CISM Practice Questions with Explanations
Use scenario questions to practise selecting the best management action, not just recalling a control.
- These four original CISM-style items cover governance, risk, the security program, and incident management.
- Each includes the answer and explains why the alternatives are weaker.
- They are study examples, not ISACA exam questions or a score predictor.
On this page8 sections
How to use these practice items
Read each scenario and select one answer before looking at the explanation. Notice the requested action and any qualifier such as first, best, or most appropriate. Then identify the accountable role and the business or security objective. CISM evaluates management decisions across four domains; a technically useful action may still be premature or outside the actor's authority.
These questions are original examples written for practice. They are not taken from, reconstructed from, or endorsed as items from ISACA's secured exam. The real exam has 150 multiple-choice questions in four hours. These examples do not reproduce its full length or its scaled scoring. For a practice set, explain every distractor and revisit the concepts that caused uncertainty.
Question 1: risk ownership
A product team wants to launch a customer analytics service. A review identifies that the service will retain personal information beyond the period currently stated in policy. The product executive says the added data could improve customer retention and asks the security manager to approve the exception. What should the security manager do first?
- Approve the exception because the product executive owns the business objective.
- Ensure the exposure and treatment options are assessed against organizational criteria and presented to the authorized risk owner for a documented decision.
- Disable analytics for all customers immediately.
- Add encryption and approve the exception without further review.
Correct answer: B. The security manager should ensure that the risk is understood and handled by the person with delegated authority, using the organization's criteria. The facts do not establish the exact legal or business impact, so assessment and a documented decision are necessary.
Why A is weaker: the product executive may own the objective but may not have authority to accept the security or privacy risk. Ownership and risk authority should be explicit. Why C is weaker: disabling the service may be a possible treatment, but the scenario does not establish that immediate shutdown is proportionate or required. Why D is weaker: encryption may reduce one exposure, but it does not resolve excessive retention or substitute for a risk decision.
The management principle is that risk acceptance belongs to an authorized owner. The CISM supports the decision by clarifying the scenario, options, and residual risk. A control can be part of treatment, but it should not be used to bypass governance or an unresolved policy exception.
Question 2: measuring a security program
A security awareness program reports that 98 percent of employees completed required training. Over the same period, incidents involving accidental sharing of restricted files increased. Senior management asks whether the program is meeting its objective. What is the best next action?
- Report the completion figure as proof that the objective has been achieved.
- Investigate the incident trend, relate the measures to the objective, and recommend adjustments based on the evidence.
- Replace the awareness platform immediately.
- Stop reporting training data because it is not a security measure.
Correct answer: B. The completion rate is an activity measure, while the incident trend is an outcome signal. Management should understand whether the program changes behavior, identify causes, and adjust controls or training based on evidence. Useful performance reporting connects indicators to the desired result and gives leaders a decision to make.
Why A is weaker: completion alone does not demonstrate that restricted information is handled safely. Why C is weaker: the platform may be functioning as designed; the cause could be confusing policy, poor access controls, workload, or other behavior. Replacing it before analysis is premature. Why D is weaker: training data may still be useful when interpreted with other measures; the problem is treating a single activity count as proof of effectiveness.
The principle is to measure program outcomes and use results for improvement. A metric should have a defined audience and purpose. If management sees only completion, it may fund the wrong intervention. If the cause is unclear, additional investigation should precede a broad technology purchase.
Question 3: governance and accountability
A growing company has security policies written by the technology team, but business units routinely approve exceptions without a risk assessment. The board receives no summary of significant exceptions. What should the CISM recommend as the most important governance improvement?
- Give the security team authority to reject every exception without consulting business leaders.
- Establish approval authority, risk criteria, documentation, and oversight reporting for exceptions.
- Replace written policies with a technical standard.
- Approve all current exceptions retroactively to avoid disruption.
Correct answer: B. The organization needs a consistent decision framework: who may approve an exception, what risk information is required, how the decision is recorded, and how significant exceptions are overseen. This restores accountability and gives the board visibility appropriate to its role.
Why A is weaker: the security function should advise and operate controls, but blanket veto authority may not reflect the organization's governance model or delegated decision rights. Why C is weaker: a technical standard can specify requirements but does not resolve who accepts exceptions or how the board exercises oversight. Why D is weaker: retroactive approval without assessment preserves the control failure and obscures accountability.
The principle is that governance connects policies to authority and oversight. Senior management and business owners retain responsibilities for business choices, while security provides expertise, monitoring, and escalation. A good process also makes exceptions visible and time-bound when appropriate.
