CoStudy

HomeCertifications › CISM — Certified Information Security Manager

CISM — Certified Information Security Manager practice questions and exam guide

400 multiple-choice questions, 160 flashcards and 10 scenario simulations, organised into 6 chapters, written to the ISACA CISM blueprint. Every question carries a full rationale.

Written and maintained by Nick Burton · last updated 2026-08-22 · how we write and review questions

Study CISM — Certified Information Security Manager in CoStudy →

About the CISM — Certified Information Security Manager exam

ISACA CISM — 2022 job practice, current until 2 November 2026; a new Exam Content Outline takes effect 3 November 2026 and ISACA has not published its domain names or weights. Current domains: Information Security Governance 17%, Information Security Risk Management 20%, Information Security Program 33%, Incident Management 30% — Program and Incident Management together are 63% of the exam. 150 questions, 4 hours, scaled score 200-800 with 450 to pass (not 75% correct), four-option single-best-answer weighted toward management judgment. Five years cumulative paid information security management experience including three years across at least three of the four domains, with up to two years substitutable but the management core non-waivable. 20 CPE hours per year and 120 per 3-year cycle.

CoStudy's CISM — Certified Information Security Manager bank holds 570 items organised into 6 chapters that follow the published blueprint. Every multiple-choice question carries a written rationale explaining why the correct answer is correct and why each distractor is tempting but wrong, and the bank includes 10 scenario-based simulations.

What the CISM bank covers

Each chapter follows a domain of the published exam outline. Practise one on its own:

Free CISM — Certified Information Security Manager practice questions

A sample of 24 multiple-choice questions from the bank, with the full rationale shown.

Information Security Governance

During strategy development the security manager identifies a large gap between current and target state. The NEXT step should be to:

  1. select the control frameworks that will be used to close each identified gap
  2. escalate the full gap to the board as an unacceptable enterprise-level exposure
  3. prioritise gap closure by business impact and define a phased, funded roadmap
  4. reduce the target state until it can be achieved within the current budget

Answer: C — prioritise gap closure by business impact and define a phased, funded roadmap

C) Correct — a gap analysis produces a prioritised, phased and costed roadmap; sequencing by business impact is what converts analysis into an executable strategy. A) Framework selection is a means question that follows the decision on what to close first. B) Escalating an unanalysed gap gives the board no decision to make and damages credibility. D) Cutting the target to fit today's budget abandons the strategic objective instead of arguing for it.

An organisation adopts the NIST Cybersecurity Framework 2.0. The PRIMARY value to governance is that it:

  1. Removes the need for a documented information security policy set and defined ISMS scope
  2. Supplies a risk-based vocabulary, including the GOVERN function, for board reporting
  3. Replaces certification against ISO/IEC 27001 for organisations in regulated sectors
  4. Guarantees compliance with the sector regulations that apply to the organisation

Answer: B — Supplies a risk-based vocabulary, including the GOVERN function, for board reporting

B is the governance value: CSF 2.0 gives executives and the board a common, risk-based language for describing current posture, target profile and the gap between them, and its GOVERN function, added in the 2024 revision alongside the original five, makes oversight and risk-strategy expectations explicit. CSF 2.0 also dropped the earlier critical-infrastructure scoping, so it applies to any organisation. A is wrong because a profile is not a policy set. C misreads a voluntary framework as a certification scheme. D is the compliance-guarantee fallacy: no framework confers regulatory compliance.

A subsidiary operates with materially different security practices than the parent. The PRIMARY governance concern is:

  1. Subsidiary employees may resent changes imposed by the parent organisation's security team
  2. Consolidated risk reporting and uniform accountability across the group are undermined
  3. Vendor contracts held by the subsidiary may carry different security and liability clauses
  4. Patch deployment cycles may not align between the subsidiary and the parent's IT function

Answer: B — Consolidated risk reporting and uniform accountability across the group are undermined

B is the governance-level concern: divergent practice means enterprise risk cannot be aggregated reliably and no single accountability model holds, so the board is briefed on a picture it cannot trust. A is a change-management symptom. C and D are real and worth managing, but they are operational consequences of the same underlying gap. Selecting an operational symptom over the enterprise accountability frame is the standard trap in this item.

