- The Number: 70% on 100 Questions
- What 70% Actually Means in Practice
- What Is and Isn't Publicly Confirmed
- Format and Delivery Through the Mile2 LMS
- Where the Points Come From: Eight Preparation Modules
- Turning 70% Into a Practice Target
- A Module-Driven Preparation Sequence
- After You Pass: Validity and Renewal
- Frequently Asked Questions
- The Lead Auditor exam has 100 multiple-choice questions and a minimum passing grade of 70%.
- Testing runs online through the Mile2 Learning Management System, with roughly two hours allotted.
- Official domain weights, the scored/unscored split and the candidate pass rate are not publicly disclosed.
- Eight unweighted course modules define your preparation scope, anchored to ISO/IEC 27001:2022.
The Number: 70% on 100 Questions
If you are preparing for the Certified Information Security Management Systems: Lead Auditor exam (the C)ISMS-LA, issued by Mile2), the headline figure is straightforward: the issuer's outline states a minimum passing grade of 70%. The exam consists of 100 multiple-choice questions and runs for approximately two hours.
That is the complete set of numerical specifications confirmed in the reviewed official materials. Everything else candidates often want to know, such as how many questions are scored, whether the passing line is adjusted between exam forms, or what share of candidates clear it, is simply not stated publicly. This article separates what is confirmed from what is not, so you can plan around real information rather than forum folklore.
For a broader view of how the credential is structured, see our overview of what the C)ISMS certification is, and for the difficulty side of the equation, read How Hard Is the C)ISMS Exam?
What 70% Actually Means in Practice
On a 100-question exam, 70% translates to 70 correct answers if every item counts toward your score. That is the clean arithmetic, and it is the safest planning assumption. However, the issuer's materials do not say whether all 100 questions are scored or whether some are unscored pretest items. If a portion of the exam is unscored, the raw number of correct answers needed could differ from 70, and you would have no way of knowing which questions were which during the sitting.
| Scenario | Interpretation | Practical Takeaway |
|---|---|---|
| All 100 questions scored | 70 correct answers needed | Plan for a margin above 70 to absorb careless misses |
| Some questions unscored | Threshold applies to scored items only | Treat every question as if it counts; you cannot tell the difference |
| Split unstated (current reality) | Not verifiable from public materials | Build readiness well above the minimum rather than targeting it exactly |
What Is and Isn't Publicly Confirmed
Many sites blur the line between confirmed specifications and guesswork. For the Lead Auditor exam, here is an honest accounting based on the issuer's current-linked materials.
Confirmed
- 100 multiple-choice questions
- Approximately two hours
- Minimum passing grade of 70%
- Delivery through the Mile2 Learning Management System (online)
- Course content referencing ISO/IEC 27001:2022
- Course purchase is not required to buy the certification exam, per the issuer's FAQ
Not Verified or Not Disclosed
- Official weighted exam domains and which domain carries the highest weight
- The scored versus unscored question split
- The candidate pass rate (see our discussion in C)ISMS Pass Rate 2026: What the Data Shows)
- Whether the exam is open-book, whether calculators are permitted, whether it is adaptive, and what proctoring conditions apply
- The current exam-only fee and any member/nonmember price difference (our C)ISMS certification cost breakdown covers what can and cannot be stated)
- A formal 2026-specific exam version
One more caution: the combined Lead Auditor/Lead Implementer web presence does not establish that the Lead Implementer exam shares these specifications. The numbers in this article apply to the Lead Auditor exam only. If you are considering the Lead Implementer track, confirm its specifications directly with the issuer before assuming anything carries over.
Format and Delivery Through the Mile2 LMS
The exam is administered online through the Mile2 Learning Management System. For candidates, this has a few practical implications even where detailed proctoring rules are not published:
- Test your environment early. Browser compatibility, stable connectivity and a quiet workspace matter more in a roughly two-hour online sitting than in a short quiz.
- Confirm conditions before exam day. Because open-book status, calculator policy and proctoring requirements are not verified in public materials, check your candidate instructions inside the LMS rather than assuming.
- Pace yourself. With 100 questions in approximately 120 minutes, you have a little over a minute per item on average. Scenario-style audit questions take longer to read than definition recall, so bank time on the easy ones.
For registration timing and scheduling considerations, our guide to C)ISMS exam dates and scheduling explains what can be confirmed. Eligibility questions are covered in C)ISMS Requirements 2026; in short, the issuer suggests an information-systems background and an interest in auditing, but exact mandatory prerequisites are not verified.
Where the Points Come From: Eight Preparation Modules
Since official exam weights are not published, you cannot know how many of the 100 questions come from each area. What the issuer does provide is an eight-module course structure, which should be treated as unweighted preparation scope, not a formal exam blueprint. The outline describes its ISO/IEC 27001 audit methodology as planning, control evaluation, substantive testing and completion, which hints at the audit-process orientation of the exam.