Question 4: incident response and communication
A cloud provider tells the security manager that it detected unusual access to a production system. The provider has not determined whether customer information was accessed. A communications executive wants to send a notice saying that customer records were stolen. What should the security manager do first?
- Send the statement immediately to demonstrate transparency.
- Activate the established incident and provider escalation process, establish verified facts, preserve evidence, and coordinate communications through authorized roles.
- Wait for the provider to finish its full investigation before notifying anyone internally.
- Terminate the provider contract before gathering more information.
Correct answer: B. The organization should use its incident plan, obtain reliable facts, preserve evidence, and coordinate accurate communications with the assigned decision makers. The response should move promptly, but it should not claim a confirmed theft when that fact is unknown.
Why A is weaker: transparency does not justify stating an unverified conclusion. Applicable notification duties should be assessed with the right internal and legal stakeholders. Why C is weaker: internal escalation and response should begin now; waiting for a complete provider investigation can delay containment and coordination. Why D is weaker: termination may be considered later, but it does not contain the immediate incident or establish what happened.
The principle is to coordinate, verify, preserve, and communicate within established authority. A response leader should not wait for perfect certainty to escalate, but external statements should reflect known facts and applicable obligations.
Question 5: selecting a program priority
An organization has budget for one major security initiative this quarter. A risk assessment identifies two options: improve recovery testing for a critical revenue service, or replace a low-risk internal tool with a newer product. The business impact analysis shows that prolonged service outage would prevent order processing. What is the best basis for prioritizing the work?
- Choose the newer product because current technology is usually more secure.
- Prioritize the initiative that reduces the most significant exposure against business objectives and risk criteria, with the accountable owners involved.
- Split the budget evenly even if neither initiative can be completed.
- Let the security team decide without reviewing business impact.
Correct answer: B. Program resources should follow risk and business impact. The critical service's recovery exposure is connected to revenue and a documented impact analysis. The decision should use organizational criteria and involve owners. The newer product may be useful, but age alone does not establish priority.
Why A is weaker: newness is not a risk analysis. Why C is weaker: dividing resources can leave both projects ineffective. Why D is weaker: security contributes expertise, but business priorities and risk ownership belong in the decision. This is a program management problem as well as a resilience concern.
Review patterns across the answers
The examples share several habits. Clarify who has authority. Use risk criteria rather than instinct. Distinguish measures of activity from evidence of outcomes. Establish facts before making incident claims. Allocate security resources according to business impact and program objectives. These habits help candidates choose between answers that appear reasonable at first glance.
When reviewing a practice set, ask why each distractor is tempting. It may describe a control that is useful but premature, place a decision with the wrong owner, skip an assessment, or overstate the facts. Naming the error makes it easier to recognize in a different scenario. Do not memorize that a certain verb always indicates the correct answer; the context determines the best response.
Build a deliberate question routine
- Answer a question before checking the key, and record your confidence separately from correctness.
- Underline the qualifier and identify the role expected to act.
- For every wrong or guessed item, explain the governing concept and each distractor.
- Map the item to an official task statement and note the appointment-date outline version.
- Revisit missed concepts with fresh questions after a delay.
- Use a timed mixed set to practise pacing, but do not convert its percentage into an official scaled score.
ISACA's free practice quiz can introduce the style, and its paid preparation options include question-and-explanation resources. Review the live product terms for current contents and access duration. A short quiz is not a 150-question mock. Avoid exam dumps or recalled items: they are not a reliable way to learn and may conflict with exam rules.
The exam's passing score is 450 on a 200-to-800 scale. This practice article does not assign a pass threshold to the five examples. Five questions cannot measure broad competence, and a practice percentage has no official conversion. Use the explanations to improve your decisions and use a sufficiently broad, current practice resource for readiness feedback.
Common questions
Are these official CISM exam questions?
No. They are original study examples, not ISACA exam items and not reconstructions of protected questions.
How should I review a CISM practice question?
Explain why the best answer fits the scenario and why every alternative is less appropriate. Note whether a miss involved content, authority, sequence, risk, or a misread qualifier.
Does a practice test percentage predict my CISM score?
No. Practice scores are specific to the question set and are not converted to ISACA's 200-to-800 scale.
Does ISACA offer free CISM practice questions?
ISACA lists a free CISM Practice Quiz. It is a limited quiz rather than a full-length mock exam.
What should CISM practice questions test?
They should test management judgment across governance, risk, security program management, and incident response using new scenarios and complete explanations.