CISM - Certified Information Security Manager - Practice Questions¶
15 questions across the four CISM domains: information security governance, information security risk management, information security program development and management, and incident management.
CISM is a management exam. When two answers are both technically defensible, the correct one is usually the one that aligns to business objectives, involves the right stakeholders, or follows governance process.
Cert page: exams/isaca/cism/
Question 1¶
Scenario: What most influences the design of an information security strategy?
A. The latest threat intelligence B. The organization's business objectives and risk appetite C. Available security products D. Peer organizations' programs
Answer
**Correct: B** **Why:** Alignment to business objectives is the recurring CISM theme, and it is what separates a security program from a shopping list. Threats inform the risk assessment, but they do not set the strategy's direction on their own.Question 2¶
Scenario: Senior management does not support a proposed security investment.
A. Implement it anyway B. Present a business case quantifying risk reduction in business terms, with options and their residual risk C. Escalate to the board D. Reduce the scope silently
Answer
**Correct: B** **Why:** Communicating risk in business language is a core CISM competency, and "we need it for security" is not a business case. Offering options with their residual risk lets management make an informed decision, which is where the decision belongs.Question 3¶
Scenario: Who should own the risk acceptance decision for a residual risk?
A. The security manager B. The business owner accountable for the affected process, at a level of authority matching the risk C. The IT department D. The auditor
Answer
**Correct: B** **Why:** Security advises, the business accepts. A security manager accepting risk on the business's behalf misplaces accountability, which is why the seniority of the accepting party should scale with the size of the risk.Question 4¶
Scenario: Which best demonstrates the value of the security program to the board?
A. The number of blocked attacks B. Metrics tied to business outcomes: risk reduction against appetite, control coverage of critical assets, and incident impact trends C. Patch counts D. Tool inventory
Answer
**Correct: B** **Why:** Activity counts show effort, not effectiveness, and blocked attacks in particular reward noisy environments. Board-level metrics answer whether risk is inside appetite and moving in the right direction.Question 5¶
Scenario: A risk assessment identifies a high risk with an expensive control.
A. Always implement the control B. Evaluate the treatment options - mitigate, transfer, avoid, or accept - against cost and business impact, and recommend accordingly C. Accept the risk D. Transfer it via insurance always
Answer
**Correct: B** **Why:** A control costing more than the risk it removes is a poor decision even when the risk is high. Insurance transfers financial loss but not regulatory or reputational consequence, which is the limit of transfer as a strategy.Question 6¶
Scenario: What is the primary purpose of information security governance?
A. To implement controls B. To ensure security supports and is aligned with business strategy, with clear accountability and measurable outcomes C. To pass audits D. To manage the security team
Answer
**Correct: B** **Why:** Governance sets direction and accountability; management executes within it. The six outcomes ISACA names are strategic alignment, risk management, value delivery, resource management, performance measurement, and assurance process integration.Question 7¶
Scenario: A new regulation applies to the organization.
A. Implement every requirement immediately B. Perform a gap analysis against current controls, assess risk and effort, and build a prioritized remediation plan with business input C. Wait for enforcement D. Buy a compliance tool
Answer
**Correct: B** **Why:** Gap analysis before action is the manager's move. Many requirements will already be satisfied by existing controls, and identifying those first is what makes the remaining plan proportionate rather than a wholesale rebuild.Question 8¶
Scenario: During an incident, who decides whether to shut down a critical production system?
A. The security analyst B. Business management, informed by security's assessment, following the escalation path defined in the incident response plan C. The CISO alone D. The system administrator
Answer
**Correct: B** **Why:** Containment that stops the business is a business decision, and the time to agree who decides is before the incident, not during it. Predefined escalation criteria are what stop the argument happening at 3am.Question 9¶
Scenario: What is the first phase of incident response?
A. Containment B. Preparation, which includes the plan, roles, tooling, and training that make every later phase possible C. Detection D. Eradication
Answer
**Correct: B** **Why:** Preparation is the phase you cannot do during an incident, and it is where most response failures originate. The sequence continues through detection and analysis, containment, eradication, recovery, and lessons learned.Question 10¶
Scenario: Post-incident review identifies the same root cause as three previous incidents.
A. Close the incident B. Escalate it as a systemic issue requiring a governance-level decision on remediation and resourcing C. Retrain the team D. Add monitoring
Answer
**Correct: B** **Why:** Recurrence means the earlier corrective actions did not address the cause, or were never funded. Treating the fourth occurrence as another incident rather than a program failure guarantees a fifth.Question 11¶
Scenario: A third-party vendor will process sensitive data.
A. Rely on their certifications B. Perform due diligence proportionate to the risk, set security requirements in the contract with a right to audit, and monitor throughout the relationship C. Prohibit third parties D. Require an on-site audit always
Answer
**Correct: B** **Why:** Certifications are a point-in-time input, not the whole assessment, and they may not cover the service you are buying. The lifecycle view is what CISM tests: due diligence, contractual requirements, ongoing monitoring, and a defined exit.Question 12¶
Scenario: Security policies exist but staff do not follow them.
A. Add more policies B. Investigate why: unclear, impractical, unenforced, or poorly communicated, then address the cause with awareness, process change, or enforcement C. Discipline offenders D. Remove the policies
Answer
**Correct: B** **Why:** Policies that conflict with how work actually gets done are routed around, and no amount of enforcement changes that. Diagnosing the cause before choosing the remedy is the management answer.Question 13¶
Scenario: Which is the best indicator that a security awareness program is effective?
A. Completion rates B. Behavioral change: fewer phishing simulation clicks, more reported suspicious emails, and fewer policy violations C. Training hours D. Satisfaction scores
Answer
**Correct: B** **Why:** Completion measures attendance rather than learning. Reporting rate is often the more valuable metric than click rate, because a workforce that reports quickly shortens detection time even when someone does click.Question 14¶
Scenario: A business unit deploys a cloud service without security review.
A. Shut it down immediately B. Assess the risk, work with the unit to bring it into compliance, and address the process gap that let it happen unnoticed C. Report the unit D. Ignore it
Answer
**Correct: B** **Why:** Shadow IT usually signals that the sanctioned path is too slow, so punishing the symptom drives the behavior further underground. Fixing the intake process is what reduces recurrence.Question 15¶
Scenario: How should the security program's risk register be maintained?
A. Annually B. Continuously, with risks owned by named business owners, rated consistently, tracked to treatment decisions, and reviewed on a defined cadence C. Only after incidents D. By the security team alone
Answer
**Correct: B** **Why:** A register maintained by security alone becomes security's list of worries rather than the organization's risk position. Named business owners and a consistent rating method are what make it usable for decisions.Where to go deeper¶
- CISM cert page - notes, practice plan, strategy
- CISA practice questions - the audit counterpart
- CISSP practice questions - the broader security professional exam
- SOC 2 guide - a control framework managers are held to
- π ISACA CISM - official exam content outline