ISO 27001 Lead Auditor Exam: 80 Questions, Open Book, 70% to Pass — and What Actually Trips Candidates

The PECB ISO/IEC 27001 Lead Auditor certification proves you can plan, conduct and close an audit of an Information Security Management System (ISMS) against the standard. The exam has a reputation for being approachable — it is open-book, multiple-choice, and needs 70% — and that reputation is exactly what fails people. Open-book removes the memory test so the paper can spend all 80 questions on judgement.

This guide covers the format as PECB publishes it, the seven competency domains with their weights, the one distinction the exam keeps returning to, and a preparation sequence that fits the paper you will actually sit.

Exam format at a glance

If a study guide quotes you a precise exam length, it did not get it from PECB's candidate handbook. Treat the rest of that guide with the same caution.

Three options, not four

Most people arrive at this exam from the ISACA world, where every question has four options. This paper has three. That is not a cosmetic difference.

With three options, eliminating one distractor leaves you a coin flip rather than a one-in-three guess, so elimination pays less and recognising the correct answer outright pays more. Practice material written for four-option questions trains a different reflex: it teaches you to discard two weak distractors and choose between the survivors. On this paper there is only ever one weak distractor to discard, and the remaining wrong option is usually a plausible auditor action that is simply the wrong one for the situation described.

Practise on three-option questions or you are rehearsing for a different exam.

The seven competency domains, weighted

PECB publishes the domains and the share of the paper each carries. With 80 questions, the weights translate into a rough question count:

# Domain Weight ≈ Questions
1 Fundamental principles and concepts of an ISMS 16.25% 13
2 ISMS and ISO/IEC 27001 requirements 10% 8
3 Fundamental audit concepts and principles 17.5% 14
4 Preparing an ISO/IEC 27001 audit 15% 12
5 Conducting an ISO/IEC 27001 audit 22.5% 18
6 Closing an ISO/IEC 27001 audit 8.75% 7
7 Managing an ISO/IEC 27001 audit program 10% 8

Two things jump out of that table.

First, conducting the audit is nearly a quarter of the paper on its own, and together with preparing and closing, the fieldwork lifecycle (domains 4 to 6) is almost half the exam. Candidates who spend their revision on the standard's clauses are preparing for domain 2, which is eight questions.

Second, domain 3 outweighs domain 2. The exam cares more about what makes evidence sufficient and appropriate, what independence means in practice, and the difference between a finding and an opinion than it does about reciting clause numbers. You need the clauses — every finding is ultimately argued against one — but they are the reference, not the subject.

What each domain is really testing:

  1. Fundamental principles and concepts of an ISMS — the vocabulary you must share with the auditee: confidentiality, integrity and availability, how threat, vulnerability and risk relate, and how a management system works as a system rather than a pile of controls.
  2. ISMS and ISO/IEC 27001 requirements — clauses 4 to 10, the Statement of Applicability, and how Annex A controls relate to the risk treatment plan.
  3. Fundamental audit concepts and principles — independence, evidence, sampling, and the professional scepticism the exam expects you to apply rather than describe.
  4. Preparing an ISO/IEC 27001 audit — scope and objectives, document review, the audit plan and checklists, team allocation, and judging whether the auditee is ready for a stage 2 audit at all.
  5. Conducting an ISO/IEC 27001 audit — interviews and observation, following audit trails, classifying nonconformities by severity, and deciding what further evidence a conclusion needs before it can be defended.
  6. Closing an ISO/IEC 27001 audit — the closing meeting, the audit report, evaluating corrective action plans, and judging whether a nonconformity has genuinely been addressed rather than merely answered.
  7. Managing an ISO/IEC 27001 audit program — the view above any single engagement: designing and monitoring an audit programme, auditor competence and evaluation, and improving the programme itself.

The distinction the exam keeps testing

Across domains 3, 5 and 6 the same question keeps coming back in different clothes: is this evidence, or is it an assertion?

An auditee tells you the backups are tested quarterly. That is a claim. A backup test log with dates and outcomes is evidence. A restore you watched happen is stronger evidence. The exam repeatedly presents a scenario where an auditor has a claim and asks what they should do next, and the plausible wrong answer is almost always "raise a nonconformity" or "accept the explanation" when the correct answer is "obtain the evidence that would settle it".

The same shape appears at the close of the audit. A corrective action plan that says the root cause was addressed is not the same as evidence that it was. Candidates who treat the auditee's response as the end of the matter lose marks in domain 6 that they could have banked.

"Open-book" is a time trap

You may bring a hard copy of the standard and your course materials. Notice what that list does not include: a bank of answered scenarios.

