ISO 27001 Lead Auditor Domain 1 Practice Questions: Concepts and Principles
Domain 1 of the CQI and IRCA ISO 27001 Lead Auditor exam is six questions worth eight marks, with a minimum of three. Six original practice questions matching that count, with a full explanation for every option.
Domain 1 of the CQI and IRCA ISO 27001 Lead Auditor exam is six questions worth eight marks, with a minimum of three. These six practice questions match that count and test the same understanding, with a full explanation for every option.
Every question below was written for this page by 3FOLD TRAINING's tutors. None is a real CQI and IRCA examination question, and none is taken from 3FOLD TRAINING's own graded mock exams. Real exam questions cannot lawfully be published, and any site offering them is offering you something it should not have.
What does Domain 1 cover, and how hard is it?
Domain 1 is concepts and principles of management standards and systems. It covers what a management system is and why an organisation runs an ISMS, what confidentiality, integrity and availability mean in practice, how the standard is put together, and what certification is for.
| Questions | Marks | Minimum mark | Level tested | Suggested time |
|---|---|---|---|---|
| 6 | 8 | 3 | Understand | 10 minutes |
Two things follow from that table. It is the shallowest domain on the paper — the only one set at understand rather than apply or evaluate — and it is one of the smallest, at 8 of the 80 marks. It is also the domain candidates over-prepare, because it is the most comfortable to revise.
Question values are fixed: two 2-mark questions and four 1-mark questions. Situations may be used, tied to a single question. Scenarios are not used in this domain. How the five domains differ sets out the rest.
How should you use this set?
This is the one set where the fix for a wrong answer is reading. Domain 1 is tested at understand and nothing else on the paper is, so a question that goes wrong here is almost always a definition or a structure that is not yet solid rather than judgement. Go back to the clause, not to more questions.
None of them predicts what you will be asked. They test the same understanding, in the two formats that carry most of the paper, so working through them shows you where you are weak while there is still time to act on it.
Every question below carries its mark value, and here the values are 1 and 2. With only eight marks available, one 2-mark question is a quarter of the domain, so score in marks rather than in questions right. Where a question asks for more than one answer, select exactly the number asked for: partial marks are given on all questions, and nothing CQI publishes says a wrong selection is deducted from a right one.
Two things about the real paper are worth carrying into this set. You cannot navigate backwards once you have clicked Next. And the exam is open book, which matters most in this domain: a definition you can find in thirty seconds is not the same problem as one you cannot place at all. See CQI and IRCA on online exams.
Two of the six carry two marks on the real paper and four carry one, so do not treat them as equally weighted when you review your answers. And remember the exam is open book: a question you could have answered by opening the standard is not really a knowledge gap, it is a navigation one.
The questions
Where do marks actually go in Domain 1?
Two misunderstandings account for most of them, and both travel with you into later domains.
- Treating Annex A as a mandatory checklist. It is a reference set, and what belongs in a given ISMS is decided by risk. This error costs marks here and does far more damage in Domain 4.
- Treating information security as secrecy. Situations are written so that more than one property may be affected, and a reader who is only watching for disclosure will read past the other two.
Domain 1 is the one domain where reading fixes the problem, because it is the one domain that tests understanding rather than judgement. If several went wrong, work through the clause structure and the four Annex A themes until you can sketch them without looking, then come back.
If you found them easy, move on to questions that challenge you in different ways. 36 of the 80 marks come from a domain that requires a different kind of thinking altogether.
Frequently asked questions
How many Domain 1 questions are on the real ISO 27001:2022 lead auditor exam?
Six, worth eight marks in total — two 2-mark questions and four 1-mark questions. You need at least three of those eight marks.
Is Domain 1 in the ISO 27001:2022 lead auditor easiest domain?
It is the shallowest, because it is the only domain set at the understand level. It is not free marks, and it is small: eight of the eighty marks on the paper.
Does Domain 1 in the ISO 27001:2022 lead auditor use scenarios?
No. Domains 1 to 3 may use short situations tied to a single question. Only Domains 4 and 5 use scenarios.
Do I need to memorise all 93 Annex A controls in ISO 27001?
No. You need to understand that Annex A is a reference set of 93 controls in four themes, selected on the basis of risk and recorded in the Statement of Applicability. The exam is open book.
Where to go next
Eight marks is eight marks, but a comfortable Domain 1 should not lead you to focus only on the same type of questions. The other sets are where the paper is decided:
- Domain 2 practice questions — audit concepts and auditor responsibilities, 6 questions, 8 marks.
- Domain 3 practice questions — planning the audit, 6 questions, 8 marks.
- Domain 4 practice questions — conducting the audit, 14 scenario questions, 36 marks.
- The sample exam questions and answers — ten questions weighted across all five domains, if you want a spread rather than a domain.
The complete CQI IRCA ISO 27001 Lead Auditor exam guide covers the format, the timing and how the sitting itself works.
3FOLD TRAINING is a CQI and IRCA Approved Training Partner, ATP number 6039853. Its ISO 27001 Lead Auditor training course is the CQI and IRCA Certified ISO/IEC 27001:2022 ISMS Lead Auditor (PR373). The course identification number is 2889. Both the partner approval and the course certification are on 3FOLD TRAINING's Approved Training Partner record, and any provider's certified courses can be looked up in CQI and IRCA's own directory of certified courses and approved training partners. The ISO 27001 Lead Auditor training course page carries the schedule and what the course includes. If you would rather ask a person first, use the course enquiry form.
Booking a PR373 course? See the schedule, trainers and what's included.
View the course






Leave a Reply
Your email is safe with us.