ISACA free practice

Free CISM practice questions

12 real CISM sample questions, each with a worked explanation and a rationale for every option, right and wrong. No account, no card. This is the reasoning the CISM tests: knowing why the tempting answer is wrong, not just spotting the right one.

The real CISM is 150 questions in 240 minutes, pass mark 450 / 800. For a domain-by-domain breakdown and a study plan, read the CISM study guide. The full bank has 298 questions.

Information Security Program (33% of the exam)

Free sampleInformation Security Programeasy

A retailer is building its first data classification scheme. The information security manager must decide what should drive the sensitivity level assigned to each information asset. Which factor should primarily determine the classification level?

  • AThe potential business impact if the asset's confidentiality, integrity, or availability were compromised Correct
  • BThe storage format of the asset, such as whether it is held in a database, a spreadsheet, or a paper file
  • CThe number of staff who currently request access to the asset during normal operations
  • DThe age of the asset and how long it has been retained in the records management system
Information asset classification should be driven by the business impact of a loss of confidentiality, integrity, or availability. Classification expresses the worth of information to the organisation, and that worth is judged by the consequences to the business if the asset is disclosed, altered, or lost, which is why impact is the primary driver rather than format, demand, or age.

Why A is correct: Correct because classification reflects the value and sensitivity of the information, which is measured by the harm to the business if it were disclosed, altered, or made unavailable.

Why B is wrong: Tempting because storage format does affect some control choices, but format is a handling consideration that follows classification; it does not define how sensitive the information itself is.

Why C is wrong: Tempting because high demand can suggest importance, but access volume reflects operational convenience, not the inherent sensitivity that classification is meant to capture.

Why D is wrong: Tempting because retention schedules relate to data governance, but age alone does not set sensitivity; old records can be highly sensitive and new ones trivial.

Free sampleInformation Security Programhard

A strategic outsourcing provider that runs the organisation's order-processing platform notifies the organisation that it intends to exit the market and wind down operations within six months. The board asks the information security manager what protects the organisation from a disorderly handover. Which prior arrangement is the manager most likely to rely on?

  • AThe cyber insurance policy the organisation purchased to cover losses from supplier-related incidents
  • BThe provider's published business continuity plan describing how it restores its own services after disruption
  • CThe exit and transition clause in the contract, setting out data return, transition assistance and knowledge transfer obligations Correct
  • DThe non-disclosure agreement that bound the provider to protect the organisation's confidential information
Recognise that a contractual exit and transition clause protects the organisation against a disorderly handover when a strategic provider leaves the engagement. Provider exit is a foreseeable supply-chain risk, so the organisation manages it in advance through an exit and transition clause that compels data return, migration support and knowledge transfer. This is what keeps the service recoverable when the provider winds down, which insurance, confidentiality terms or the provider's own continuity plan do not achieve.

Why A is wrong: Tempting because insurance offsets some financial loss, but a policy pays out after harm occurs and does nothing to keep the service running or to return the organisation's data and processes in usable form during the wind-down.

Why B is wrong: Tempting because continuity planning sounds relevant, but the provider's plan covers recovering its operations, not an orderly handover to the organisation when the provider deliberately leaves the market.

Why C is correct: Correct: a negotiated exit and transition provision obliges the departing provider to return data in a usable form, support migration and transfer knowledge, which is precisely the prior arrangement that prevents a disorderly handover when a provider exits.

Why D is wrong: Tempting because confidentiality remains important during a transition, but a non-disclosure agreement only restricts disclosure of information and does not compel the provider to hand back data or assist migration, so it does not secure the handover.

Free sampleInformation Security Programmedium

An information security manager is selecting metrics to report monthly to the board. Several candidate measures are proposed, including the number of firewall rule changes, the percentage of staff who completed security awareness training, the count of malware files quarantined, and the average time to deploy operating system patches. The board has asked for metrics that demonstrate whether the security programme is achieving its stated objectives. Which characteristic should most influence which measures are promoted to the board report?