Which reporting line BEST preserves CISO independence in governance?

  1. Reporting solely to the CIO, who consolidates all technology risk into one channel
  2. Reporting to the CEO or board risk committee, with a dotted line to the CIO
  3. Reporting to the head of IT operations, who owns the production control environment
  4. Reporting to the service desk manager, who sees incidents first as they are raised

Answer: B — Reporting to the CEO or board risk committee, with a dotted line to the CIO

B preserves independence: a line to the CEO or the board risk committee lets risk be reported without passing through a function whose delivery targets it may constrain, while the dotted line to the CIO keeps technology delivery coordinated. A, C and D all place the CISO inside or beneath IT delivery, where speed-to-ship and cost pressures compete directly with the risk message. A is the tempting one because it is still the most common arrangement in practice; prevalence is not independence.

Information Security Risk Management

Two overlapping controls each address the same risk to a similar degree. The MOST appropriate management action is to:

  1. retain both of them, since layered controls always reduce risk further
  2. check that retiring one keeps residual risk within tolerance
  3. retire the more expensive of the two controls immediately to reduce spend
  4. reclassify one of them as a compensating control in the risk register

Answer: B — check that retiring one keeps residual risk within tolerance

B) Correct - redundancy is only waste if removing it still leaves residual risk inside the agreed tolerance, so the decision is a tolerance test, not a cost test. A) Layering helps against differing attack paths, but genuine duplication buys little and consumes budget. C) Cutting on cost alone ignores whether the remaining control actually covers the same failure modes. D) Relabelling changes documentation without addressing the duplication.

What should be done FIRST in the risk management process?

  1. Select and implement treatments for the exposures the security team believes are most significant
  2. Purchase cyber insurance so financial exposure is transferred before any analysis has been performed
  3. Identify and inventory assets with the threats and vulnerabilities that apply to them
  4. Defer action until an incident reveals which assets actually matter to the organization's operations
  5. Engage external consultants to benchmark the program against peers operating in the same sector

Answer: C — Identify and inventory assets with the threats and vulnerabilities that apply to them

C applies the life cycle: identify assets, threats and vulnerabilities, then assess likelihood and impact, then treat, then monitor. You cannot protect or prioritize what you have not enumerated. A is the classic managerially wrong answer, jumping to treatment on intuition and misdirecting spend. B is a treatment option, not a first step, and transfers only part of the loss. D abandons management judgment to events. E can inform target state but presumes a current-state inventory already exists.

After implementing a control, the risk that remains is termed:

  1. Inherent risk
  2. Total risk
  3. Residual risk
  4. Secondary risk

Answer: C — Residual risk

Residual risk = post-control. Inherent = pre-control. Secondary risk = risk introduced by the control itself. Residual must fit within risk appetite or trigger further action.

A proposed control costs 150,000 per year and reduces the annualised loss expectancy of a risk from 120,000 to 20,000. The MOST appropriate recommendation is to:

  1. implement the control because it removes most of the enterprise's assessed annual exposure
  2. implement the control but seek a vendor discount to improve the economics
  3. implement a lower-cost partial control and monitor the remaining exposure
  4. present the negative return to the risk owner and let them decide on treatment

Answer: D — present the negative return to the risk owner and let them decide on treatment

D) Correct — the control costs more than the loss it avoids, but the treatment decision belongs to the risk owner, who may weigh factors such as regulatory or reputational consequence the ALE does not capture. A) Reducing exposure is not sufficient justification when the annual cost exceeds the annual benefit. B) A discount might change the arithmetic but presumes the decision before the economics support it. C) A cheaper partial control is often sensible, yet selecting it unilaterally still substitutes the manager's judgment for the owner's.

