Management-focused information security certification covering governance, risk, programme management and incident response for the ISACA CISM exam.
Free sample questions
No account needed. Every question has a worked explanation, just like the full bank.
lock_openFree sampleInformation Security Programeasy
A retailer is building its first data classification scheme. The information security manager must decide what should drive the sensitivity level assigned to each information asset. Which factor should primarily determine the classification level?
- AThe potential business impact if the asset's confidentiality, integrity, or availability were compromisedcheck_circle Correct
- BThe storage format of the asset, such as whether it is held in a database, a spreadsheet, or a paper file
- CThe number of staff who currently request access to the asset during normal operations
- DThe age of the asset and how long it has been retained in the records management system
Information asset classification should be driven by the business impact of a loss of confidentiality, integrity, or availability. Classification expresses the worth of information to the organisation, and that worth is judged by the consequences to the business if the asset is disclosed, altered, or lost, which is why impact is the primary driver rather than format, demand, or age.
Why A is correct: Correct because classification reflects the value and sensitivity of the information, which is measured by the harm to the business if it were disclosed, altered, or made unavailable.
Why B is wrong: Tempting because storage format does affect some control choices, but format is a handling consideration that follows classification; it does not define how sensitive the information itself is.
Why C is wrong: Tempting because high demand can suggest importance, but access volume reflects operational convenience, not the inherent sensitivity that classification is meant to capture.
Why D is wrong: Tempting because retention schedules relate to data governance, but age alone does not set sensitivity; old records can be highly sensitive and new ones trivial.
lock_openFree sampleInformation Security Governancehard
Midway through the financial year, an unforeseen regulatory change forces the information security manager to fund an urgent data-protection project that was not in the approved budget. The annual security budget is already fully committed and the board has frozen requests for additional funds until the next cycle. Which action best reflects sound resource allocation in this situation?
- ADefer the regulatory project to the next budget cycle and formally document the resulting compliance exposure as an accepted risk.
- BRe-prioritise the existing portfolio and reallocate funds from lower-risk initiatives to the regulatory project after assessing the impact.check_circle Correct
- CReduce the scope of every active initiative by an equal percentage to free the funds the regulatory project needs.
- DFund the regulatory project from operational contingency without informing the board until the year-end budget review.
Under a frozen budget, sound resource allocation re-prioritises committed funds toward the highest risk based on an impact assessment. Resource management means continuously steering finite funds toward the greatest risk reduction. Reallocating from lower-risk initiatives, supported by an impact assessment, meets the regulatory obligation without breaching governance, whereas deferral accepts an avoidable breach, equal cuts ignore relative risk, and drawing contingency in secret bypasses board oversight.
Why A is wrong: Tempting because it respects the funding freeze and uses formal risk acceptance, but accepting a known regulatory breach when reallocation is possible is poor stewardship and the manager rarely has authority to accept that level of risk alone.
Why B is correct: Correct because re-prioritising within the committed budget directs scarce resources to the highest-risk obligation while a documented impact assessment keeps the deferred work visible, which is disciplined resource management under constraint.
Why C is wrong: Tempting because spreading the cut feels even-handed, but uniform reductions ignore the relative risk of each initiative and can weaken high-value controls, which is the opposite of risk-based allocation.
Why D is wrong: Tempting because contingency exists for surprises, but quietly drawing it down and bypassing governance for a material regulatory matter breaches transparency and undermines the board's oversight of the budget.
lock_openFree sampleInformation Security Programmedium
An information security manager is selecting metrics to report monthly to the board. Several candidate measures are proposed, including the number of firewall rule changes, the percentage of staff who completed security awareness training, the count of malware files quarantined, and the average time to deploy operating system patches. The board has asked for metrics that demonstrate whether the security programme is achieving its stated objectives. Which characteristic should most influence which measures are promoted to the board report?
- AWhether each measure links to a defined programme objective and supports a decision the recipient is positioned to makecheck_circle Correct
- BWhether each measure can be collected automatically from existing tools without additional manual effort by the security team
- CWhether each measure produces a number that has risen or fallen since the previous reporting period
- DWhether each measure is already tracked by peer organisations in the same industry sector
Board-level security metrics should be chosen for their link to programme objectives and their ability to support governance decisions, not for ease of collection or trend visibility. A metric earns its place in management reporting when it connects a measured value to a defined objective and enables the recipient to decide or act; measures that are merely easy to collect or that simply show movement do not support decision-making at board level.
Why A is correct: Board metrics must tie to objectives and inform governance decisions; relevance to the audience and to a stated outcome is what makes a measure worth reporting at that level.
Why B is wrong: Ease of automated collection is operationally convenient, but a measure that is cheap to gather still fails the board if it does not relate to a programme objective the board cares about.
Why C is wrong: A visible trend is tempting because movement looks like insight, but direction of change is meaningless if the underlying measure is not tied to an objective the board is accountable for.
Why D is wrong: Peer benchmarking has value for context, but copying a peer's measure does not guarantee it reflects this organisation's own programme objectives or supports its decisions.
More free CISM practice questions with worked answersFrequently asked questions
- How many questions are on the CISM exam?
- The Certified Information Security Manager (CISM) exam has 150 questions and runs for 240 minutes. The format is multiple choice, computer-based at psi testing centres or remote proctored.
- What score do I need to pass CISM?
- The pass mark is 450 / 800. Examworthy gives you a per-domain readiness score so you can see which domains are holding you back before you book.
- How much does the CISM exam cost?
- The exam costs 760 USD to sit. Practising on Examworthy is free to start, with a worked explanation on every question.
- Is there a CISM practice exam?
- Yes. Examworthy's exam mode runs a timed CISM practice exam (mock) paced to match the real exam, scored per domain so you can see exactly where you stand against the blueprint. Timed mocks are free with an account.
- How does Examworthy help me prepare for CISM?
- Every practice question carries a worked explanation and a per-distractor rationale, mapped to the official blueprint domains. You learn why each answer is right or wrong, not just the letter.
- Is Examworthy affiliated with ISACA?
- No. Examworthy is not affiliated with or endorsed by ISACA. Our questions are original, blueprint-aligned practice material; we never reproduce live exam items.
Examworthy is not affiliated with or endorsed by ISACA. All questions are original, blueprint-aligned practice material. We never reproduce live exam items. CISM and related marks belong to their respective owners.