  • AWhether each measure links to a defined programme objective and supports a decision the recipient is positioned to make Correct
  • BWhether each measure can be collected automatically from existing tools without additional manual effort by the security team
  • CWhether each measure produces a number that has risen or fallen since the previous reporting period
  • DWhether each measure is already tracked by peer organisations in the same industry sector
Board-level security metrics should be chosen for their link to programme objectives and their ability to support governance decisions, not for ease of collection or trend visibility. A metric earns its place in management reporting when it connects a measured value to a defined objective and enables the recipient to decide or act; measures that are merely easy to collect or that simply show movement do not support decision-making at board level.

Why A is correct: Board metrics must tie to objectives and inform governance decisions; relevance to the audience and to a stated outcome is what makes a measure worth reporting at that level.

Why B is wrong: Ease of automated collection is operationally convenient, but a measure that is cheap to gather still fails the board if it does not relate to a programme objective the board cares about.

Why C is wrong: A visible trend is tempting because movement looks like insight, but direction of change is meaningless if the underlying measure is not tied to an objective the board is accountable for.

Why D is wrong: Peer benchmarking has value for context, but copying a peer's measure does not guarantee it reflects this organisation's own programme objectives or supports its decisions.

Incident Management (30% of the exam)

Free sampleIncident Managementmedium

An organisation operating in a jurisdiction with a mandatory data breach notification regime has confirmed that personal data has been exfiltrated and that the breach is likely to result in serious harm to affected individuals. The information security manager is deciding what most strongly determines the deadline by which the supervisory authority must be notified. Which factor is the primary driver of that deadline?

  • AThe date on which technical containment of the affected systems was fully completed by the response team.
  • BThe point at which the organisation became aware, or reasonably should have become aware, that a notifiable breach had occurred. Correct
  • CThe date on which the board of directors formally reviews and signs off the incident response report.
  • DThe date on which the organisation finishes calculating the total financial cost of the incident for insurance purposes.
Mandatory breach notification deadlines to regulators are generally driven by when the organisation became aware of a notifiable breach. Statutory breach regimes set notification timeframes running from the organisation's knowledge, or reasonable means of knowledge, of a notifiable breach; awareness, not containment or internal governance, is what triggers and bounds the regulatory clock.

Why A is wrong: Tempting because containment is an important operational milestone, but notification obligations are tied to awareness of the breach rather than to completing technical remediation, which may come much later.

Why B is correct: Correct because mandatory breach regimes generally start the regulatory notification clock from the organisation's awareness of a notifiable breach, making the date of awareness the key driver of the statutory deadline.

Why C is wrong: Tempting because senior approval feels procedurally necessary, but a board review schedule is internal and cannot lawfully delay a statutory notification deadline driven by awareness.

Why D is wrong: Tempting because insurers and cost data matter for recovery, but financial quantification is unrelated to the regulatory deadline, which is anchored to awareness of a notifiable breach.

Free sampleIncident Managementhard

A retailer's BIA must decide which processes are critical so recovery investment can be focused. One business unit insists its month-end reporting process is critical because executives value the reports highly. On what basis should the security manager judge whether a process is genuinely critical for recovery prioritisation?

  • AOn how strongly the process's owners and executive sponsors regard it, since perceived importance reflects the value the business places on the process.
  • BOn the volume of data the process holds and the number of integrations it has, since the most connected and data-rich processes are the hardest to restore.
  • COn how much the process costs to operate each year, since the most expensive processes represent the greatest investment to protect and recover first.
  • DOn how quickly and severely disruption to the process would harm the organisation, measured against agreed impact criteria such as financial loss and regulatory breach. Correct
Judge process criticality by the speed and severity of disruption impact against agreed criteria, not by stakeholder sentiment, complexity, or operating cost. Recovery prioritisation requires an objective and consistent basis, so criticality is assessed by how fast and how badly an outage would damage the organisation, scored against shared impact criteria such as financial, operational, legal, and reputational harm. This keeps prioritisation defensible and prevents louder stakeholders or technical complexity from distorting where recovery resources are placed.