Information Security Program — Development and Resources

A single engineer is the only person able to operate a critical security platform. The MOST appropriate management action is to:

  1. cross-train additional staff and document the operating procedures
  2. increase the engineer's compensation to reduce the chance of departure
  3. place the platform under a support contract with the vendor
  4. restrict the engineer's ability to take extended leave

Answer: A — cross-train additional staff and document the operating procedures

A) Correct - key person dependency is a resilience risk in the programme's own resources, and it is treated by distributing knowledge and codifying the procedure. B) Retention incentives reduce the likelihood of departure but leave the exposure fully intact if it happens. C) Vendor support covers product faults, not the enterprise's specific configuration and operating knowledge. D) Constraining leave is unsustainable, harms the individual, and does nothing for an unplanned absence.

A compensating control is appropriate when:

  1. The primary control is available and preferred by the control owner
  2. A vendor recommends its own product in place of the specified control
  3. The auditor is unavailable to test the primary control this cycle
  4. The primary control is infeasible and the alternative is equivalent

Answer: D — The primary control is infeasible and the alternative is equivalent

D is the key: a compensating control is a deliberate substitute that must demonstrate equivalent risk reduction and be approved. A removes the reason to compensate. B is vendor-led control selection. C confuses assurance scheduling with control design.

An enterprise applies ISO/IEC 27001:2022 in building its programme. Which statement is accurate about the Annex A control set?

  1. It contains 93 controls organised into four themes
  2. It contains 114 controls organised into fourteen domains
  3. It contains 93 controls organised into fourteen domains
  4. It contains 114 controls organised into four themes

Answer: A — It contains 93 controls organised into four themes

A) Correct - the 2022 edition restructured Annex A into 93 controls across organisational, people, physical and technological themes. B) That is the superseded 2013 structure, and the transition period for it has closed. C) This mixes the current control count with the retired domain structure. D) This mixes the retired control count with the current theme structure.

A newly hired security manager is asked to build an information security programme from scratch. The FIRST activity should be to:

  1. select a control framework and begin a gap assessment against it
  2. understand the business objectives, obligations and risk appetite
  3. recruit the core security team so that work can begin in parallel
  4. deploy baseline technical controls on the most exposed systems

Answer: B — understand the business objectives, obligations and risk appetite

B) Correct - a programme is an instrument for delivering business outcomes, so its objectives must be derived from what the enterprise is trying to achieve and what it is obliged to do. A) Framework selection before understanding requirements produces a checklist programme that is expensive and poorly aligned. C) Hiring precedes knowing what capabilities are needed and locks in the wrong skill mix. D) Deploying controls first is activity without direction and creates commitments that are hard to unwind.

Information Security Program — Operations, Architecture and Third Party

Data flow mapping reveals that regulated data is decrypted at an integration broker sitting outside the regulated zone. The security manager's NEXT step should be to:

  1. Require the broker to be rebuilt inside the regulated zone before the next scheduled release
  2. Add the broker to the monitoring scope and record an exception in the enterprise risk register
  3. Instruct the integration team to implement end-to-end encryption that passes through the broker
  4. Assess the exposure and present treatment options to the accountable data owner

Answer: D — Assess the exposure and present treatment options to the accountable data owner

D) Correct — a newly identified gap is first analysed and then put to the owner with options; selecting the treatment before the exposure is understood is the recurring management error. A) Re-platforming may well be the right treatment, but mandating it pre-empts the owner's decision and the cost comparison. B) Monitoring plus an exception entry documents the gap without treating it or informing the decision-maker. C) End-to-end encryption is one candidate treatment and may be incompatible with what the broker must do to the data.

A review finds that four critical business services all depend on the same cloud provider operating in a single region. The MOST significant issue to escalate is:

  1. Concentration risk, because one single provider event would remove several critical services at once
  2. Vendor lock-in, because migration costs will rise as the enterprise deepens its use of the provider
  3. Shared responsibility confusion, because provider and enterprise may each assume the other is acting
  4. Insufficient due diligence, because one provider was assessed for four separate business processes

Answer: A — Concentration risk, because one single provider event would remove several critical services at once

A) Correct — aggregation of critical dependencies on a single provider and region is a resilience issue that a per-service risk assessment will systematically miss. B) Lock-in is a real commercial concern but its impact is cost and flexibility, not simultaneous loss of critical services. C) Responsibility ambiguity is a genuine cloud risk, yet it is not what this particular finding reveals. D) A single well-executed assessment can legitimately cover multiple services; the number of processes is not itself the defect.

