60 practice questions for PECB ISO/IEC 27005 Risk Manager, with full explanations.
Every question comes with the correct answer, the reasoning behind it, and a short note on why each distractor is wrong. The set is mapped to the published exam objectives across all four competency domains.
- 60 questions across all four ISO/IEC 27005 Risk Manager domains
- Answers and explanations for every question, including the wrong options
- A questions-only PDF for timed practice runs
- Instant delivery by email the moment you check out
- Free monthly updates for as long as the exam is live
- Pass or your money back
PECB does not publish a standalone exam price: the exam is bundled into the accredited training course, which each PECB partner prices itself, so a failed attempt means a retake fee on top. This pack is US$39, paid once, and refunded if you fail.
Try 10 questions free before you buy.
Last updated September 2026 · 60 questions
What makes the ISO/IEC 27005 Risk Manager hard
Almost half the marks come from the domain people skim. Domain 1, the fundamental principles and concepts of information security risk management, carries 44% of the points. The ISO/IEC 27005 framework and process itself is 30%, implementing a risk management programme 16%, and alternative assessment methods 10%.
Candidates who jump straight to memorising the process steps lose marks on the vocabulary underneath. The traps are terms that sound interchangeable but are not: risk identification and risk analysis, likelihood and consequence, risk criteria and acceptance criteria, residual risk and accepted risk.
ISO/IEC 27005:2022 also moved to event-based and asset-based approaches to identifying risk, so older study material describes a process that no longer matches the standard. The exam is open book, with three options per question: one right answer and two distractors.
About the exam
The ISO/IEC 27005 Risk Manager is PECB’s certification for professionals who establish and run an information security risk management process based on ISO/IEC 27005. It is the natural companion to ISO/IEC 27001, which requires a risk assessment and risk treatment process but does not say how to build one.
Exam domains
- Domain 1: Fundamental principles and concepts of information security risk management: 44%
- Domain 2: Implementation of an information security risk management program: 16%
- Domain 3: Information security risk management framework and process based on ISO/IEC 27005: 30%
- Domain 4: Other information security risk assessment methods: 10%
Multiple choice with three options per question, open book, pass mark 70%. There is no standalone exam price: the exam, the certification application and the first year of the annual maintenance fee are bundled into the three-day accredited training course, which carries 21 CPD credits and is priced by each PECB partner.








Reviews
There are no reviews yet.