All Practice Exams

100+ Free ISO/IEC 27005 Lead Risk Manager Practice Questions

Prepare for the PECB Certified ISO/IEC 27005:2022 Lead Risk Manager exam with instant access — no signup required.

✓ No registration✓ No credit card✓ No hidden fees✓ Start practicing immediately
Not published Pass Rate
100+ Questions
100% Free

Loading practice questions...

2026 Statistics

Key Facts: ISO/IEC 27005 Lead Risk Manager Exam

80 MCQ, 3h

Exam Format

PECB Candidate Handbook

70%

Passing Score

PECB ISO/IEC 27005:2022 Certification Scheme

Open-book

Exam Type

PECB Candidate Handbook

USD 1000

Exam-Only Fee (Lead)

PECB Candidate Handbook

6 domains

Competency Domains

PECB Candidate Handbook

3 years

Credential Validity

PECB Certification Maintenance Policy

PECB Certified ISO/IEC 27005:2022 Lead Risk Manager is an open-book, 80-question, 3-hour multiple-choice exam (stand-alone plus scenario-based items) with a 70% passing score. It targets professionals who design and run information security risk management programs across six domains from fundamentals to assessment methodologies.

Sample ISO/IEC 27005 Lead Risk Manager Practice Questions

Try these sample questions to test your ISO/IEC 27005 Lead Risk Manager exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.

1What is the primary purpose of ISO/IEC 27005?
A.To specify mandatory requirements that an information security management system must fulfil for certification
B.To provide guidelines for managing information security risks within an organization
C.To define a catalogue of security controls that organizations must implement
D.To certify products and cloud services against information security criteria
Explanation: ISO/IEC 27005 provides guidelines for information security risk management, supporting the risk management requirements of an ISMS based on ISO/IEC 27001. It is a guidance document, not a requirements standard, so organizations cannot be certified against ISO/IEC 27005 itself.
2In the context of ISO/IEC 27005, how is information security risk best described?
A.The probability that a cyberattack will succeed against an organization
B.The financial loss an organization suffers after a security incident
C.The potential that threats will exploit vulnerabilities of assets and thereby cause harm to the organization
D.The weakness in a system that can be triggered by an external event
Explanation: Information security risk is the potential that a given threat will exploit vulnerabilities of an asset or group of assets and thereby cause harm to the organization. It is typically expressed as a combination of the likelihood of an event and its consequence.
3During a risk assessment, Lina discovers that employees do not change their passwords as required by the password policy because the system does not enforce the rule. What has Lina identified?
A.A vulnerability
B.A threat
C.A risk treatment
D.A security control
Explanation: A vulnerability is a weakness of an asset or control that can be exploited by one or more threats. The lack of enforcement of the password change rule is an internal weakness, so it is a vulnerability. Risk would arise when a threat (e.g. an attacker guessing weak passwords) exploits this vulnerability, causing harm.
4A technology company uses ISO/IEC 27005 as the guideline for establishing its information security risk management process. Is this an appropriate use of the standard?
A.No, ISO/IEC 27005 may only be used by organizations that are already certified to ISO/IEC 27001
B.No, ISO/IEC 27005 specifies requirements for achieving information security through an ISMS and cannot be used as guidance
C.Only if the organization operates in the financial sector, where the standard is mandated
D.Yes, ISO/IEC 27005 provides guidance to assist organizations in performing information security risk management activities
Explanation: ISO/IEC 27005 is a guidance standard applicable to any type of organization that wishes to manage information security risks. It supports, but does not require, an ISMS based on ISO/IEC 27001, and prior certification is not a precondition for using it.
5Who is a risk owner?
A.The external auditor who verifies the effectiveness of the risk management process
B.The insurance provider that underwrites the organization's residual risks
C.The person or entity with the accountability and authority to manage a risk
D.The consultant who performed the most recent penetration test
Explanation: A risk owner is the person or entity with the accountability and authority to manage a risk. Risk owners decide on risk treatment and formally accept residual risk within their level of authority.
6How does ISO/IEC 27005 relate to ISO 31000?
A.ISO/IEC 27005 replaces ISO 31000 for all risk management activities
B.ISO/IEC 27005 supports and is aligned with the general risk management guidelines of ISO 31000, applied specifically to information security
C.ISO 31000 applies only to financial risk, while ISO/IEC 27005 applies to all other risk types
D.The two standards are unrelated and use conflicting risk management terminology
Explanation: ISO 31000 provides generic principles and guidelines for risk management in any discipline. ISO/IEC 27005 aligns with those concepts and applies them specifically to information security risk management, so the two standards are consistent by design.
7What are risk criteria?
A.Terms of reference against which the significance of risk is evaluated
B.A list of all controls the organization has already implemented
C.The maximum budget allocated to the risk treatment plan
D.The mandatory set of risks defined by regulators for each industry
Explanation: Risk criteria are the terms of reference against which the significance of risk is evaluated. They include impact criteria, likelihood definitions, risk evaluation criteria, and risk acceptance criteria, and they are defined during context establishment.
8A risk analyst notes that organized criminal groups are actively targeting e-commerce platforms with credential-stuffing attacks. In risk management terms, what has the analyst identified?
A.A vulnerability
B.A residual risk
C.A control
D.A threat
Explanation: A threat is a potential cause of an unwanted incident that may result in harm to a system or organization. Organized criminal groups conducting credential-stuffing attacks are a threat source; their activity represents a threat. A vulnerability would be an internal weakness that such a threat could exploit.
9What is residual risk?
A.The risk identified before any risk assessment has been performed
B.The risk remaining after risk treatment
C.The risk that has been fully eliminated by avoidance
D.The sum of all risks recorded in the risk register
Explanation: Residual risk is the risk remaining after risk treatment has been applied. Because controls rarely eliminate risk completely, residual risk must be evaluated against the risk acceptance criteria and explicitly accepted by the appropriate risk owners.
10An asset-based risk identification approach distinguishes between primary and supporting assets. Which of the following best represents primary assets?
A.Routers, switches, and firewalls that carry network traffic
B.The data centre facility and its power supply equipment
C.Business processes and the information they handle
D.Software applications and operating systems
Explanation: In an asset-based approach, primary assets are the business processes, activities, and information of value to the organization. Supporting assets — such as hardware, software, network equipment, personnel, and facilities — are the assets on which the primary assets depend, and threats typically compromise supporting assets to harm primary ones.

