ISO 28000 SUPPLY CHAIN SECURITY
MANAGEMENT SYSTEMS LEAD AUDITOR
CERTIFICATION PRACTICE EXAMINATION
QUESTIONS AND CORRECT ANSWERS
(VERIFIED ANSWERS) PLUS RATIONALES
2026 Q&A | INSTANT DOWNLOAD PDF
Note: These are original practice questions based on ISO 28000:2022, auditing principles, and
supply-chain security concepts. They are not leaked or confidential examination questions, and
no pass guarantee is implied. ISO 28000:2022 is the current published edition, while ISO
28000:2007 has been withdrawn.
Questions 1–40
1. What is the primary purpose of ISO 28000:2022?
A. To regulate customs duties
B. To specify requirements for a security management system
C. To replace all transport regulations
D. To certify individual security guards
Correct Answer: B
Rationale: ISO 28000 specifies requirements for establishing, implementing, maintaining, and
improving a security management system applicable to supply-chain activities.
2. Which organization is responsible for publishing ISO 28000?
,A. World Trade Organization
B. International Labour Organization
C. International Organization for Standardization
D. World Customs Organization
Correct Answer: C
Rationale: ISO develops and publishes international management-system standards.
3. Which edition is currently applicable to ISO 28000?
A. ISO 28000:1999
B. ISO 28000:2005
C. ISO 28000:2007
D. ISO 28000:2022
Correct Answer: D
Rationale: ISO 28000:2022 is the published second edition.
4. ISO 28000 can be applied to:
A. Only shipping companies
B. Only airports and seaports
C. Organizations of different sizes and sectors
D. Only government agencies
Correct Answer: C
Rationale: The standard is generic and can apply to commercial, governmental, nonprofit,
manufacturing, service, storage, and transportation organizations.
5. What is the main focus of a supply-chain security management system?
A. Increasing advertising revenue
, B. Managing security risks affecting the supply chain
C. Reducing employee salaries
D. Eliminating all business risks
Correct Answer: B
Rationale: The system addresses security threats and risks that could affect the continuity,
integrity, and reliability of supply-chain operations.
6. Which activity should be considered when determining the scope of an ISO 28000 system?
A. Only activities performed inside the head office
B. Internal and external activities that affect security
C. Only activities performed by senior management
D. Only financial activities
Correct Answer: B
Rationale: Supply-chain security may be affected by internal operations, suppliers, contractors,
transporters, customers, and other external parties.
7. What should an organization establish before implementing security controls?
A. A security risk assessment process
B. A marketing plan
C. A payroll schedule
D. A product catalogue
Correct Answer: A
Rationale: Security controls should be based on identified threats, vulnerabilities,
consequences, and risk levels.
8. A security threat is best described as:
A. A documented audit finding
MANAGEMENT SYSTEMS LEAD AUDITOR
CERTIFICATION PRACTICE EXAMINATION
QUESTIONS AND CORRECT ANSWERS
(VERIFIED ANSWERS) PLUS RATIONALES
2026 Q&A | INSTANT DOWNLOAD PDF
Note: These are original practice questions based on ISO 28000:2022, auditing principles, and
supply-chain security concepts. They are not leaked or confidential examination questions, and
no pass guarantee is implied. ISO 28000:2022 is the current published edition, while ISO
28000:2007 has been withdrawn.
Questions 1–40
1. What is the primary purpose of ISO 28000:2022?
A. To regulate customs duties
B. To specify requirements for a security management system
C. To replace all transport regulations
D. To certify individual security guards
Correct Answer: B
Rationale: ISO 28000 specifies requirements for establishing, implementing, maintaining, and
improving a security management system applicable to supply-chain activities.
2. Which organization is responsible for publishing ISO 28000?
,A. World Trade Organization
B. International Labour Organization
C. International Organization for Standardization
D. World Customs Organization
Correct Answer: C
Rationale: ISO develops and publishes international management-system standards.
3. Which edition is currently applicable to ISO 28000?
A. ISO 28000:1999
B. ISO 28000:2005
C. ISO 28000:2007
D. ISO 28000:2022
Correct Answer: D
Rationale: ISO 28000:2022 is the published second edition.
4. ISO 28000 can be applied to:
A. Only shipping companies
B. Only airports and seaports
C. Organizations of different sizes and sectors
D. Only government agencies
Correct Answer: C
Rationale: The standard is generic and can apply to commercial, governmental, nonprofit,
manufacturing, service, storage, and transportation organizations.
5. What is the main focus of a supply-chain security management system?
A. Increasing advertising revenue
, B. Managing security risks affecting the supply chain
C. Reducing employee salaries
D. Eliminating all business risks
Correct Answer: B
Rationale: The system addresses security threats and risks that could affect the continuity,
integrity, and reliability of supply-chain operations.
6. Which activity should be considered when determining the scope of an ISO 28000 system?
A. Only activities performed inside the head office
B. Internal and external activities that affect security
C. Only activities performed by senior management
D. Only financial activities
Correct Answer: B
Rationale: Supply-chain security may be affected by internal operations, suppliers, contractors,
transporters, customers, and other external parties.
7. What should an organization establish before implementing security controls?
A. A security risk assessment process
B. A marketing plan
C. A payroll schedule
D. A product catalogue
Correct Answer: A
Rationale: Security controls should be based on identified threats, vulnerabilities,
consequences, and risk levels.
8. A security threat is best described as:
A. A documented audit finding