ISO 27001 Lead Auditor Domain 2 Practice Questions: Audit Concepts and Responsibilities
Domain 2 of the CQI and IRCA ISO 27001 Lead Auditor exam is six questions worth eight marks, with a minimum of three. Six original practice questions matching that count, with an explanation for every option.
Domain 2 of the CQI and IRCA ISO 27001 Lead Auditor exam is six questions worth eight marks, with a minimum of three. It is the only fully generic domain on the paper. These six practice questions match that count, with an explanation for every option.
Every question below was written for this page by 3FOLD TRAINING's tutors. None is a real CQI and IRCA examination question, and none is taken from 3FOLD TRAINING's own graded mock exams. Real exam questions cannot lawfully be published, and any site offering them is offering you something it should not have.
What makes Domain 2 different?
Domain 2 is audit concepts and auditor responsibilities. It covers the principles of auditing, the stages of an audit, and the difference between first-, second- and third-party audits. It also covers who does what on an audit team, and the impartiality and confidentiality obligations that make an audit valid.
| Questions | Marks | Minimum mark | Scope | Level tested | Suggested time |
|---|---|---|---|---|---|
| 6 | 8 | 3 | Generic | Apply | 10 minutes |
This is the only wholly generic domain on the paper. Nothing in it is specific to information security — it is the general management-system auditing discipline, and it would look the same on a quality or environmental paper. Domains 3 and 5 are wholly scheme-specific; Domains 1 and 4 mix the two.
There is a practical consequence. If you already hold a lead auditor qualification in another scheme, this is the domain you have covered before. It is also why the Auditor Conversion exam removes Domain 2 entirely, running to 34 questions and 72 marks rather than 40 and 80.
Note the level. Domain 2 is set at apply, not understand: listing the seven principles is not what earns the marks, recognising which one a situation engages is.
How should you use this set?
Answer these once quickly, then a second time asking a different question of each: which principle, which stage, or which role is this actually about? Domain 2 is a small vocabulary applied to situations, and the candidates who lose marks here can usually recite the list but cannot spot it in a paragraph. The second pass is where that gap closes. None of them predicts what you will be asked. They test the same understanding, in the two formats that carry most of the paper, so working through them shows you where you are weak while there is still time to act on it.
Every question below carries its mark value, and here the values are 1 and 2. With only eight marks available, one 2-mark question is a quarter of the domain, so score in marks rather than in questions right. Where a question asks for more than one answer, select exactly the number asked for: partial marks are given on all questions, and nothing CQI publishes says a wrong selection is deducted from a right one.
Remember that the real exam does not allow you to go back: once you click “Next,” your answer is final. Domain 2 questions are generally short, so it is important to practise making a clear decision and moving forward rather than leaving a question to revisit later. On exam day, going back is not an option, so build this habit into your practice sessions.. See CQI and IRCA on online exams.
One point of technique for this domain. Because the content is generic, the wrong options are often generically sensible — things a reasonable person might do. Ask which option the audit principles actually require, not which one sounds most cooperative.
The questions
Where do marks actually go in Domain 2?
Three places, consistently:
- Confusing the audit client with the audit team leader. Two parties, two sets of responsibilities, and options written to reward anyone who can say which is which.
- Treating a guide as a source of evidence. A guide arranges access and finds people; they are not someone you audit through, and the distinction is examined in situations rather than defined.
- Picking the principle you remember rather than the one engaged. All seven sound plausible; read what the situation turns on.
Domain 2 rewards a small amount of precise learning. Get the seven principles, the five stages and the audit roles straight — the technical expert included, who supports the team but does not audit — then practise recognising them in situations rather than reciting. That is the domain.
Watch for distractors that sound like principles but are not on the list. Anything describing a commercial outcome, an administrative habit or a desirable trait of the auditee belongs to a different question. If you cannot place a term in the seven, it is not one of them.
Frequently asked questions
How many Domain 2 questions are on the real ISO 27001:2022 lead auditor exam?
Six, worth eight marks — two 2-mark questions and four 1-mark questions. You need at least three of those eight marks.
Why is Domain 2 removed from the Auditor Conversion exam?
Because it covers generic auditing requirements a converting auditor has already been assessed on. The conversion paper is 34 questions and 72 marks in 1 hour 35 minutes, with a 36-mark pass.
Is Domain 2 the same on every CQI and IRCA lead auditor exam?
The content is generic rather than scheme-specific, so the discipline is the same. The questions are set for each scheme's own paper.
How many principles of auditing are there?
Seven: integrity, fair presentation, due professional care, confidentiality, independence, the evidence-based approach and the risk-based approach.
Where to go next
Domain 2 is generic auditing. The next two apply it to an ISMS, which is different work:
- Domain 1 practice questions — concepts and principles, 6 questions, 8 marks.
- Domain 3 practice questions — planning the audit, 6 questions, 8 marks.
- Domain 4 practice questions — conducting the audit, 14 scenario questions, 36 marks.
- The sample exam questions and answers — ten questions weighted across all five domains, if you want a spread rather than a domain.
The complete CQI IRCA ISO 27001 Lead Auditor exam guide covers the format, the timing and how the sitting itself works.
3FOLD TRAINING is a CQI and IRCA Approved Training Partner, ATP number 6039853. Its ISO 27001 Lead Auditor training course is the CQI and IRCA Certified ISO/IEC 27001:2022 ISMS Lead Auditor (PR373). The course identification number is 2889. Both the partner approval and the course certification are on 3FOLD TRAINING's Approved Training Partner record, and any provider's certified courses can be looked up in CQI and IRCA's own directory of certified courses and approved training partners. The ISO 27001 Lead Auditor training course page carries the schedule and what the course includes. If you would rather ask a person first, use the course enquiry form.
Booking a PR373 course? See the schedule, trainers and what's included.
View the course





Leave a Reply
Your email is safe with us.