About the ISO/IEC 27005 Lead Risk Manager Exam

The PECB Certified ISO/IEC 27005:2022 Lead Risk Manager certification validates the skills to establish, lead, and continually improve an information security risk management program based on ISO/IEC 27005. It covers context establishment, risk assessment (identification, analysis, evaluation), risk treatment and acceptance, communication and monitoring, and leading methodologies such as OCTAVE, MEHARI, EBIOS RM, NIST SP 800-30, CRAMM, and Harmonized TRA, aligned with an ISO/IEC 27001 ISMS.

Questions

80 scored questions

Time Limit

3 hours

Passing Score

70%

Exam Fee

USD 1000 exam-only (Lead level); included when taken with PECB partner training (PECB (Professional Evaluation and Certification Board))

ISO/IEC 27005 Lead Risk Manager Exam Content Outline

~12%

Fundamental Principles and Concepts of Information Security Risk Management

Core definitions (risk, asset, threat, vulnerability, consequence, risk owner, residual risk), the CIA consequence model, ISO/IEC 27005's guidance role versus ISO/IEC 27001 requirements, alignment with ISO 31000, and the iterative nature of the process

~20%

Implementation of an Information Security Risk Management Program

Context establishment (basic risk criteria, scope and boundaries, organization for risk management), top management leadership, roles of risk managers and risk owners, competence and resources, awareness, framework versus process, and review of context after change

~22%

Information Security Risk Assessment

Risk identification of assets, threats, existing controls, vulnerabilities, and consequences; qualitative, quantitative, and semi-quantitative analysis; likelihood and impact estimation; level of risk; risk evaluation and prioritization against criteria; risk registers; consistent, valid, comparable results

~20%

Information Security Risk Treatment

The four treatment options (modification, retention, avoidance, sharing), control selection referencing ISO/IEC 27001 Annex A and ISO/IEC 27002 guidance, Statement of Applicability, risk treatment plans, cost-benefit and proportionality, residual risk acceptance by risk owners

~14%

Information Security Risk Communication, Monitoring, and Improvement

Continual communication and consultation with interested parties, audience-tailored reporting, monitoring and review activities, periodic and change-triggered reassessment, documented information, key risk indicators, management review inputs, and continual improvement