A review of non-human accounts used by applications and automation identifies a governance weakness. The MOST significant is that these identities:

  1. Are usually excluded from the enterprise's password complexity and rotation standard
  2. Cannot be enrolled in multifactor authentication in the majority of environments
  3. Often lack a named owner and any defined lifecycle for review, rotation and revocation
  4. Are typically created by development teams rather than by the central identity team

Answer: C — Often lack a named owner and any defined lifecycle for review, rotation and revocation

C) Correct — ownerless machine identities accumulate entitlements, outlive their purpose and are never recertified, which is the governance failure that turns them into standing attack paths. A) Exclusion from password standards is a symptom of the missing lifecycle rather than the underlying problem. B) Workload authentication uses certificates, keys and platform-issued credentials, so the absence of multifactor is not the defining issue. D) Who creates them matters less than whether anyone is accountable for reviewing them afterwards.

A critical supplier declines an on-site audit, offering instead a recent independent assurance report on its service. The BEST response is to:

  1. Insist on exercising the contractual right to audit, since third-party reports cannot evidence control operation
  2. Accept the report and close the review, as an independent auditor's opinion supersedes internal assessment
  3. Review the report's scope, period covered and noted exceptions against the services actually consumed
  4. Require the supplier to complete the enterprise's own security questionnaire in place of the assurance report

Answer: C — Review the report's scope, period covered and noted exceptions against the services actually consumed

C) Correct — an assurance report can satisfy the need, but only after management checks that the scope covers the service used, the period is current and the exceptions do not touch relied-upon controls. A) A well-scoped report over an operating period does evidence control operation; insisting on an audit ignores a valid alternative. B) Accepting without reading the scope and exceptions is the classic false comfort in third-party assurance. D) A self-completed questionnaire is weaker evidence than an independent opinion, so substituting it is a step backwards.

Incident Management — Readiness and Response

After a confirmed compromise of a domain controller, the response team wants to reimage the server immediately to restore service. Litigation is considered likely. The security manager's NEXT action should be to:

  1. Direct that forensic images and volatile data be captured before rebuilding
  2. Approve the reimage because service restoration is the priority
  3. Escalate the decision to the chief executive for a business call
  4. Instruct the team to isolate the server and take no further action pending audit

Answer: A — Direct that forensic images and volatile data be captured before rebuilding

A) Correct — where litigation is reasonably anticipated, preservation obligations attach, and capturing images and memory first costs little while destroying them is irreversible. B) is the technically fastest path and the classic trap; speed here forfeits evidence the organisation will need. C) tempts because major incidents escalate, but the preservation decision sits with the response plan and counsel, not the chief executive. D) freezes the response entirely; isolation plus preservation plus rebuild is the correct sequence, and audit is not the gating function.

How does incident management differ from incident response?

  1. The terms are interchangeable and describe the same activities within the information security program
  2. Response is the tactical handling of an event; management is the program of preparation and improvement
  3. Response is the broader program and incident management is one activity performed inside it
  4. Management refers to routine daily operations while response applies only to declared disasters
  5. No distinction exists, as both are governed by the same plan and executed by the same people

Answer: B — Response is the tactical handling of an event; management is the program of preparation and improvement

B has the scope right: response is what the team does when an event occurs, while management is the surrounding program covering the plan, the team and its authorities, playbooks, exercises, communication arrangements, metrics and post-incident improvement. A and E deny a distinction the exam tests. C reverses the containment relationship. D invents a threshold that does not exist, since incident management applies across the full severity range, not only to declared disasters.

What is the PRIMARY purpose of an incident response plan?