You can look up what clause 9.2 requires of an internal audit programme. You cannot look up whether the programme described in this scenario meets it, and the second question is the only kind the exam asks. Candidates who plan to "find it in the standard" spend the paper flipping pages and run out of time on the scenario sets, where five questions hang on one careful reading.

Use the book for what it is good for: confirming a clause reference you already know is relevant, quickly, from a tabbed and annotated copy you have handled for weeks. If you are opening the standard to discover which clause applies, you are already behind.

Passing the exam is not the same as being certified

This catches people every session. There is no prerequisite to sit the exam, but the credential you receive afterwards depends on the experience you can evidence:

Credential Total experience In information security management Audit hours
Provisional Auditor None None None
Auditor 2 years 1 year 200
Lead Auditor 5 years 2 years 300
Senior Lead Auditor 10 years 7 years 1,000

All four also require signing the PECB Code of Ethics. So you can pass with no experience at all and hold the Provisional credential until your hours catch up. Confirm the current thresholds with PECB before deciding which credential you are working toward.

Lead Auditor or Lead Implementer?

They are separate exams with different competency domains, and the honest test is what you will actually do:

Both are open-book, both pass at 70%, and neither requires a prior credential. If you are still deciding, the ISO 27001 certifications overview sets the two side by side, and the Lead Implementer exam guide covers that paper's very different question format.

A four-week preparation sequence

If you have the training course behind you, four focused weeks is a realistic runway.

Week 1 — Build the book you will take in. Work through clauses 4 to 10 with the standard open. Tab every clause, annotate the margins with what an auditor would ask for as evidence of each requirement. The goal is navigation speed and an evidence mindset, not memorisation.

Week 2 — Domains 1 to 3. Fundamentals, requirements, audit principles. For every requirement, practise naming the evidence that would satisfy it and the evidence that would not. This is the week that pays off in every scenario later.

Week 3 — Domains 4 to 7. Preparing, conducting, closing and managing the audit. Work scenario sets — five questions on one situation — not flashcards. Practise classifying nonconformities by severity and writing the one-sentence finding that ties an observation to a clause.

Week 4 — Full-length timed practice. Sit complete 80-question papers with three-option questions and scenario blocks, against a clock you set yourself. Then review every question you got right for the wrong reason — those are the ones that will fail you on a differently worded stem.

Track readiness per domain rather than as one overall percentage. A 72% average can hide a 50% in conducting the audit, and that domain is eighteen questions.

How CertPrepX helps

CertPrepX has 1,000 ISO/IEC 27001 Lead Auditor practice questions and 574 flashcards across all seven competency domains, including 16 complete scenario blocks that mirror the five-questions-per-scenario format of the real exam. Every question uses three options, like the paper, and carries a worked explanation of why the correct answer is correct and why each distractor is not. Mock exams are scored as a percentage against the 70% pass mark, and your readiness is tracked per domain — so you can see whether it is preparing, conducting or closing the audit that would fail you.

See the full ISO 27001 Lead Auditor exam prep guide, or start free practice.

Sources

Every exam fact on this page was read from PECB's own product page, candidate handbook and published rules — including the absence of a published exam duration. Last verified 21 August 2026.

Frequently asked questions

How many questions are on the ISO 27001 Lead Auditor exam? Eighty multiple-choice questions, combining standalone questions with scenario-based sets in which one scenario is followed by five related questions.

What is the passing score? 70%.

Is the ISO 27001 Lead Auditor exam open book? Yes. You may bring a hard copy of the ISO/IEC 27001 standard and your training course materials. It tests how you apply audit judgement to a scenario, not what you can recall, so the book helps less than candidates expect.

How many answer options does each question have? Three: one correct response and two distractors. That differs from most ISACA exams, which use four, so practice written for four options does not reflect this paper.

How long is the exam? PECB does not publish a fixed duration for this exam. If you sit a Lead-level exam in a language that is not your native one, you are granted an extra 30 minutes.

Which domain carries the most marks? Conducting an ISO/IEC 27001 audit, at 22.5% — roughly eighteen of the eighty questions.

Can I sit the exam without experience? Yes. Experience determines which of the four credentials you receive afterwards, not whether you can take the paper.

What happens if I fail? There is no limit on the number of attempts, though PECB applies waiting periods between them.

Know exactly when you're ready to pass

Adaptive practice, full-length mock exams, and a readiness score for CISA, CISM, CISSP, PMP, ISO 27001 and AAIA.

Start free practice

Related exam guide

More from the blog