100+ Free ISO/IEC 27005 Foundation Practice Questions
Prepare for the PECB ISO/IEC 27005 Foundation exam with instant access — no signup required.
Loading practice questions...
Explore More PECB Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
Key Facts: ISO/IEC 27005 Foundation Exam
40 MCQ, 1h
Exam Format
PECB Candidate Handbook / Training Course Catalog
70%
Passing Score
PECB Candidate Handbook
Closed-book
Exam Type
PECB Candidate Handbook
USD 500
Exam-Only Fee
PECB Candidate Handbook
2 domains, 50/50
Domain Weighting
PECB Candidate Handbook
3 options
Answers per Question
PECB Candidate Handbook
PECB ISO/IEC 27005 Foundation is a closed-book, 40-question, 1-hour MCQ exam (70% to pass) covering the two handbook domains at 50% each: fundamental concepts of information security risk management, and risk management approaches and processes. Official questions carry three response options; scenario-based items are included. Entry-level, no experience required.
Sample ISO/IEC 27005 Foundation Practice Questions
Try these sample questions to test your ISO/IEC 27005 Foundation exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.
1What does ISO/IEC 27005 provide?
2How is information security risk defined in ISO/IEC 27005?
3According to ISO 31000, risk is defined as:
4Which statement best describes a threat in information security risk management?
5A vulnerability is best defined as:
6In the context of information security risk management, an asset is:
7Confidentiality, as a property of information, means that:
8An attacker modifies transaction amounts in a database without authorization. Which property of information security has primarily been harmed?
9Availability is the property of:
10Which combination correctly distinguishes a risk from a threat and a vulnerability?
About the ISO/IEC 27005 Foundation Exam
The PECB ISO/IEC 27005 Foundation certificate program validates that holders understand the fundamental concepts, principles, and processes of information security risk management based on ISO/IEC 27005. The closed-book exam covers two equally weighted domains: fundamental risk management concepts (definitions, CIA, controls, principles, roles) and the risk management process (context establishment, assessment, treatment, acceptance, communication, recording, and monitoring). It is an entry-level credential with no professional experience prerequisites. Note: the official exam presents each question with three response options; this practice bank uses four-option MCQs as a study adaptation covering the same competency domains.
Questions
40 scored questions
Time Limit
1 hour
Passing Score
70%
Exam Fee
USD 500 exam-only (Foundation level), plus USD 200 certificate application; included when taken with PECB partner training (PECB (Professional Evaluation and Certification Board))
ISO/IEC 27005 Foundation Exam Content Outline
Fundamental Concepts of Information Security Risk Management
Structure and purpose of ISO/IEC 27005; relation to ISO 31000, ISO/IEC 27001, IEC/ISO 31010, and the ISO/IEC 27000 family; definitions of information security risk, threat, vulnerability, event, consequence, likelihood, and opportunity; confidentiality, integrity, and availability; classification of controls by type and function; risk management principles; definition and advantages of risk management; risk assessment vs risk management; roles of the risk owner, risk manager, top management, and interested parties (20 of 40 exam questions)
Information Security Risk Management Approaches and Processes
Analyzing the organization and its context; basic criteria (risk evaluation, impact, risk acceptance); scope and boundaries; choosing an assessment methodology; asset-based and event-based risk identification; qualitative, quantitative, and semi-quantitative analysis; risk evaluation and prioritization; treatment options (modification, retention, avoidance, sharing) and the risk treatment plan; residual risk evaluation and acceptance; risk communication and consultation; recording and reporting; monitoring and review; management review, corrective actions, and continual improvement (20 of 40 exam questions)
How to Pass the ISO/IEC 27005 Foundation Exam
What You Need to Know
- Passing score: 70%
- Exam length: 40 questions
- Time limit: 1 hour
- Exam fee: USD 500 exam-only (Foundation level), plus USD 200 certificate application; included when taken with PECB partner training
Keys to Passing
- Complete 500+ practice questions
- Score 80%+ consistently before scheduling
- Focus on highest-weighted sections
- Use our AI tutor for tough concepts
ISO/IEC 27005 Foundation Study Tips from Top Performers
Frequently Asked Questions
What is the PECB ISO/IEC 27005 Foundation exam format?
The exam contains 40 multiple-choice questions to be completed in 1 hour, and the passing score is 70%. It is closed-book: no standards, training materials, or notes are allowed. Each official question offers three response options (one correct, two distractors), and the exam mixes stand-alone questions with scenario-based questions. It can be taken online (proctored via the PECB Exams application) or paper-based through an authorised partner.
Does this practice bank exactly match the official exam format?
Not exactly — it is a study adaptation. The official PECB exam gives each question three response options, while this bank uses four-option MCQs and contains 100 questions rather than 40. The content, however, follows the official competency domains and their 50/50 weighting, so it builds the same knowledge the exam measures.
How much does the PECB ISO/IEC 27005 Foundation exam cost?
According to the candidate handbook, the Foundation exam costs USD 500 when purchased directly, plus a USD 200 certificate application fee. Candidates who complete the training course with an authorised PECB partner typically have the course, the exam (first attempt and first retake), and the certificate application bundled into the training fee, with the cycle completed within 12 months.
What are the two exam domains and their weightings?
Domain 1, Fundamental Concepts of Information Security Risk Management, covers definitions (risk, threat, vulnerability, event, consequence, likelihood), the CIA properties, control classification, risk management principles, and key roles. Domain 2, Information Security Risk Management Approaches and Processes, covers context establishment, risk identification/analysis/evaluation, treatment options and plans, residual risk acceptance, communication, recording and reporting, and monitoring and review. Each domain contributes 20 of the 40 questions (50%).
What happens if I fail the exam?
PECB permits unlimited retakes subject to the waiting periods in its Exam Rules and Policies (a 15-day wait applies after a failed first attempt). Candidates who fail receive an email listing the domains where they performed poorly to guide retake preparation. When the exam is bundled with partner training, the first retake is included.
Are there prerequisites for the ISO/IEC 27005 Foundation certificate?
No professional or risk management experience is required — it is an entry-level credential. Candidates need at least secondary education, must complete the PECB training course (required for ANAB-accredited certificate programs), pass the exam, and sign the PECB Code of Ethics. Successful candidates earn the designation 'PECB Certificate Holder in ISO/IEC 27005 Foundation'.