  1. To create the formal record of incidents after they have been contained and services restored
  2. To define roles, authorities, procedures and communications before an incident occurs
  3. To eliminate the possibility that a security incident will affect the organization's operations
  4. To take the place of the business continuity plan for disruptions arising from any cause
  5. To reassure customers and regulators that the organization takes its security duties seriously

Answer: B — To define roles, authorities, procedures and communications before an incident occurs

B is the point of the plan: decisions about who leads, who may authorize disconnection, whom to notify and on what trigger must be made in advance, because they cannot be made well under pressure. A describes an output of the process, not its purpose. C is unattainable, since no plan prevents incidents. D confuses scope; the response plan handles the security event while continuity keeps the business running. E is a by-product of a credible plan rather than its objective.

Short-term containment differs from long-term containment in that short-term:

  1. Replaces eradication, since the threat goes when the host is isolated
  2. Stops immediate damage while a durable fix is engineered separately
  3. Is the permanent end state once affected systems are segregated
  4. Always requires a full shutdown of the affected business service line

Answer: B — Stops immediate damage while a durable fix is engineered separately

B is the key: two-phase containment buys time without committing to the final architecture. A conflates containment with eradication. C ignores the second phase entirely. D overstates a specific tactic as a rule.

Business Continuity, Recovery and Resilience

The PRIMARY input that determines which processes appear in the business continuity plan is:

  1. The asset inventory maintained by IT operations
  2. The results of the business impact analysis
  3. The findings of the most recent risk assessment
  4. The service catalogue agreed with business units

Answer: B — The results of the business impact analysis

B) Correct — the BIA identifies critical processes, their dependencies and their time-based impact, which is what determines continuity scope and priority. A) tempts because dependency mapping needs it, but an inventory lists what exists rather than what matters. C) informs likelihood and treatment of threats; continuity planning is impact-driven and largely threat-agnostic. D) documents services offered and their support levels, which is an input to, not a substitute for, impact analysis.

Which is the MOST appropriate frequency and trigger arrangement for reviewing the business continuity plan?

  1. Every three years, aligned to the strategic planning cycle
  2. Whenever the internal audit function schedules a continuity plan review
  3. Annually, and after any significant business or supplier change
  4. After each exercise, with no fixed periodic review requirement

Answer: C — Annually, and after any significant business or supplier change

C) Correct — a periodic baseline review catches drift while change-driven triggers keep the plan aligned to what the business actually looks like now. A) leaves the plan stale through years of change in most organisations. B) makes maintenance dependent on an assurance function's schedule rather than on management ownership. D) tempts because exercise-driven updates are valuable, but without a calendar review a plan can go unexamined if exercises lapse.

Which of the following is the STRONGEST evidence that lessons learned from disruptions are improving the organisation?

  1. Repeat causes decline across successive incidents and exercises
  2. Post-incident reviews are completed within ten working days of closure
  3. Review reports are distributed to all senior managers promptly
  4. Each review produces at least one documented recommendation

Answer: A — Repeat causes decline across successive incidents and exercises

A) Correct — the purpose of the loop is to stop the same failure recurring, so a falling rate of repeat root causes is the outcome measure that matters. B) measures timeliness of the process, not its effect. C) measures dissemination, which is necessary but not sufficient. D) measures output volume and can be satisfied by trivial recommendations.

What distinguishes a business continuity plan from a disaster recovery plan?

  1. The two terms describe the same plan and differ only in the vocabulary the auditor happens to prefer
  2. The continuity plan addresses information technology recovery and nothing outside that boundary
  3. The disaster recovery plan is the broader of the two and contains the continuity plan within it
  4. Continuity keeps business processes operating during disruption; recovery restores IT systems
  5. The disaster recovery plan governs business processes while continuity governs the technology estate

Answer: D — Continuity keeps business processes operating during disruption; recovery restores IT systems

D states the relationship correctly: continuity is the enterprise-wide plan covering people, premises, suppliers and communication, and disaster recovery is the technology subset that restores systems and data. Both derive their targets from the BIA. A denies a distinction the exam tests directly. B narrows continuity to IT. C and E simply reverse the two scopes, which is the most frequently seen error.

