Foundation Practice Exam
A comprehensive review and 20-question practice exam covering everything from lessons 1-13 — ISMS fundamentals, all clauses, all 93 Annex A controls, the SoA, and the certification process.
Learning Objectives
- → Recall key concepts across all 13 preceding Foundation lessons under exam-like conditions
- → Apply the same reasoning-over-memorization approach real Foundation exams test
- → Self-assess readiness for an accredited Foundation-level exam
- → Identify which specific lessons to revisit based on missed questions
This is the capstone of the Foundation tier — a comprehensive review and a 20-question practice exam spanning every lesson so far. Treat it like the real thing: work through it without re-opening previous lessons first, then use your results to target your review.
What a real Foundation-level exam typically looks like
Accredited bodies (PECB, BSI, IBITGQ, and others) each run their own exam, and formats vary — always check the specific body's current exam guide rather than assuming. That said, most Foundation-level ISO/IEC 27001 exams share some general characteristics: multiple-choice format, a time limit of roughly an hour, and a pass mark in the 65-70% range. Just like the practice questions throughout this roadmap, real exam questions tend to favor scenario-based reasoning over pure recall of a control number.
Review checklist — one line per lesson
Before starting the exam below, mentally check whether you can explain each of these without looking back:
- Lesson 1: The difference between asset, threat, vulnerability, and risk — and the CIA triad
- Lesson 2: Why 27001 is certifiable but 27002/27005 are not, and clauses vs. Annex A
- Lesson 3: What "context" and "leadership" require concretely (clauses 4-5)
- Lesson 4: The risk assessment steps and the four treatment options (clause 6)
- Lesson 5: Competence vs. awareness, and documented information control (clauses 7-8)
- Lesson 6: Internal audit independence, management review inputs, correction vs. corrective action (clauses 9-10)
- Lesson 7: The 9 Organizational control clusters, and 5.31 vs. 5.34
- Lesson 8: All 8 People controls, and when SoA exclusions are legitimate
- Lesson 9: The shared responsibility model for Physical controls with cloud providers
- Lesson 10: Logging vs. monitoring, and why 8.31 (environment separation) underpins other controls
- Lesson 11: What makes an SoA entry defensible, and SoA vs. Risk Treatment Plan
- Lesson 12: Stage 1 vs. Stage 2, finding classification, and ISO/IEC 17021 accreditation
- Lesson 13: How a real gap analysis handles conflicting evidence and prioritizes findings
If any of these feel shaky, it's worth a quick revisit before treating your practice exam score as a reliable signal of real exam readiness.
After the exam
Your score isn't the point — where you lost points is. A single wrong answer on a topic you otherwise understand well is normal; a cluster of wrong answers concentrated in one or two lessons is a clear, actionable signal about exactly where to spend your remaining study time before attempting a real accredited exam.
Without looking back at any previous lesson, write one sentence each for: (1) the difference between a threat and a vulnerability, (2) why ISO/IEC 27002 is not itself certifiable, (3) the four risk treatment options, (4) the difference between logging and monitoring, (5) what makes an SoA entry defensible.
If you struggled with more than one of these five review points, what should you do before attempting the practice exam below?
💪 Exercises & Challenges
Foundation Practice Exam — 20 Questions
Foundation Practice Exam — 20 Questions