Study the ISO/IEC 27001 Information Security Management (ISO 27001) standard published by ISO with free practice questions on CyberCertPrep. Our ISO 27001 knowledge check is 80 questions in 2 hours with a 70% target score. There is no single ISO 27001 exam for us to mirror, so those three figures are ours, not a vendor blueprint.
Choose from Practice mode, Knowledge Check, Weak Areas review, and Daily Challenge. Track your progress with detailed analytics and study with flashcards.
ISO/IEC 27001 Information Security Management (ISO 27001) Exam Domain
Focus your study on this domain with targeted practice questions. This domain accounts for 20% of your ISO 27001 exam score.
The ISMS Planning & Context domain is one of 5 exam domains on the ISO/IEC 27001 Information Security Management (ISO 27001) certification exam by ISO. At 20% of the total exam, this is one of the most heavily weighted domains, mastering it is critical for passing.
The ISO 27001 exam consists of 80 questions with a time limit of 2 hours and a passing score of 70%. That means approximately 16 questions on your exam will come from the ISMS Planning & Context domain.
Penetration Testing
An authorized simulated cyberattack on a computer system, network, or application performed to evaluate its security pos...
ISO 27001
An international standard for information security management systems (ISMS) that specifies requirements for establishin...
Business Continuity Plan (BCP)
A plan that outlines procedures and instructions for maintaining essential business functions during and after a disaste...
Serverless Security
Security practices for Function-as-a-Service (FaaS) platforms like AWS Lambda, Azure Functions, and Google Cloud Functio...
Retrieval-Augmented Generation (RAG)
An architecture that grounds an LLM's responses in an external knowledge base by retrieving relevant documents at query ...
CVSS
The Common Vulnerability Scoring System, an open framework that produces a 0.0-10.0 severity score from characteristics ...
NIST AI Risk Management Framework
A voluntary framework, published as NIST AI 100-1, for managing risks across the AI lifecycle, organised into four funct...
Indirect Prompt Injection
An attack in which malicious instructions reach a model through content it consumes rather than through the user's own p...
These certifications also cover topics related to ISMS Planning & Context: