CISM practice test: 497 questions with full explanations
- Questions on the exam
- 150
- Time allowed
- 240 minutes format →
- Passing score
- 450 of 800 — vendor, checked September 4, 2026 detail →
- Exam fee
- $760 ($575 members) — vendor, checked September 4, 2026 detail →
497 practice test questions for CISM, grouped by exam domain. Every question below shows all four options, which one is correct, and why each of the other three is not — the wrong answers are where most candidates lose marks.
Not sure where you stand? Take the free 5-min CISM readiness check →
CISM exam format → · CISM passing score → · CISM exam cost →
Questions by domain
- Information Security Governance — 131 questions →
- Information Security Risk Management — 124 questions →
- Information Security Program — 124 questions →
- Incident Management — 118 questions →
Sample questions
Develop a security strategy that explicitly maps security: What should the CISM do FIRST to address this situa
- Develop a security strategy that explicitly maps security objectives to business goals and present that alignment to executive leadership for endorsement. ✓Correct. The CISM's primary responsibility is ensuring the information security program is aligned with the organization's business strategy and objectives. Developing a strategy that links security objectives to business goals demonstrates value, reduces friction, and gains executive support.
- Expand security awareness training for business unit managers so they better understand why existing security controls sometimes delay revenue-generating initiatives.Incorrect. Awareness training addresses knowledge gaps among staff, but does not resolve the strategic misalignment between the security program and business objectives. The problem is governance-level, not training-level.
- Conduct a gap analysis comparing current security controls against applicable regulatory requirements and report the resulting deficiencies to leadership.Incorrect. While regulatory compliance is important, performing a gap analysis does not address the core problem of misalignment between security and business strategy. This action would further reinforce the perception of security as a compliance function rather than a business enabler.
- Establish a risk acceptance process that lets business units bypass certain security controls on revenue-generating projects when justified.Incorrect. Simply creating workarounds without strategic alignment does not resolve the underlying governance issue and could introduce significant unmanaged risk. Risk acceptance should follow a formal process tied to risk appetite, not be used as a default bypass mechanism.
All 131 Information Security Governance questions →
Quantitative risk assessment using ALE calculations: Which risk assessment approach is MOST appropriate in thi
- A vendor risk assessment using the Common Vulnerability Scoring System (CVSS), because it provides standardized risk scores for technical systems.Incorrect. CVSS is a vulnerability severity scoring system for technical vulnerabilities, not a business risk assessment methodology. It does not account for asset value, business impact, or organizational risk context. CVSS scores inform technical remediation prioritization, not business risk investment decisions.
- Quantitative risk assessment using ALE calculations, because the available data and investment scale support financially precise risk metrics. ✓Correct. When historical incident data, asset values, and business impact models are available, quantitative risk assessment using metrics like Annual Loss Expectancy (ALE = ARO × SLE) provides financially precise risk metrics that directly support investment decisions. For a $2M security investment, executives and board members will expect financial justification (e.g., 'the control reduces annual expected loss by $800K'), which quantitative methods provide. The available data specifically enables this approach.
- A hybrid approach that uses qualitative methods first, followed by quantitative validation of the top three risks.Incorrect. While hybrid approaches have merit in some contexts, this scenario has sufficient data to proceed directly with quantitative assessment. A hybrid approach would add process steps and potentially dilute the precision of the quantitative results. Given the investment scale and available data, leading with full quantitative assessment is more appropriate.
- Qualitative risk assessment using a 5x5 risk matrix, because it is faster and provides sufficient information for decision-making.Incorrect. While qualitative assessment is valuable for rapid triage, the scenario provides conditions that enable and require quantitative analysis: historical incident data, documented asset values, and a significant investment decision. Qualitative assessment would not provide the financial precision needed to justify a $2M investment to executive leadership.
