEC 27005 provides guidelines for managing information security risks. It supports the implementation of the information security risk management requirements of ISO/IEC 27001 and aligns with the general risk management guidelines of ISO 31000.
2How is information security risk defined in ISO/IEC 27005?
A.Coordinated activities to direct and control an organization with regard to risk
B.An identified occurrence indicating a possible breach of information security policy
C.The effect of uncertainty on information security objectives
D.A weakness of an asset that can be exploited by a threat
Explanation: Information security risk is defined as the effect of uncertainty on information security objectives. It is the ISO 31000 definition of risk applied specifically to information security objectives such as confidentiality, integrity, and availability.
3According to ISO 31000, risk is defined as:
A.The effect of uncertainty on objectives
B.The probability that a threat will exploit a vulnerability
C.The potential financial loss from an adverse event
D.Any deviation from an approved security policy
Explanation: ISO 31000 defines risk as the effect of uncertainty on objectives. The effect can be positive, negative, or both, and an effect is a deviation from what is expected.
4Which statement best describes a threat in information security risk management?
A.A weakness in a system that an attacker could exploit
B.The outcome of an event that affects objectives
C.The likelihood that harm will occur
D.A potential cause of an unwanted incident that can harm a system or organization
Explanation: A threat is a potential cause of an unwanted incident which can result in harm to a system or organization. Threats can be deliberate, accidental, or environmental in origin.
5A vulnerability is best defined as:
A.An external actor intending to cause harm to the organization
B.A weakness of an asset or control that can be exploited by one or more threats
C.Any event that has already caused a security breach
D.The residual exposure remaining after risk treatment
Explanation: A vulnerability is a weakness of an asset or control that can be exploited by one or more threats. Vulnerabilities only contribute to risk when a relevant threat has the potential to exploit them.
6In the context of information security risk management, an asset is:
A.Only the physical hardware owned by the organization
B.Only information stored in electronic form
C.Anything that has value to the organization
D.Any item listed in the organization's financial accounts
Explanation: An asset is anything that has value to the organization. In information security this includes information, software, hardware, services, people, and intangibles such as reputation and image.
7Confidentiality, as a property of information, means that:
A.Information is not made available or disclosed to unauthorized individuals, entities, or processes
B.Information is accurate and complete at all times
C.Information is accessible and usable on demand by authorized users
D.Information can be traced back to its original creator
Explanation: Confidentiality is the property that information is not made available or disclosed to unauthorized individuals, entities, or processes. It is one of the three core properties of information security alongside integrity and availability.
8An attacker modifies transaction amounts in a database without authorization. Which property of information security has primarily been harmed?
A.Availability
B.Confidentiality
C.Authenticity of the database server hardware
D.Integrity
Explanation: Integrity is the property of accuracy and completeness of information and processing methods. Unauthorized modification of data directly damages integrity, even if no information was disclosed.
9Availability is the property of:
A.Preventing unauthorized changes to information
B.Being accessible and usable upon demand by an authorized entity
C.Ensuring information is never disclosed outside the organization
D.Guaranteeing that data is backed up off-site
Explanation: Availability is the property of being accessible and usable upon demand by an authorized entity. Loss of availability occurs, for example, when a denial-of-service attack or equipment failure prevents legitimate use.
10Which combination correctly distinguishes a risk from a threat and a vulnerability?
A.Risk is a weakness, a threat is an outcome, and a vulnerability is an uncertainty
B.Risk is the attacker, a threat is the weakness, and a vulnerability is the impact
C.Risk is the effect of uncertainty on objectives, a threat is a potential cause of an unwanted incident, and a vulnerability is a weakness that a threat can exploit
D.Risk, threat, and vulnerability are three interchangeable terms for the same concept
Explanation: These three concepts are distinct: risk is the effect of uncertainty on objectives; a threat is a potential cause of an unwanted incident; and a vulnerability is a weakness that can be exploited by a threat. Risk typically materializes when a threat exploits a vulnerability and causes consequences for assets.

About the ISO/IEC 27005 Foundation Exam

The PECB ISO/IEC 27005 Foundation certificate program validates that holders understand the fundamental concepts, principles, and processes of information security risk management based on ISO/IEC 27005. The closed-book exam covers two equally weighted domains: fundamental risk management concepts (definitions, CIA, controls, principles, roles) and the risk management process (context establishment, assessment, treatment, acceptance, communication, recording, and monitoring). It is an entry-level credential with no professional experience prerequisites. Note: the official exam presents each question with three response options; this practice bank uses four-option MCQs as a study adaptation covering the same competency domains.

