Study the ISO/IEC 27001 Information Security Management (ISO 27001) standard published by ISO with free practice questions on CyberCertPrep. Our ISO 27001 knowledge check is 80 questions in 2 hours with a 70% target score. There is no single ISO 27001 exam for us to mirror, so those three figures are ours, not a vendor blueprint.
Choose from Practice mode, Knowledge Check, Weak Areas review, and Daily Challenge. Track your progress with detailed analytics and study with flashcards.
ISO/IEC 27001 Information Security Management (ISO 27001) Exam Domain
Focus your study on this domain with targeted practice questions. This domain accounts for 25% of your ISO 27001 exam score.
The Risk Assessment & Treatment domain is one of 5 exam domains on the ISO/IEC 27001 Information Security Management (ISO 27001) certification exam by ISO. At 25% of the total exam, this is one of the most heavily weighted domains, mastering it is critical for passing.
The ISO 27001 exam consists of 80 questions with a time limit of 2 hours and a passing score of 70%. That means approximately 20 questions on your exam will come from the Risk Assessment & Treatment domain.
Multi-Factor Authentication (MFA)
A security mechanism that requires two or more independent credentials to verify a user's identity, combining factors fr...
Zero-Day Exploit
An attack that targets a previously unknown vulnerability in software, hardware, or firmware before the vendor has relea...
Risk Assessment
The process of identifying, analyzing, and evaluating potential risks to an organization's information assets to determi...
Vulnerability Assessment
A systematic process to identify, quantify, and prioritize security vulnerabilities in systems, applications, and networ...
Penetration Testing
An authorized simulated cyberattack on a computer system, network, or application performed to evaluate its security pos...
Compliance
The act of conforming to established guidelines, specifications, regulations, or legislation related to information secu...
NIST Framework
A set of guidelines and best practices published by the National Institute of Standards and Technology to manage cyberse...
ISO 27001
An international standard for information security management systems (ISMS) that specifies requirements for establishin...
These certifications also cover topics related to Risk Assessment & Treatment:
Risk Identification, Monitoring and Analysis, 15% of exam
Governance, Risk & Compliance, 20% of exam
Security & Risk Management, 16% of exam
Information Security Risk Management, 20% of exam
IT Risk Assessment, 20% of exam
Privacy Risk Management and Compliance, 18% of exam