ISO 27001 Lead Auditor Domain 4 Practice Questions: Conducting the Audit
Domain 4 is the largest domain on the CQI and IRCA ISO 27001 Lead Auditor exam: fourteen questions worth 36 of the 80 marks, with a minimum of 14. These fourteen practice questions match the real paper's count and mark split, with an explanation for every option.
Domain 4 is the largest domain on the CQI and IRCA ISO 27001 Lead Auditor exam: fourteen questions worth 36 of the 80 marks, with a minimum of 14. These fourteen practice questions match the real paper's count and mark split, with an explanation for every option.
Every question below was written for this page by 3FOLD TRAINING's tutors. None is a real CQI and IRCA examination question, and none is taken from 3FOLD TRAINING's own graded mock exams. Real exam questions cannot lawfully be published, and any site offering them is offering you something it should not have.
Why does Domain 4 decide results?
| Questions | Marks | Minimum mark | Scope | Level tested | Suggested time |
|---|---|---|---|---|---|
| 14 | 36 | 14 | Generic and scheme-specific | Apply and evaluate | 45 minutes |
Domain 4 carries more marks than Domains 1, 2 and 3 combined, which total 24. Its floor of 14 marks is the largest single block on the paper, nothing compensates for it, and a candidate above 50 per cent overall can still fail.
The values are eight 3-mark and six 2-mark questions. It is the only domain tested at two levels, apply and evaluate, and every question is built on a scenario — a described situation carrying several questions, each standing alone. The set below follows that construction: fourteen questions across four scenarios, same 8×3 and 6×2 split, 36 marks.
What does Domain 4 cover?
- The opening meeting
- Gathering evidence, following trails, corroborating what you are told
- Interviewing and observation, including remote and cloud evidence
- Auditing Clauses 4 to 10 and a risk-based sample of Annex A controls
- Forming and grading findings
How should you use this set?
Read each scenario once, then answer every question hung off it before moving on. That is how the real paper presents them, and it is a different exercise from fourteen unrelated questions. Write down the requirement and the evidence you relied on each time: a right answer reached from the wrong evidence will not survive a differently-worded question. None of them predicts what you will be asked. They test the same understanding, in the two formats that carry most of the paper, so working through them shows you where you are weak while there is still time to act on it.
Every question below carries its mark value, and here they are 2 and 3 rather than the 1 and 2 of the smaller domains. Score in marks: fourteen questions carry 36, so what you can afford to lose works out differently from anywhere else on the paper. Where a question asks for more than one answer, select exactly the number asked for: partial marks apply throughout, and nothing CQI publishes says a wrong selection is deducted from a right one.
This set is worth timing. The framework's recommended time for Domain 4 is 45 minutes, and because these are scenario questions of the same construction, the comparison means something. Running out of time here, after too long on the smaller domains, is a common and entirely avoidable way to lose marks.
Two constraints of the real paper matter more here than anywhere else. You cannot navigate backwards once you have clicked Next, so a scenario you half-decide is one you have lost. And the exam is open book: in a domain built on naming the requirement, finding a clause quickly beats memorising it. See CQI and IRCA on online exams.
The questions
Where do marks actually go in Domain 4?
Three errors, all habits.
- Grading on impression rather than evidence. Seriousness is not the test, and grading on how bad something feels goes wrong in both directions.
- Recognising a nonconformity without tying it to a requirement. Name the clause or control and the evidence; an untraceable finding falls over.
- Choosing the answer that sounds most thorough. The best answer is the one the evidence supports.
One habit earns marks across the domain. Ask of every scenario: what is the requirement, and what does the evidence show? Most questions resolve once you have both. And remember the exam is open book. A question you could have answered by opening the standard is a navigation problem, not a knowledge gap, and the fix is to practise finding things rather than memorising them.
Look at why each went wrong rather than what it was about; the fix differs.
- You could not name the requirement. A knowledge gap; reading fixes it. Work Clauses 4 to 10 and the four Annex A themes until you can place a finding without hunting for it.
- You named the requirement but graded it wrongly. Judgement, improved by working scenarios.
- You chose the most thorough-sounding option. An exam habit, the easiest to break once noticed.
Frequently asked questions
How many Domain 4 questions are on the real ISO 27001:2022 lead auditor exam?
Fourteen, worth 36 marks: eight 3-mark and six 2-mark. You need 14 of those 36.
Why is Domain 4 in ISO 27001:2022 lead auditor worth so many marks?
Because it tests what an auditor does, at apply and evaluate, from the opening meeting to grading the findings.
Are all Domain 4 in ISO 27001:2022 lead auditor questions scenario-based?
Yes. Domains 4 and 5 use scenarios only. One scenario may drive several questions, but each stands alone, so you never need an earlier answer.
Can I make up a weak Domain 4 in ISO 27001:2022 lead auditor elsewhere?
No. Every domain has its own minimum; Domain 4's is 14 of 36, and missing it fails the paper.
Where to go next
The Domain 5 set — reporting and closing out, eight questions and 20 marks — follows separately. How the ISO 27001 Lead Auditor exam pass mark works explains why one weak domain fails an otherwise comfortable paper, and the five exam domains sets out what each asks.
- Domain 1 practice questions — concepts and principles, 6 questions, 8 marks.
- Domain 2 practice questions — audit concepts and auditor responsibilities, 6 questions, 8 marks.
- Domain 3 practice questions — planning the audit, 6 questions, 8 marks.
- The sample exam questions and answers — ten questions weighted across all five domains, if you want a spread rather than a domain.
3FOLD TRAINING is a CQI and IRCA Approved Training Partner, ATP number 6039853. Its ISO 27001 Lead Auditor training course is the CQI and IRCA Certified ISO/IEC 27001:2022 ISMS Lead Auditor (PR373). The course identification number is 2889. Both the partner approval and the course certification are on 3FOLD TRAINING's Approved Training Partner record, and any provider's certified courses can be looked up in CQI and IRCA's own directory of certified courses and approved training partners. The ISO 27001 Lead Auditor training course page carries the schedule and what the course includes. If you would rather ask a person first, use the course enquiry form.
Booking a PR373 course? See the schedule, trainers and what's included.
View the course





Leave a Reply
Your email is safe with us.