← GoToCertify
ISO/IEC 27001 · APMG · Practitioner

The ISO/IEC 27001 Practitioner exam format, explained

Four questions. Eighty marks. Two and a half hours. Restricted open book, forty marks to pass. If that sounds unlike every other exam on this site, it is — and the shape tells you exactly what is being tested.

4Questions
80Marks available
150 minTime limit
40 / 80Pass mark

The exam on paper

The APMG ISO/IEC 27001 Practitioner certificate — Information Security Officer — tests whether you can apply the standard to manage information security, not whether you can describe it.

Questions4 objective-testing questions, worth 80 marks in total
Duration150 minutes
Pass mark50% — 40 marks out of 80
MaterialsRestricted open book
PrerequisitesNone stated
Accredited trainingNot mandatory. Self-study and direct exam booking are supported
Typical courseTwo days, where a course is taken

Twenty marks a question, thirty-seven minutes each

The arithmetic of this paper is unlike anything else in the families we cover.

Questions4
Marks per question20
Time per questionAbout 37 minutes 30 seconds
Marks to pass40 — the equivalent of two questions answered perfectly
Marks you can drop40

Each question is a substantial piece of work built around a scenario, with parts that are marked individually. There is no recall element to speak of and no time pressure in the ordinary sense: thirty-seven minutes is a long time to sit with one problem.

The risk is the opposite of the usual one. On a fast paper you run out of clock; here you run out of discipline, and write around the question instead of answering it.

What "Information Security Officer" means for the questions

APMG frames this level as applying ISO/IEC 27001 to enable the management of information security — the officer’s job rather than the auditor’s.

Practically, that moves the questions from “does this comply” to “what would you do”: scoping an ISMS, deciding what belongs in a Statement of Applicability, treating a risk, planning what management review should look at. The standard supplies the frame; the decision is yours, and the marks are for the decision and the reasoning behind it.

It is the same distinction that separates the Auditor certificate from this one. An auditor judges a system that exists. An officer builds and runs one.

Restricted open book, with a lot of time to use it

You may consult the permitted materials, and with thirty-seven minutes a question you actually can — this is the one exam here where looking something up properly is affordable.

Use that. On a four-question paper, one misremembered requirement can cost a large share of twenty marks, and you have the time to check rather than guess. Confirm what the standard requires before you build an answer on top of it.

What this means for how you prepare

Practise writing full answers, not recognising right ones. This is not a multiple-choice paper in any meaningful sense.

Budget by question. Thirty-seven minutes each, and hold the line — overrunning on question one is how people lose question four.

Answer the question asked. Forty of the eighty marks are yours to lose, and they are most often lost to answers that are about the right topic but not about the question.

Questions people ask

How many questions are in the ISO/IEC 27001 Practitioner exam?

Four, worth eighty marks in total.

What is the pass mark?

Forty marks out of eighty — 50%.

How long is the exam?

Two and a half hours, which is about thirty-seven minutes per question.

Is it open book?

Restricted open book — the permitted materials only.

Do I need the Foundation certificate first?

APMG does not state it as a prerequisite, though most providers sequence the levels that way.

How is this different from the Auditor certificate?

The Auditor level judges a system against the standard. The Practitioner level designs and manages one — the information security officer’s role.

Sources. Every figure on this page comes from APMG International’s own published certification pages, checked in September 2026.

Four questions, and no hiding behind the ones you know

GoToCertify will offer preparation for the ISO/IEC 27001 certifications, with the exam voucher alongside it.

Not on sale on GoToCertify yet — we are setting it up. In the meantime the exam facts above are free to use.

APMG International Accredited Training Organization for ISO/IEC 27001

BITIL.COM is an ATO (Accredited Training Organization) of APMG-International for ISO/IEC 27001® courses.

PrivacyTermsVerify