~12%

Information Security Risk Assessment Methodologies

Selection and tailoring of methodologies compatible with ISO/IEC 27005: OCTAVE and OCTAVE Allegro, MEHARI (CLUSIF), EBIOS RM (ANSSI), NIST SP 800-30 and the RMF, CRAMM, and Harmonized TRA, including their origins, structures, and fit to organizational context

How to Pass the ISO/IEC 27005 Lead Risk Manager Exam

What You Need to Know

  • Passing score: 70%
  • Exam length: 80 questions
  • Time limit: 3 hours
  • Exam fee: USD 1000 exam-only (Lead level); included when taken with PECB partner training

Keys to Passing

  • Complete 500+ practice questions
  • Score 80%+ consistently before scheduling
  • Focus on highest-weighted sections
  • Use our AI tutor for tough concepts

ISO/IEC 27005 Lead Risk Manager Study Tips from Top Performers

1Read ISO/IEC 27005 itself before the exam — it is open-book, so practise navigating to context establishment, assessment, treatment, and monitoring clauses quickly
2Drill the vocabulary distinctions the exam loves: threat vs vulnerability vs risk, inherent vs residual risk, and risk owner vs risk manager
3Memorise the four treatment options (modification, retention, avoidance, sharing) and practise classifying real scenarios, such as insurance (sharing) and decommissioning a system (avoidance)
4Know the process sequence cold: context establishment -> assessment (identification, analysis, evaluation) -> treatment -> acceptance, with communication and monitoring running throughout
5Learn one distinguishing fact per methodology: OCTAVE Allegro (streamlined, information-asset focus), MEHARI (CLUSIF), EBIOS RM (ANSSI workshops), NIST SP 800-30 (risk assessment guide), CRAMM (UK asset-based), Harmonized TRA (Canada)
6Practise scenario-based question sets, since the real exam includes scenarios with five linked questions each — read the scenario once and annotate the key facts before answering

Frequently Asked Questions

What is the PECB ISO/IEC 27005 Lead Risk Manager exam format?

The exam contains 80 multiple-choice questions in a 3-hour session and requires 70% to pass. It mixes stand-alone questions with scenario-based sets (five questions per scenario). It is open-book: candidates may use a hard copy of the ISO/IEC 27005 standard, training course materials, and personal notes. Note that official PECB exam questions present three answer options, while this practice bank uses four options for broader distractor coverage.

How much does the PECB ISO/IEC 27005 Lead Risk Manager exam cost?

Taken without training, the Lead-level exam costs USD 1000. When taken with a PECB partner training course, the training fee includes the first exam attempt, one free retake, the certification application fee, and the first year of the Annual Maintenance Fee, within 12 months of course completion (or purchase for self-study/eLearning).

Which domains does the exam cover and how are they weighted?

The PECB candidate handbook defines six domains: risk management fundamentals, program implementation, risk assessment, risk treatment, communication/monitoring/improvement, and risk assessment methodologies. PECB confirms the exam contains 80 questions mapped to these domains; risk assessment and risk treatment carry the greatest weight in practice, so prioritise those alongside context establishment.

How does ISO/IEC 27005 relate to ISO/IEC 27001 for the exam?

ISO/IEC 27001 requires organizations to define and apply risk assessment and risk treatment processes and to produce a Statement of Applicability; ISO/IEC 27005 provides the guidance for doing exactly that. Expect questions on how the two standards interact — including that ISO/IEC 27005 contains guidance, not certifiable requirements — and on concepts like consistent, valid, and comparable assessment results.

Which risk assessment methodologies should I know?

Domain 6 expects familiarity with OCTAVE and OCTAVE Allegro (self-directed, organization-focused), MEHARI (developed by CLUSIF in France), EBIOS RM (ANSSI's workshop-based method), NIST SP 800-30 and the Risk Management Framework, CRAMM (UK, asset-based), and Harmonized TRA (Canada). Know what distinguishes each and how to select or tailor a method to the organization's context.

What is the retake policy and how long is the credential valid?

Retakes are unlimited, with a 15-day waiting period after a failed first attempt; partner training packages include one free retake. PECB certifications are valid for three years and are maintained through continuing professional development (CPD) hours and payment of the Annual Maintenance Fee.