Domain 1: Lead Auditor Intro
The orientation layer: what a lead auditor does and how the course frames the role.
- Role expectations and audit mindset
- How the engagement of an ISMS audit is framed
Domain 2: The ISO/27001:2022
The standard itself, in its 2022 edition, is the reference point for everything an auditor tests against.
- Clause structure and management system requirements
- How the 2022 edition shapes audit criteria
Domain 3: Information Security and Key Controls
The controls an auditor must recognize, evaluate and test.
- What each control intends to achieve
- Evidence an auditor would expect to see for a control
Domain 4: Risk Management
Risk is the engine of an ISMS, so auditors must understand how it is identified and assessed.
- Risk identification and assessment concepts
- How risk drives scope and control selection
Domain 5: Risk Treatment
What organizations do with assessed risk, and how an auditor verifies it.
- Treatment options and their documentation
- Linking treatment decisions to controls
Domain 6: Audits and Auditors
The profession of auditing: principles, conduct and the auditor's responsibilities.
- Auditor competence and ethical conduct
- Types of audits and their purposes
Domain 7: Auditing the Information Security Management System
Applying audit technique specifically to an ISMS.
- Evaluating management system effectiveness
- Testing controls and documenting findings
Domain 8: Planning and Conducting an Audit
The end-to-end audit lifecycle, from preparation through completion.
- Audit planning and scoping
- Fieldwork, substantive testing and closing activities
For a deeper treatment of each area, see C)ISMS Exam Domains 2026: Complete Guide to All 8 Content Areas.
Turning 70% Into a Practice Target
Knowing the pass mark is only useful if you convert it into a measurable readiness threshold. Because the passing line is a percentage of a 100-question exam and the real item distribution is unknown, the most defensible approach is to build breadth first and depth second.
- Do not gamble on a favorite domain. With no published weights, you cannot safely neglect any of the eight modules. A strong showing in risk topics will not rescue a weak showing in audit process questions if the exam leans the other way.
- Set your own buffer. Aim to consistently score well above 70% on full-length timed practice, so that nerves, an unfamiliar question style or an unscored-item surprise does not push you under the line.
- Review misses by module. Tag every wrong answer to one of the eight modules. Patterns reveal where your real gaps are, which is more valuable than a single overall percentage.
- Practice scenario reasoning. Lead Auditor questions reward knowing what an auditor would do or conclude in a situation, not just reciting definitions.
Key Takeaway
Treat 70% as the floor, not the goal. Because the scored/unscored split and domain weights are undisclosed, readiness means consistent timed practice results clearly above 70% across all eight modules, not just your strongest ones. Our C)ISMS practice tests are built to help you measure exactly that.
A Module-Driven Preparation Sequence
Rather than a generic schedule, sequence your preparation by how the modules depend on each other. The standard comes first because every later topic references it; audit execution comes last because it synthesizes everything else. The allocation below is an editorial suggestion, not an official weighting.
Foundations and the Standard
- Lead Auditor Intro and the role of the auditor
- Read through ISO/IEC 27001:2022 structure and clauses
Controls and Risk
- Information Security and Key Controls
- Risk Management, then Risk Treatment, in that order
Audit Practice
- Audits and Auditors
- Auditing the Information Security Management System
- Planning and Conducting an Audit
Timed Simulation
- Full 100-question practice runs inside roughly two hours
- Re-study the modules where misses cluster
For a fuller planning framework, our C)ISMS Study Guide 2026 goes into more depth, and the C)ISMS cheat sheet gives you a compact final review before test day.
After You Pass: Validity and Renewal
Clearing 70% earns a credential with a defined lifespan. Under the issuer's current dedicated renewal policy, certification is valid for three years, and renewal involves 60 qualifying CEUs, agreement to the issuer's policies and ethics requirements, and payment of the applicable renewal fee (the amount is not verified here).
If you are weighing whether the investment makes sense for your career, see Is the C)ISMS Certification Worth It? and the C)ISMS salary guide for what can responsibly be said about earning potential.
Frequently Asked Questions
The issuer's outline states a minimum passing grade of 70%. The exam has 100 multiple-choice questions and runs for approximately two hours, delivered online through the Mile2 Learning Management System.
The reviewed official materials do not state whether the exam includes unscored pretest items. The safest approach is to treat every question as scored and prepare to perform comfortably above 70%.
No official weights are published, so the highest-weighted area is unverified. The eight modules are unweighted preparation headings, so study all of them rather than betting on a single area.
The candidate pass rate is not publicly disclosed in the reviewed official materials. Any specific percentage you encounter online should be treated skeptically unless it cites a verifiable source.
The verified numbers in this article apply to the Lead Auditor exam only. Lead Implementer specifications require separate confirmation with the issuer, since the combined course page does not establish identical exam details.