All 124 Information Security Risk Management questions →
Background checks and clean desk policy are administrative: Which classification CORRECTLY categorizes these c
- All five controls are preventive controls, and the classification into administrative/technical/physical is less important than their preventive function.Incorrect. CCTV is primarily a detective control (it detects/records incidents) rather than a preventive control. Additionally, the classification into administrative/technical/physical is fundamental to security architecture design, defense-in-depth planning, and control gap analysis. Both dimensions (control type and control function) are important.
- Background checks are technical; biometric access, CCTV, and full-disk encryption are physical; clean desk policy is administrative.Incorrect. Background checks are an administrative control (personnel procedure), not a technical control. Full-disk encryption is a technical control, not a physical control. This misclassification reflects a misunderstanding of the control type framework.
- Background checks and clean desk policy are administrative; biometric access and CCTV are physical; full-disk encryption is technical. ✓Correct. Administrative controls are policies, procedures, and people-based controls: background checks (pre-employment screening procedure) and clean desk policy (behavioral policy). Physical controls protect the physical environment: biometric access controls (physical access restriction) and CCTV (physical surveillance). Technical controls use technology to protect information: full-disk encryption (technical data protection mechanism).
- Background checks and clean desk policy are administrative; biometric access, CCTV, and full-disk encryption are all technical controls because they all use technology.Incorrect. Biometric access controls and CCTV are physical controls protecting the physical environment, even though they use technology to do so. The classification is based on what the control protects (the physical environment vs. information systems) not on whether technology is used. Full-disk encryption is correctly classified as technical.
All 124 Information Security Program questions →
Activate the incident response team: The organization's incident response policy requires board notification f
- Immediately notify the board of directors and legal counsel, since the potential volume of 50,000 records clearly exceeds the policy's defined breach notification threshold and demands immediate executive escalation.Incorrect. The policy specifies notification for 'confirmed' exfiltration. Notifying the board of an unconfirmed alert before initial investigation would trigger unnecessary escalation and may cause organizational disruption based on a false positive. Initial containment and investigation should precede board notification, with escalation occurring once the incident is confirmed.
- Submit a standard ticket to the IT operations team asking them to investigate the alert during normal business hours and provide a detailed written status report by the close of business on Monday.Incorrect. A potential breach of 50,000 customer credit card records is a Priority 1 security incident requiring immediate response, not a routine ticket. Routing it through normal IT operations with a 3-day SLA is grossly inadequate and would likely result in regulatory violations for failure to respond timely.
- Wait until Monday morning when the full incident response team is on site before taking any action, since the incident response policy formally requires confirmed exfiltration before a response begins.Incorrect. Waiting 60+ hours in a potential data breach situation is not appropriate. The time to contain a potential breach is critical—the longer you wait, the more data may be exfiltrated or the harder it becomes to preserve forensic evidence. The incident response process should begin immediately upon detecting a potential incident.
- Activate the incident response team, initiate containment procedures to stop any potential ongoing exfiltration, and preserve forensic evidence while the investigation confirms or rules out the suspected breach. ✓Correct. The first response to a potential data breach should always be containment to stop any ongoing harm, followed by evidence preservation to support investigation and legal proceedings. The fact that exfiltration is unconfirmed does not delay the initial response—it means the response proceeds as a precautionary measure until confirmation or denial. Waiting for confirmation before acting can result in additional data loss and destruction of forensic evidence.
All 118 Incident Management questions →
COBIT for IT governance and enterprise alignment: Which combination BEST satisfies both requirements?
- COBIT for IT governance; NIST SP 800-53 for information security controls.Incorrect. NIST SP 800-53 is a controls catalog primarily designed for US federal agencies. While it is comprehensive, it is not the international standard for information security management systems. ISO 27001 is more appropriate for an international manufacturing company seeking a globally recognized security management framework.
- COBIT for IT governance and enterprise alignment; ISO 27001 for information security controls. ✓Correct. COBIT (Control Objectives for Information and Related Technologies) is designed to bridge IT governance with enterprise governance and provides a comprehensive metrics framework for IT performance. ISO 27001 provides a systematic approach to managing information security with a defined set of controls (Annex A). Using both together satisfies the CIO's governance and metrics requirements and the CISO's security controls requirements.
