All Practice Exams

100+ Free ISO/IEC 27701 Foundation Practice Questions

Prepare for the PECB ISO/IEC 27701 Foundation exam with instant access — no signup required.

✓ No registration✓ No credit card✓ No hidden fees✓ Start practicing immediately
Not published Pass Rate
100+ Questions
100% Free

Loading practice questions...

2026 Statistics

Key Facts: ISO/IEC 27701 Foundation Exam

40 MCQ, 1h

Exam Format

PECB Help Center — List of PECB Exams

Closed-book

Exam Type

PECB Help Center — List of PECB Exams

70%

Passing Score

PECB Examination Rules and Policies

2 domains

Competency Domains

PECB ISO/IEC 27701 Foundation page

USD 500

Exam-Only Fee (Foundation level)

PECB

3 years

Credential Validity

PECB

PECB ISO/IEC 27701 Foundation is a closed-book, 40-question, 1-hour multiple-choice exam (pass mark 70%) covering two competency domains: fundamental PIMS principles and concepts, and the PIMS itself. Successful candidates can apply for the PECB Certificate Holder in ISO/IEC 27701 Foundation credential; no professional experience is required.

Sample ISO/IEC 27701 Foundation Practice Questions

Try these sample questions to test your ISO/IEC 27701 Foundation exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.

