CISM Exam Format and Time Management
The CISM exam is a computer-based, fixed-length test with 150 multiple-choice questions and four hours (240 minutes).
- ISACA describes scenario-oriented questions.
- The average available time is 96 seconds per question, including any review.
- The public format does not establish CAT, hands-on labs, or performance tasks, so candidates should practise management judgment in original multiple-choice scenarios.
On this page8 sections
The published CISM format
ISACA's 2026 Candidate Guide lists CISM as 150 multiple-choice questions in four hours, or 240 minutes. It is delivered as a computer-based exam at an authorized PSI test center or remotely where that option is available. The public exam description uses scenario-style questions. This is a fixed question count and time allotment; the official description does not identify CISM as a computerized adaptive test.
| Format detail | CISM information |
|---|---|
| Question count | 150 |
| Question type | Multiple choice; scenario-based reasoning is part of the public description |
| Time | Four hours, or 240 minutes |
| Average budget | 96 seconds per question if time is divided evenly |
| Delivery | Computer-based through authorized PSI center or remote proctoring where available |
| Adaptive behavior | No CAT format identified in the public official description |
| Practical lab | No hands-on lab or performance task identified in the public format |
The 96-second figure is arithmetic: 240 minutes divided by 150 questions. It is not an official per-question time limit. Some questions are quick, while a dense scenario can take longer. A workable pacing plan uses the average as a checkpoint and reserves enough time for marked items, not as a command to stop reading at the 96-second mark.
What a scenario question asks you to do
CISM questions assess management judgment across security governance, risk management, program management, and incident management. A scenario may describe a business objective, a control gap, competing stakeholder priorities, or an event in progress. The task is to identify the best management action given the facts and the qualifier in the question. It is not necessarily asking what a technician can do immediately.
Read the last sentence first to identify the requested decision. Words such as first, best, most important, primary, and next change the answer. Then identify the actor: a business owner, security manager, incident lead, executive, or board. Ask which authority and responsibility belong to that actor. Finally, eliminate options that skip risk ownership, violate an approved process, make unsupported assumptions, or jump to a tool before understanding the business need.
For example, a vendor reports a potential breach in a service that stores company data. The security manager does not know whether customer records were accessed. The most defensible action is to activate the organization's incident and vendor escalation processes, establish facts with the response team, preserve evidence, and coordinate communication under assigned authority. An answer that immediately declares a data breach or terminates the contract outruns the known facts.
A reliable approach to each question
- Identify the command word and the exact decision requested.
- Name the management objective: reduce risk, align security to business priorities, maintain accountability, respond safely, or improve the program.
- Separate facts from assumptions. Do not invent a regulator deadline, incident scope, or approved risk decision that the scenario does not provide.
- Locate the accountable owner and the security manager's role. Security advises and coordinates; the business owner or delegated executive accepts business risk.
- Choose the option that addresses the cause or next decision at the right level, then check whether it solves the stated problem without skipping a required step.
This method is especially useful when several answers sound technically plausible. A vulnerability scan, awareness campaign, policy update, and new monitoring tool may all help in some situation. The prompt's risk, authority, and timing determine which one is appropriate now. CISM tests selection and sequence as much as technical familiarity.
Time management across 150 questions
Use a simple checkpoint schedule. At 60 minutes, aim to have completed roughly 38 questions; at 120 minutes, about 75; at 180 minutes, about 112; and reserve the final hour for the remaining questions and review. These are approximate landmarks based on average pace, not instructions from ISACA. If you spend more time on early items, note whether you are resolving genuine uncertainty or rereading without a decision.
| Elapsed time | Approximate completed | Purpose |
|---|---|---|
| 1 hour | 38 questions | Check that reading pace is sustainable |
| 2 hours | 75 questions | Halfway checkpoint; adjust if far behind |
| 3 hours | 112 questions | Protect enough time to finish the full set |
| 4 hours | 150 questions | Finish and use remaining time for review if available |
If the testing interface allows marking or flagging, use it for a question where you can eliminate options but need a second look. Do not use a mark as a reason to leave every difficult question unanswered. Make the best supported selection, then move on. A return pass can revisit marked items after you have answered the rest. Follow the current candidate guide and on-screen rules for navigation, breaks, and submitting responses.