- ISO 27001 for both IT governance and information security controls, since it covers both domains.Incorrect. ISO 27001 is an information security management system (ISMS) standard and does not specifically address enterprise IT governance integration and IT performance metrics in the way COBIT does. Using ISO 27001 alone would not fully satisfy the CIO's requirement for enterprise-level IT governance.
- NIST CSF for IT governance; ISO 27001 for information security controls.Incorrect. While the NIST Cybersecurity Framework (CSF) provides a risk-based approach to security, it is not specifically designed to integrate IT governance with enterprise governance in the way COBIT does. COBIT is the more appropriate choice for meeting enterprise governance alignment and IT performance measurement requirements.
All 131 Information Security Governance questions →
Implement compensating controls to reduce the ALE below: What is the MOST appropriate risk treatment recommend
- Transfer the risk by purchasing cyber insurance sized to cover the potential $350K annual loss until the modernized replacement system is fully deployed.Incorrect. Risk transfer through insurance is a valid treatment option, but it does not reduce the likelihood or impact of the actual security incident—it only provides financial compensation after a loss occurs. For a payment processing system with active encryption vulnerabilities, cyber insurance alone does not address the underlying risk and may not be the most cost-effective option for an 18-month period. Additionally, insurers may require compensating controls before providing coverage for known vulnerabilities.
- Accept the risk outright because the application will be retired in 18 months and the $500K remediation cost exceeds the annual risk tolerance threshold.Incorrect. Risk acceptance is only appropriate when the risk falls within the organization's risk appetite. The current ALE of $350K exceeds the maximum tolerated annual loss of $200K, meaning the risk exceeds the defined risk tolerance and cannot simply be accepted without additional controls to reduce it to an acceptable level.
- Implement compensating controls to reduce the ALE below $200K for the 18-month interim period, with formal risk acceptance for any remaining residual risk. ✓Correct. This approach recognizes that: (1) full remediation is cost-inefficient for a system with an 18-month lifespan, (2) the current risk exceeds the defined tolerance and cannot be simply accepted, (3) compensating controls (e.g., network segmentation, enhanced monitoring, access restrictions) can reduce the ALE to within tolerance at a fraction of the $500K remediation cost, and (4) any residual risk above tolerance requires formal risk acceptance with management accountability. This balances cost efficiency with governance requirements.
- Mitigate the risk by immediately investing the full $500K to rebuild the encryption capabilities of the legacy payment application well before its scheduled replacement.Incorrect. While remediation would address the risk, investing $500K in a system scheduled for replacement in 18 months is difficult to justify. The $500K investment in a legacy system that will be decommissioned is not cost-effective when compensating controls may reduce the ALE below the $200K tolerance threshold at lower cost.
All 124 Information Security Risk Management questions →
The organization's HIPAA Business Associate Agreement: What is the CISM's MOST critical immediate concern?
- The organization's HIPAA Business Associate Agreement (BAA) obligations may have been violated by the vendor's undisclosed subcontracting arrangement without consent. ✓Correct. Under HIPAA, when a covered entity shares PHI with a Business Associate (the SaaS vendor), a Business Associate Agreement (BAA) is required. The BAA must include provisions requiring the Business Associate to ensure that any subcontractors (fourth parties) that access PHI also agree to the same HIPAA protections through a Subcontractor BAA. If the vendor subcontracted PHI processing without a Subcontractor BAA and without the covered entity's awareness, this constitutes a potential HIPAA violation regardless of the original contract's 'reasonable security measures' language. This is the immediate compliance and legal risk that requires urgent attention.
- The vendor's undisclosed subcontractor may have failed to implement encryption for data at rest and in transit, directly creating a PHI data breach exposure.Incorrect. While encryption is an important control, it is a secondary concern to the fundamental HIPAA compliance violation. The primary issue is not whether encryption is present, but whether the PHI transfer and processing arrangement is legally authorized under the BAA framework. An encryption gap can be remediated; a BAA violation may require immediate operational changes and regulatory notification.
