Foundation Practice Exam

A comprehensive review and 20-question practice exam covering everything from lessons 1-13 — ISMS fundamentals, all clauses, all 93 Annex A controls, the SoA, and the certification process.

Hard 90m 1 task

Learning Objectives

  • Recall key concepts across all 13 preceding Foundation lessons under exam-like conditions
  • Apply the same reasoning-over-memorization approach real Foundation exams test
  • Self-assess readiness for an accredited Foundation-level exam
  • Identify which specific lessons to revisit based on missed questions

This is the capstone of the Foundation tier — a comprehensive review and a 20-question practice exam spanning every lesson so far. Treat it like the real thing: work through it without re-opening previous lessons first, then use your results to target your review.

What a real Foundation-level exam typically looks like

Accredited bodies (PECB, BSI, IBITGQ, and others) each run their own exam, and formats vary — always check the specific body's current exam guide rather than assuming. That said, most Foundation-level ISO/IEC 27001 exams share some general characteristics: multiple-choice format, a time limit of roughly an hour, and a pass mark in the 65-70% range. Just like the practice questions throughout this roadmap, real exam questions tend to favor scenario-based reasoning over pure recall of a control number.

Review checklist — one line per lesson

Before starting the exam below, mentally check whether you can explain each of these without looking back:

  1. Lesson 1: The difference between asset, threat, vulnerability, and risk — and the CIA triad
  2. Lesson 2: Why 27001 is certifiable but 27002/27005 are not, and clauses vs. Annex A
  3. Lesson 3: What "context" and "leadership" require concretely (clauses 4-5)
  4. Lesson 4: The risk assessment steps and the four treatment options (clause 6)
  5. Lesson 5: Competence vs. awareness, and documented information control (clauses 7-8)
  6. Lesson 6: Internal audit independence, management review inputs, correction vs. corrective action (clauses 9-10)
  7. Lesson 7: The 9 Organizational control clusters, and 5.31 vs. 5.34
  8. Lesson 8: All 8 People controls, and when SoA exclusions are legitimate
  9. Lesson 9: The shared responsibility model for Physical controls with cloud providers
  10. Lesson 10: Logging vs. monitoring, and why 8.31 (environment separation) underpins other controls
  11. Lesson 11: What makes an SoA entry defensible, and SoA vs. Risk Treatment Plan
  12. Lesson 12: Stage 1 vs. Stage 2, finding classification, and ISO/IEC 17021 accreditation
  13. Lesson 13: How a real gap analysis handles conflicting evidence and prioritizes findings

If any of these feel shaky, it's worth a quick revisit before treating your practice exam score as a reliable signal of real exam readiness.

After the exam

Your score isn't the point — where you lost points is. A single wrong answer on a topic you otherwise understand well is normal; a cluster of wrong answers concentrated in one or two lessons is a clear, actionable signal about exactly where to spend your remaining study time before attempting a real accredited exam.

Without looking back at any previous lesson, write one sentence each for: (1) the difference between a threat and a vulnerability, (2) why ISO/IEC 27002 is not itself certifiable, (3) the four risk treatment options, (4) the difference between logging and monitoring, (5) what makes an SoA entry defensible.

✦ Answer the questions to complete this task

If you struggled with more than one of these five review points, what should you do before attempting the practice exam below?

💪 Exercises & Challenges

📝 MCQ Hard +50 XP

Foundation Practice Exam — 20 Questions

Foundation Practice Exam — 20 Questions

Start →