Avoid spending several minutes trying to prove an answer with information the question does not provide. If two options remain, compare them against the decision level and qualifier. Does one establish ownership or risk criteria while the other jumps directly to a control? Does one preserve incident facts and approved communications while the other asserts an unverified conclusion? Make the judgment and continue.
Original worked example: choosing the right first action
A business unit wants to deploy a new customer portal in two weeks. The risk review finds that sensitive data may be retained longer than intended. The project sponsor asks the CISM to approve launch. What is the best next step? A. Approve the launch because the portal passed functional testing. B. Ask the business risk owner to evaluate the documented exposure against approved criteria and decide on treatment before release. C. Buy additional storage encryption and approve launch without a risk decision. D. Move the launch date automatically by six months.
Best answer: B. The scenario presents a risk and asks for the next management decision. Functional testing does not resolve a retention risk. Encryption may protect confidentiality but does not determine lawful or appropriate retention. An arbitrary six-month delay is not a risk treatment analysis. The security manager should make the issue clear, ensure the accountable owner considers the exposure under approved criteria, and verify that required treatment and release controls are decided.
Breaks and delivery rules
The candidate guide governs whether breaks are allowed, how to request them, and whether the exam clock continues. Do not assume that an informal pause stops the timer. The center and remote testing environments also have different operational requirements. Before booking, read the current guide and the appointment confirmation for identification, prohibited items, check-in, room, and device rules.
For remote proctoring, run the official compatibility check on the machine and network you plan to use. A quiet, compliant room and stable connection reduce preventable disruption. For a test center, plan travel and arrival time, and verify the location in the provider confirmation. In either case, an account-name mismatch or late arrival can affect your appointment and registration fee.
Match your practice to the outline date
The revised CISM outline takes effect for appointments on or after November 3, 2026. Question mechanics remain 150 multiple-choice questions and four hours in the Candidate Guide. The new outline changes domain weighting slightly and revises task statements. Use scenarios aligned to the version for your appointment. A change in outline does not turn the test into a different question format, but it can change which management tasks are emphasized.
Practice sets should help you explain why an answer is best and why each distractor fails. If you only score questions and move on, you will not find recurring reasoning errors. Label each miss: content gap, misunderstood qualifier, wrong stakeholder, premature control selection, or assumption unsupported by the facts. Review a short set after studying the concept, then return later with mixed-domain questions.
Common format misconceptions
- The four hours are total exam time for 150 questions; the 96-second average is a planning calculation, not a per-item deadline.
- The official description confirms multiple-choice questions and scenario reasoning. It does not establish CAT, a live lab, or a performance simulation.
- Do not assume every question is equally long or that a scenario uses a fixed number of questions unless the official guide says so.
- A strong practice percentage is useful feedback, not a guaranteed exam result or official score conversion.
- Break, navigation, and review mechanics should be taken from the current candidate guide and on-screen instructions.
A good format strategy is simple: learn the current domain tasks, practise choosing management actions in original scenarios, and maintain a steady pace. Read carefully enough to notice the requested action and authority, but avoid spending time on imagined facts. The exam rewards a supported decision within the situation presented.
Common questions
How many questions are on the CISM exam?
The 2026 ISACA Candidate Guide lists 150 multiple-choice questions.
How long is the CISM exam?
The exam lasts four hours, or 240 minutes. Dividing by 150 gives an average of 96 seconds per question, but that is only a pacing calculation.
Is CISM a CAT exam?
The public ISACA format describes a fixed 150-question exam and does not identify CISM as computerized adaptive testing.
Does the CISM exam have hands-on labs?
The published CISM format identifies multiple-choice questions. It does not identify hands-on labs or performance tasks.
What question types should I practise?
Practise original management scenarios that ask for the best first, next, or most appropriate action across governance, risk, program management, and incidents.