- The original contract's vague 'reasonable security measures' clause is legally unenforceable and should be renegotiated to specify concrete technical security standards.Incorrect. While vague contractual language is a genuine procurement weakness that should be addressed in contract renegotiation, it is not the most critical immediate concern. The 'reasonable security measures' clause is a contract risk; the BAA violation is a regulatory compliance risk with potential financial penalties and mandatory notification requirements.
- The fourth party operates in a country lacking data protection laws equivalent to HIPAA, creating cross-border jurisdictional and data sovereignty risk for the organization.Incorrect. Jurisdictional risk and data sovereignty are valid concerns, particularly for GDPR-regulated data. For HIPAA-regulated PHI, the primary immediate concern is the BAA compliance failure, as HIPAA requirements follow the data regardless of geography. Jurisdictional risk is a serious long-term concern but is secondary to the immediate BAA violation.
All 124 Information Security Program questions →
BCP addresses how the organization continues critical: How should the CISM respond?
- BCP addresses how the organization continues critical business operations during a disruption while DRP addresses how IT systems are recovered afterward; both would be invoked concurrently for a data center flood, with the DRP recovering IT systems and the BCP maintaining business operations throughout the recovery period. ✓Correct. BCP is a broader plan covering how the entire organization maintains critical business functions during a disruption—including manual workarounds, alternative locations, communication plans, and business process continuity. DRP is a subset of BCP focused specifically on recovering IT infrastructure and systems. For a data center flood: the DRP would guide IT in recovering systems at the alternate site, while the BCP would guide business units in maintaining operations (manual procedures, customer communication, vendor notifications) during the IT recovery period. Both plans operate concurrently.
- BCP is strictly a long-term strategic recovery plan while DRP handles only short-term operational recovery; for a data center flood, therefore, just the DRP would be invoked because the event is fundamentally an IT infrastructure problem rather than a broader business continuity concern for the wider organization's overall operations.Incorrect. This characterization misdefines both plans. BCP is not about 'long-term' recovery—it governs maintaining business operations throughout the disruption period, which may be days or weeks. A data center flood affects business operations, not just IT infrastructure, so BCP must also be invoked to maintain business continuity during the IT recovery period.
- BCP and DRP are essentially the same document and the two terms are used interchangeably for regulatory and audit purposes; for a data center flood the combined DRP/BCP would simply be invoked as one unified plan to guide the organization's overall response and recovery from the incident.Incorrect. BCP and DRP are distinct plans with different scope, objectives, and audiences. Conflating them at the board level demonstrates a governance gap and may result in both plans being inadequately developed.
- DRP is the plan reserved specifically for natural disasters while BCP is the plan reserved specifically for cyber incidents; because a flood is by definition a natural disaster, only the DRP would be invoked to guide the organization's response to this particular data center event.Incorrect. This is a fundamental misclassification. BCP and DRP are distinguished by scope (business operations vs. IT systems), not by the type of disruptive event. Both plans may be applicable to natural disasters, cyber incidents, and other disruptions depending on their impact.
All 118 Incident Management questions →
CISM exam: the facts
How many questions are on the CISM exam?
150, as published by the exam vendor.
How long is the CISM exam?
240 minutes. Across 150 questions that is about 96 seconds per question.
What topics does the CISM exam cover?
4 domains: Information Security Program, Incident Management, Information Security Risk Management, Information Security Governance. Weights: Information Security Program 0.33%, Incident Management 0.3%, Information Security Risk Management 0.2%, Information Security Governance 0.17%.
How many CISM practice test questions does Certsqill have?
497, spread across 4 exam domains. Every one shows all options, which is correct, and why each of the others is not.
Would you pass CISM today?
Five minutes, and you get a score per domain — not one number, but which section to open tonight.
Test your CISM readiness — free