All Practice Exams

100+ Free ISO/IEC 27034 Foundation Practice Questions

Prepare for the PECB Certified ISO/IEC 27034 Foundation exam with instant access — no signup required.

✓ No registration✓ No credit card✓ No hidden fees✓ Start practicing immediately
Not published Pass Rate
100+ Questions
100% Free

Loading practice questions...

2026 Statistics

Key Facts: ISO/IEC 27034 Foundation Exam

40 MCQ, 1h

Exam Format

PECB List of Exams

Closed-book

Exam Type

PECB List of Exams

70%

Passing Score

PECB Examination and Certification Program

USD 500

Exam-Only Fee (Foundation)

PECB

2 domains

Competency Domains

PECB ISO/IEC 27034 Foundation Brochure

English

Exam Language

PECB List of Exams

PECB Certified ISO/IEC 27034 Foundation is a closed-book, 40-question, 1-hour multiple-choice exam (English) covering two domains: application security fundamentals and organizational/application security planning, implementation, and monitoring. Passing score is 70%. The exam-only fee is USD 500 (Foundation level), and the exam is delivered online via the PECB Exams app or on paper at authorised venues.

Sample ISO/IEC 27034 Foundation Practice Questions

Try these sample questions to test your ISO/IEC 27034 Foundation exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.

1What is the primary purpose of ISO/IEC 27034?
A.To define legal penalties for application security breaches
B.To certify software products as free of vulnerabilities
C.To replace the organization's information security management system
D.To provide guidelines for embedding security throughout the application life cycle
Explanation: ISO/IEC 27034 gives organizations a structured, life cycle approach to application security, integrating security controls from development through deployment, operation, and maintenance. It complements rather than replaces an ISMS such as one based on ISO/IEC 27001.
2Which property of information security ensures that information is accessible and usable when needed by authorized users?
A.Confidentiality
B.Availability
C.Integrity
D.Authenticity
Explanation: Availability is the property of being accessible and usable upon demand by an authorized entity. Together with confidentiality and integrity, it forms the classic CIA triad that underpins application security objectives in ISO/IEC 27034.
3In application security terms, what is a vulnerability?
A.A potential cause of an unwanted incident that may harm a system
B.A weakness of an asset or control that can be exploited by a threat
C.The estimated financial loss from a security incident
D.A control applied to reduce risk to an acceptable level
Explanation: A vulnerability is a weakness in an asset, process, or control that could be exploited by one or more threats. In ISO/IEC 27034, identifying application vulnerabilities feeds the risk assessment used to select Application Security Controls.
4What is the Organization Normative Framework (ONF) in ISO/IEC 27034?
A.A regulatory authority that audits an organization's applications
B.A set of security controls hard-coded into every application the organization buys
C.A centralized repository of the organization's application security components, such as business context, specifications, roles, processes, and the ASC library
D.A software tool that automatically tests applications for vulnerabilities
Explanation: The ONF is the organization's centralized repository of application security components: business, regulatory, and technical contexts, specifications, roles and responsibilities, processes, and the Application Security Control (ASC) library. All Application Normative Frameworks (ANFs) are derived from the ONF.
5How is the Application Normative Framework (ANF) best described?
A.A contract between the organization and its penetration testing supplier
B.A generic international framework applied identically to every application
C.The documented source code security review of a single application
D.A framework derived from the ONF that contains the ASCs and processes a specific application needs to reach its Targeted Level of Trust
Explanation: An ANF is created for a specific application by selecting and tailoring components of the ONF so the application can achieve its Targeted Level of Trust (TLT). It contains the applicable ASCs and processes adapted to that application's context and risk.
6What does the Targeted Level of Trust (TLT) represent for an application?
A.The market share the application is expected to reach
B.The security level the application must achieve, determined by the sensitivity of its information and the risks it faces
C.The maximum number of users the application can support
D.The compliance score assigned by an external certification body
Explanation: The TLT is the required level of security confidence for an application, derived from the sensitivity of the information it processes and the organization's risk assessment. Application Security Controls are selected and verified so the application's actual level of trust meets the TLT.
7What is an Application Security Control (ASC)?
A.A scoring model for ranking software developers
B.A firewall rule that protects the entire corporate network
C.A legal clause inserted into outsourcing contracts
D.A security measure applied to protect an application, selected from the ONF's ASC library and tailored in the ANF
Explanation: An ASC is a control applied at the application level to mitigate identified risks. Organizations maintain an ASC library within the ONF, and the controls relevant to a given application are selected and tailored into its ANF to meet the TLT.
8Confidentiality, as a security principle, primarily ensures that:
A.information is accurate and complete
B.systems remain operational during disruptions
C.information is not made available or disclosed to unauthorized individuals, entities, or processes
D.users can be held accountable for their actions
Explanation: Confidentiality is the property that information is not made available or disclosed to unauthorized individuals, entities, or processes. Application controls such as access control and encryption help preserve confidentiality of information handled by applications.
9Which statement best describes the relationship between ISO/IEC 27034 and ISO/IEC 27001?
A.ISO/IEC 27034 replaces ISO/IEC 27001 for organizations that develop software
B.The two standards are unrelated and cannot be used together
C.ISO/IEC 27001 certifies applications while ISO/IEC 27034 certifies organizations
D.ISO/IEC 27034 complements an ISO/IEC 27001-based ISMS by adding a life cycle approach to application security
Explanation: ISO/IEC 27034 is independent of, but well aligned with, ISO/IEC 27001. It deepens application-level security within the broader ISMS, and both can be managed with a process approach consistent with Plan-Do-Check-Act.
10In risk management terms, how is information security risk generally understood?
A.The probability that a vendor will miss a delivery deadline
B.The total cost of all security controls in the budget
C.The number of incidents detected by the security operations centre
D.The potential that threats will exploit vulnerabilities of an asset and thereby cause harm to the organization
Explanation: Risk combines the likelihood that threats exploit vulnerabilities with the resulting business impact on assets. ISO/IEC 27034 uses this understanding to determine an application's Targeted Level of Trust and to select proportionate ASCs.