Questions

40 scored questions

Time Limit

1 hour

Passing Score

70%

Exam Fee

USD 500 exam-only (Foundation level), plus USD 200 certificate application; included when taken with PECB partner training (PECB (Professional Evaluation and Certification Board))

ISO/IEC 27005 Foundation Exam Content Outline

50%

Fundamental Concepts of Information Security Risk Management

Structure and purpose of ISO/IEC 27005; relation to ISO 31000, ISO/IEC 27001, IEC/ISO 31010, and the ISO/IEC 27000 family; definitions of information security risk, threat, vulnerability, event, consequence, likelihood, and opportunity; confidentiality, integrity, and availability; classification of controls by type and function; risk management principles; definition and advantages of risk management; risk assessment vs risk management; roles of the risk owner, risk manager, top management, and interested parties (20 of 40 exam questions)

50%

Information Security Risk Management Approaches and Processes

Analyzing the organization and its context; basic criteria (risk evaluation, impact, risk acceptance); scope and boundaries; choosing an assessment methodology; asset-based and event-based risk identification; qualitative, quantitative, and semi-quantitative analysis; risk evaluation and prioritization; treatment options (modification, retention, avoidance, sharing) and the risk treatment plan; residual risk evaluation and acceptance; risk communication and consultation; recording and reporting; monitoring and review; management review, corrective actions, and continual improvement (20 of 40 exam questions)

How to Pass the ISO/IEC 27005 Foundation Exam

What You Need to Know

  • Passing score: 70%
  • Exam length: 40 questions
  • Time limit: 1 hour
  • Exam fee: USD 500 exam-only (Foundation level), plus USD 200 certificate application; included when taken with PECB partner training

Keys to Passing

  • Complete 500+ practice questions
  • Score 80%+ consistently before scheduling
  • Focus on highest-weighted sections
  • Use our AI tutor for tough concepts

ISO/IEC 27005 Foundation Study Tips from Top Performers

1Memorise the exact ISO definitions and learn to separate risk, threat, vulnerability, event, consequence, and likelihood — the exam tests these distinctions directly
2Know the two risk identification approaches cold: asset-based starts from assets; event-based starts from risk sources and operational scenarios
3Drill the four risk treatment options (modification, retention, avoidance, sharing) with real-world examples such as insurance for sharing and decommissioning for avoidance
4Remember that risk assessment = identification + analysis + evaluation only; treatment, acceptance, and monitoring are separate processes
5Study the risk management principles from ISO 31000 (integrated, customized, inclusive, dynamic, best available information, human and cultural factors, continual improvement)
6Because the exam is closed-book, practise recalling domain content without notes and finish timed sets well inside the 1-hour limit

Frequently Asked Questions

What is the PECB ISO/IEC 27005 Foundation exam format?

The exam contains 40 multiple-choice questions to be completed in 1 hour, and the passing score is 70%. It is closed-book: no standards, training materials, or notes are allowed. Each official question offers three response options (one correct, two distractors), and the exam mixes stand-alone questions with scenario-based questions. It can be taken online (proctored via the PECB Exams application) or paper-based through an authorised partner.

Does this practice bank exactly match the official exam format?

Not exactly — it is a study adaptation. The official PECB exam gives each question three response options, while this bank uses four-option MCQs and contains 100 questions rather than 40. The content, however, follows the official competency domains and their 50/50 weighting, so it builds the same knowledge the exam measures.

How much does the PECB ISO/IEC 27005 Foundation exam cost?

According to the candidate handbook, the Foundation exam costs USD 500 when purchased directly, plus a USD 200 certificate application fee. Candidates who complete the training course with an authorised PECB partner typically have the course, the exam (first attempt and first retake), and the certificate application bundled into the training fee, with the cycle completed within 12 months.

What are the two exam domains and their weightings?

Domain 1, Fundamental Concepts of Information Security Risk Management, covers definitions (risk, threat, vulnerability, event, consequence, likelihood), the CIA properties, control classification, risk management principles, and key roles. Domain 2, Information Security Risk Management Approaches and Processes, covers context establishment, risk identification/analysis/evaluation, treatment options and plans, residual risk acceptance, communication, recording and reporting, and monitoring and review. Each domain contributes 20 of the 40 questions (50%).

What happens if I fail the exam?

PECB permits unlimited retakes subject to the waiting periods in its Exam Rules and Policies (a 15-day wait applies after a failed first attempt). Candidates who fail receive an email listing the domains where they performed poorly to guide retake preparation. When the exam is bundled with partner training, the first retake is included.

Are there prerequisites for the ISO/IEC 27005 Foundation certificate?

No professional or risk management experience is required — it is an entry-level credential. Candidates need at least secondary education, must complete the PECB training course (required for ANAB-accredited certificate programs), pass the exam, and sign the PECB Code of Ethics. Successful candidates earn the designation 'PECB Certificate Holder in ISO/IEC 27005 Foundation'.