1What is the primary purpose of a Privacy Information Management System (PIMS) based on ISO/IEC 27701?
A.To certify that an organization has fully eliminated all privacy risks to PII principals
B.To provide a framework for establishing, implementing, maintaining, and continually improving the management of personally identifiable information
C.To replace an organization's information security management system with a privacy-only system
D.To guarantee automatic compliance with every national data protection law worldwide
Explanation: ISO/IEC 27701 specifies requirements and guidance for a PIMS, which is a management system framework for the protection of privacy as it relates to processing PII. Like other ISO management system standards, it follows a continual improvement approach rather than promising zero risk or universal legal compliance.
2In the terminology of ISO/IEC 27701, what is a 'PII principal'?
A.The natural person to whom the personally identifiable information relates
B.The organization that determines the purposes of processing PII
C.The external auditor who assesses privacy compliance
D.The senior manager accountable for the privacy policy
Explanation: A PII principal is the natural person to whom the personally identifiable information (PII) relates. This corresponds to the 'data subject' in legislation such as the GDPR.
3Which statement best defines 'personally identifiable information' (PII)?
A.Any information stored electronically in a customer database
B.Only government-issued identifiers such as passport or tax numbers
C.Any information that can be used to establish a link between the information and the natural person to whom it relates
D.Information that has been formally classified as confidential by the organization
Explanation: PII is any information that can be used to identify a natural person, directly or indirectly, by establishing a link between the information and that person. This includes identifiers, but also combinations of attributes that together single out an individual.
4What distinguishes a PII controller from a PII processor?
A.The controller stores PII on its own servers while the processor always uses cloud services
B.The controller is always a public authority while the processor is always a private company
C.The controller determines the purposes and means of processing PII, while the processor processes PII on behalf of the controller
D.The controller performs privacy impact assessments while the processor performs security audits
Explanation: A PII controller determines the purposes and means of the processing of PII. A PII processor processes PII on behalf of, and according to the instructions of, the controller. This controller/processor distinction drives the two sets of PIMS-specific controls in ISO/IEC 27701.
5How does ISO/IEC 27701 relate to ISO/IEC 27001?
A.It is an extension to ISO/IEC 27001 that adds privacy-specific requirements and controls for the management of PII
B.It is a competing standard that organizations must choose instead of ISO/IEC 27001
C.It is a sector-specific version of ISO/IEC 27001 applicable only to healthcare organizations
D.It is the audit procedure used to certify ISO/IEC 27001 information security management systems
Explanation: ISO/IEC 27701 is a privacy extension to ISO/IEC 27001 (and ISO/IEC 27002). It builds on the information security management system by adding PIMS-specific requirements and guidance for PII controllers and processors, so organizations extend an ISMS into a PIMS rather than choosing between the two.
6An organization already certified to ISO/IEC 27001 wants to demonstrate privacy accountability. What does ISO/IEC 27701 allow it to do?
A.Replace its ISMS scope statement with a privacy notice published on its website
B.Extend its existing ISMS with PIMS-specific requirements and controls so the combined system manages both information security and PII privacy
C.Obtain a GDPR compliance certificate that regulators must accept as proof of conformity
D.Transfer all privacy responsibilities to its cloud service provider
Explanation: ISO/IEC 27701 is designed so an organization with an ISMS can extend it into a PIMS by applying the additional PIMS-specific requirements and the controller and/or processor controls. This creates one integrated management system covering security and privacy.
7Which ISO/IEC standard provides the code of practice for information security controls that ISO/IEC 27701 extends with privacy guidance?
A.ISO/IEC 27002
B.ISO/IEC 27005
C.ISO/IEC 27017
D.ISO/IEC 31000
Explanation: ISO/IEC 27002 provides guidance on information security controls, and ISO/IEC 27701 extends that guidance with PIMS-specific implementation guidance for protecting PII. ISO/IEC 27701 therefore builds on both ISO/IEC 27001 (requirements) and ISO/IEC 27002 (control guidance).
8Which standard provides a privacy framework of privacy principles that ISO/IEC 27701 maps to, covering principles such as consent and choice, collection limitation, and accountability?
A.ISO/IEC 27035 on incident management
B.ISO/IEC 29100
C.ISO/IEC 27031 on business continuity
D.ISO 9001
Explanation: ISO/IEC 29100 provides a high-level privacy framework with eleven privacy principles, including consent and choice, purpose legitimacy and specification, collection limitation, data minimization, and accountability. ISO/IEC 27701 includes mappings to these principles to help organizations demonstrate privacy protection.
9Under the privacy principle of 'collection limitation', an organization should:
A.Limit PII collection to what is lawful, fair, and not excessive in relation to the identified purposes
B.Collect as much PII as technically possible in case it becomes useful later
C.Limit collection to data subjects who have signed a paper consent form
D.Stop collecting any PII once the PIMS is certified
Explanation: Collection limitation requires that PII be obtained lawfully and fairly, and that collection be limited to what is adequate and not excessive for the identified purposes. Collecting data 'just in case' conflicts with this principle and with data minimization.
10What does the privacy principle of 'data minimization' require?
A.That PII be kept on the smallest possible storage devices
B.That processing be limited to the minimum PII necessary to fulfil the identified purposes
C.That organizations delete all PII at the end of each calendar year
D.That PII principals provide only their initials when registering
Explanation: Data minimization means limiting the PII processed to the minimum necessary to achieve the identified purposes. It is one of the ISO/IEC 29100 privacy principles reflected in ISO/IEC 27701 controls and in regulations such as the GDPR.

About the ISO/IEC 27701 Foundation Exam

The PECB ISO/IEC 27701 Foundation certification validates understanding of the fundamental concepts and principles of a Privacy Information Management System (PIMS) based on ISO/IEC 27701, the privacy extension to ISO/IEC 27001 and ISO/IEC 27002. It covers PII roles (principals, controllers, processors), privacy principles, lawful processing, PIMS requirements and operation, and the controller and processor control sets that support compliance with privacy laws such as the GDPR.

Questions

40 scored questions

Time Limit

1 hour

Passing Score

70%

Exam Fee

USD 500 exam-only (Foundation level); included when taken with PECB partner training (PECB (Professional Evaluation and Certification Board))

ISO/IEC 27701 Foundation Exam Content Outline

~45% (unofficial estimate; PECB does not publish domain weightings)

Fundamental Principles and Concepts of a Privacy Information Management System (PIMS)

Definitions of PII, PII principals, controllers, processors, joint controllers and sub-processors; purpose and benefits of a PIMS; privacy versus information security; the ISO/IEC 29100 privacy principles (consent and choice, collection limitation, data minimization, purpose specification, retention and disclosure limitation, accuracy, openness and notice, individual participation, accountability, information security, privacy compliance); lawful bases and consent; data subject rights; privacy impact assessments; pseudonymization versus anonymization; PII breach concepts; relationship with ISO/IEC 27001, ISO/IEC 27002 and the GDPR