CISM — Certified Information Security Manager flashcards

6 sample cards from the 160 in the bank.

What are the NIST CSF 2.0 functions?

Six: Govern • Identify • Protect • Detect • Respond • Recover. Govern was added in CSF 2.0 (February 2024) and covers risk strategy, roles and responsibilities, policy, oversight and supply-chain risk management - it is the function a CISM candidate should lead with. CSF 2.0 also dropped the critical-infrastructure scoping, so it now applies to organizations of any sector or size.

Access control models?

DAC (discretionary), MAC (mandatory), RBAC (role-based), ABAC (attribute-based).

CISM exam structure and passing score?

150 questions in 4 hours, four-option single-best-answer, delivered at PSI test centres or via remote proctoring. Scoring is a scaled 200-800 range with 450 required to pass - this is a scaled score, not 75 percent of items correct, and stating it as a percentage is the most common error in third-party material. Note also that a new Exam Content Outline takes effect 3 November 2026.

What should determine the depth of due diligence applied to a vendor?

The vendor's risk tier — driven by the sensitivity and volume of data accessed, criticality to business processes, level of network or privileged access, and regulatory exposure — not the contract value. A low-cost supplier with privileged access to production warrants deeper assurance than an expensive but isolated one.

BCP vs DR?

BCP: business continuity (broad). DR: technology recovery (subset of BCP).

Maturity model levels (CMMI-like)?

Initial, Managed, Defined, Quantitatively Managed, Optimizing.

Practise the full CISM — Certified Information Security Manager bank

These samples are a small slice. The full bank runs flashcards, multiple choice and timed mock exams with per-chapter progress tracking, on the web and in the iOS app.

Open CISM — Certified Information Security Manager →

CISM — frequently asked

How many CISM practice questions does CoStudy have?

The CISM — Certified Information Security Manager bank holds 570 items: 400 multiple-choice questions, 160 flashcards and 10 scenario-based simulations. 30 of them are on this page to read free, with no signup.

Do the CISM questions come with explanations?

Yes. Every multiple-choice item carries a written rationale that states the controlling principle behind the correct answer and then addresses each wrong option in turn — why it tempts and precisely where it fails. Knowing why the plausible answer was wrong is worth more than knowing which letter was right.

What topics does the CISM bank cover?

It is organised into 6 chapters that follow the published exam blueprint: Information Security Governance; Information Security Risk Management; Information Security Program — Development and Resources; Information Security Program — Operations, Architecture and Third Party; Incident Management — Readiness and Response; Business Continuity, Recovery and Resilience. The number of questions in each chapter is proportional to that domain's published weight, so working through the bank exposes you to roughly the mix the real exam uses.

What is on the CISM exam?

ISACA CISM — 2022 job practice, current until 2 November 2026; a new Exam Content Outline takes effect 3 November 2026 and ISACA has not published its domain names or weights. Current domains: Information Security Governance 17%, Information Security Risk Management 20%, Information Security Program 33%, Incident Management 30% — Program and Incident Management together are 63% of the exam. 150 questions, 4 hours, scaled score 200-800 with 450 to pass (not 75% correct), four-option single-best-answer weighted toward management judgment. Five…

Are the CISM practice questions free?

The samples on this page are free to read in full, rationales included, with no account. The complete 570-item bank, the timed mock exams and per-chapter progress tracking are part of CoStudy on the web and in the iOS app.

How current is the CISM content?

Last reviewed 2026-08-22. Banks are written against the certifying body's published exam outline and re-checked when that outline changes — exams get renumbered, retired and reweighted, and a bank written to a superseded outline teaches the wrong proportions. Figures that are re-indexed annually are deliberately not asserted as rules; the questions test the governing principle instead.

Primary source

This bank is written against ISACA's published exam material. Check the ISACA exam content outlines for the current outline, fees and eligibility rules — those change, and the certifying body is the only authority on them. CoStudy is not affiliated with ISACA.

Related study guides

Related certifications

Browse all 222 study banks →