About the ISO/IEC 27034 Foundation Exam

The PECB Certified ISO/IEC 27034 Foundation certification validates understanding of application security fundamentals based on the ISO/IEC 27034 series. It covers the Organization Normative Framework (ONF), Application Normative Frameworks (ANFs), Application Security Controls (ASCs), the Targeted Level of Trust (TLT), and the processes for planning, implementing, verifying, and monitoring application security across the application life cycle.

Questions

40 scored questions

Time Limit

1 hour

Passing Score

70%

Exam Fee

USD 500 exam-only (Foundation level); included when taken with PECB partner training (PECB (Professional Evaluation and Certification Board))

ISO/IEC 27034 Foundation Exam Content Outline

~40%

Fundamental Principles and Concepts of Application Security

Purpose and scope of ISO/IEC 27034; confidentiality, integrity, and availability; threats, vulnerabilities, and risk; structure of the ISO/IEC 27034 series (Part 1 overview and concepts, Part 2 ONF, Part 3 management process, Part 5/5-1 ASC data structures and XML schemas, Part 6 case studies, Part 7 assurance prediction); ONF components (business, regulatory, and technical contexts, specifications, roles, processes, ASC library); ANF derivation; Application Security Controls; Targeted vs actual level of trust; Application Security Life Cycle; alignment with ISO/IEC 27001 and the PDCA process approach

~60%

Organizational and Application Security Planning, Implementation, and Monitoring

Establishing and maintaining the ONF; validating application security requirements; application security risk assessment (threats, vulnerabilities, impact, sensitive information); setting and approving the Targeted Level of Trust; deriving and tailoring ANFs; selecting and implementing ASCs (in, on, or around the application); verification methods and independence; KPIs and monitoring; audits and management reviews; risk acceptance; change management and re-verification; third-party and procurement considerations; corrective action and continual improvement

How to Pass the ISO/IEC 27034 Foundation Exam

What You Need to Know

  • Passing score: 70%
  • Exam length: 40 questions
  • Time limit: 1 hour
  • Exam fee: USD 500 exam-only (Foundation level); included when taken with PECB partner training

Keys to Passing

  • Complete 500+ practice questions
  • Score 80%+ consistently before scheduling
  • Focus on highest-weighted sections
  • Use our AI tutor for tough concepts

ISO/IEC 27034 Foundation Study Tips from Top Performers

1Memorize the core framework components and how they relate: ONF (organizational repository) -> ANF (application-specific) -> ASCs (controls) -> TLT (target assurance level)
2Learn the ISO/IEC 27034 series structure: Part 1 overview/concepts, Part 2 ONF, Part 3 management process, Part 5/5-1 ASC data structure and XML schemas, Part 6 case studies, Part 7 assurance prediction
3The exam is closed-book: drill definitions of threat, vulnerability, risk, and the CIA triad until recall is instant
4Master the process sequence: establish ONF, identify application and sensitive information, assess risk, set TLT, derive ANF, implement ASCs, verify, monitor, improve
5Understand verification depth: higher TLTs demand stronger and more independent verification evidence
6Practice with timed 40-question sets to build pace for the 1-hour limit

Frequently Asked Questions

What is the PECB ISO/IEC 27034 Foundation exam format?

The PECB ISO/IEC 27034 Foundation exam consists of 40 multiple-choice questions with a 1-hour time limit. It is a closed-book exam delivered in English, available online through the proctored PECB Exams app or in paper form at authorised exam venues. The passing score is 70%.

What are the ONF, ANF, and ASC in ISO/IEC 27034?

The Organization Normative Framework (ONF) is the organization's centralized repository of application security components: business, regulatory, and technical contexts, specifications, roles, processes, and the Application Security Control (ASC) library. An Application Normative Framework (ANF) is derived from the ONF for a specific application, containing the selected and tailored ASCs and processes needed to reach that application's Targeted Level of Trust (TLT). ASCs are security controls applied at the application level.

Is the ISO/IEC 27034 Foundation exam open-book?

No. According to the PECB List of Exams, the ISO/IEC 27034 Foundation exam is closed-book, unlike many PECB Lead-level exams which are open-book. You cannot use the standard, training materials, or notes during the exam, so memorizing the core concepts (ONF, ANF, ASC, TLT, and the process sequence) is essential.

What is the Targeted Level of Trust (TLT)?

The TLT is the security level an application must achieve, determined through risk analysis of the sensitivity of the information it processes, stores, or transmits, plus relevant threats, vulnerabilities, and business impact. Controls are implemented and verified so the application's actual level of trust meets the TLT, and significant changes trigger reassessment.

How much does the PECB ISO/IEC 27034 Foundation exam cost?

The exam-only fee for PECB Foundation-level exams is USD 500. When you take the exam as part of a PECB partner training course, the exam fee is included in the course price, and candidates who fail the first attempt are eligible for one free retake within 12 months of receiving the exam coupon.

What happens if I fail the exam?

PECB requires a 15-day waiting period after a failed first attempt before retaking the exam. If you completed the training course with a PECB partner, you are entitled to one free retake within a 12-month period from the date the coupon code was received; otherwise retake fees apply.