~55% (unofficial estimate; PECB does not publish domain weightings)

Privacy Information Management System (PIMS)

PIMS establishment and operation: context of the organization, scope, leadership and top-management commitment, privacy policy and objectives, privacy risk assessment and treatment including the Statement of Applicability, support requirements (resources, competence, awareness, communication, documented information), operational control, performance evaluation (monitoring, internal audit, management review), nonconformity and continual improvement, plus the PIMS-specific control sets for PII controllers (obligations to principals, conditions for collection and processing, privacy by design, sharing and disclosure) and PII processors (customer instructions, contracts, records of processing, sub-processing, breach notification to customers)

How to Pass the ISO/IEC 27701 Foundation Exam

What You Need to Know

  • Passing score: 70%
  • Exam length: 40 questions
  • Time limit: 1 hour
  • Exam fee: USD 500 exam-only (Foundation level); included when taken with PECB partner training

Keys to Passing

  • Complete 500+ practice questions
  • Score 80%+ consistently before scheduling
  • Focus on highest-weighted sections
  • Use our AI tutor for tough concepts

ISO/IEC 27701 Foundation Study Tips from Top Performers

1Memorise the role definitions cold: PII principal, controller, processor, joint controller and sub-processor — many questions turn on who determines purposes and means
2Learn the eleven ISO/IEC 29100 privacy principles and be able to apply them to short scenarios (e.g. which principle is violated by collecting unused data)
3Know the management-system clause logic: context, leadership, planning, support, operation, performance evaluation, improvement — and which activities belong to each
4Contrast the two control sets: controllers owe obligations to PII principals and set conditions for collection; processors act on documented instructions, keep records and notify customers of breaches
5Understand pseudonymization versus anonymization: pseudonymized data is still PII and stays in scope of the PIMS
6Since the exam is closed-book, practise recalling definitions and clause purposes without notes using timed 40-question runs

Frequently Asked Questions

What is the PECB ISO/IEC 27701 Foundation exam format?

The exam consists of 40 multiple-choice questions with a 1-hour time limit. It is closed-book and is available online (proctored via the PECB Exams app) or paper-based at authorised PECB venues. The passing score is 70%. PECB's official exam list shows it is offered in English and Czech.

What is ISO/IEC 27701 and how does it relate to ISO/IEC 27001?

ISO/IEC 27701 is the international standard for a Privacy Information Management System (PIMS). It is a privacy extension to ISO/IEC 27001 (requirements) and ISO/IEC 27002 (control guidance), adding PIMS-specific requirements and dedicated control sets for PII controllers and PII processors. Organizations extend an existing ISMS into a PIMS rather than replacing it.

Do I need experience or prerequisites to take the Foundation exam?

No. The Foundation level has no prerequisites and requires no professional experience. PECB recommends the 2-day ISO/IEC 27701 Foundation training course, whose price includes the exam and certificate application fees. To obtain the credential you pass the exam and sign the PECB Code of Ethics.

Which topics should I prioritise when preparing?

Focus on the two official domains. For Domain 1, master PII terminology (principal, controller, processor, sub-processor, joint controller), the ISO/IEC 29100 privacy principles, lawful bases and consent, data subject rights, PIAs, and pseudonymization versus anonymization. For Domain 2, learn the management-system clauses (context, leadership, planning, support, operation, performance evaluation, improvement) and the differences between the controller and processor control sets.

How does the exam treat the GDPR and other privacy laws?

The exam is standard-based, not jurisdiction-specific, but ISO/IEC 27701 maps to instruments such as the GDPR and ISO/IEC 29100. Expect questions on GDPR-aligned concepts — lawful bases, data subject rights, breach notification expectations, international transfer safeguards — always framed as how the PIMS supports compliance rather than as legal trivia.

What happens if I fail the exam?

You can retake the exam. PECB requires a 15-day waiting period after a failed first attempt. Candidates who attended the official training course are entitled to one free retake within twelve months of the initial exam date.