Why A is wrong: Tempting because owner sentiment is easy to gather, but stakeholder enthusiasm is subjective and unevenly expressed; criticality must rest on the demonstrable impact of disruption, not on how strongly a process is valued.

Why B is wrong: Tempting because complex, integrated processes are harder to recover, but technical complexity describes recovery effort, not business criticality; a simple process can be critical and a complex one non-critical.

Why C is wrong: Tempting because cost feels like a proxy for importance, but operating spend reflects running cost, not the impact of an outage; a cheap process can be business-critical and an expensive one merely convenient.

Why D is correct: Correct: criticality is determined by the speed and severity of harm a disruption causes, assessed against consistent impact criteria, which lets processes be ranked objectively for recovery prioritisation.

Free sampleIncident Managementhard

Following containment of a credential-theft incident, an investigation confirms that an attacker exploited an unpatched application server to plant a persistent backdoor and harvest service-account passwords. The information security manager is now planning the eradication phase. Which action should be completed first to ensure eradication actually removes the threat rather than merely the symptoms?

  • ARestore the affected application server from the most recent pre-incident backup so that operations can resume on a known-good build
  • BIdentify and remove the underlying vulnerability and all attacker artefacts, confirming the root cause so the same entry point cannot be reused Correct
  • CRotate the harvested service-account passwords and re-enable the accounts so dependent services can continue to authenticate
  • DRe-image every workstation on the same network segment to be certain no lateral-movement footholds remain on user endpoints
Eradication must remove the confirmed root cause and all attacker artefacts before recovery begins, or the threat will recur. Eradication is the phase where the underlying cause and every malicious artefact are eliminated; if recovery proceeds before the root cause is removed, the restored systems inherit the same exploitable weakness and any persistence the attacker established, allowing reinfection.

Why A is wrong: Restoring from backup is a recovery activity, and doing it before the root cause is addressed risks reinstating the same unpatched vulnerability and any compromised data captured in the backup, so it is tempting as a fast route to availability but premature.

Why B is correct: Eradication must address the root cause and remove every attacker artefact, including the backdoor and the exploited weakness, otherwise the threat can re-establish itself; confirming the root cause first is the correct foundation before recovery.

Why C is wrong: Rotating credentials is a necessary eradication step, but doing it before the backdoor and vulnerability are removed leaves the persistence mechanism intact, so the attacker can simply harvest the new credentials again, making this a partial fix that feels decisive but is incomplete.

Why D is wrong: Wholesale re-imaging of unaffected endpoints is disproportionate when the investigation has scoped the compromise to the application server, so it consumes effort and downtime without confirming the root cause, making it a tempting but misdirected over-reaction.

Information Security Risk Management (20% of the exam)

Free sampleInformation Security Risk Managementhard

An information security manager is preparing a risk assessment for a newly launched product that has no internal incident history, no comparable industry loss data and a fast-changing threat landscape. The board wants a defensible prioritisation of risks within two weeks. Which analysis approach should the manager adopt first, and why?

  • AA quantitative analysis, because expressing every risk in annual loss expectancy gives the board the precise monetary ranking it expects.
  • BA quantitative Monte Carlo simulation, because modelling thousands of loss iterations compensates for the absence of historical data.
  • CA qualitative analysis, because expert-judgement ratings of likelihood and impact can prioritise risks quickly when reliable loss frequency data is unavailable. Correct
  • DA deferral of any analysis, because no prioritisation can be defended until at least twelve months of incident data has accumulated.
Select qualitative analysis when reliable frequency and loss data are absent and a rapid, defensible prioritisation of risks is required. Quantitative methods depend on credible occurrence and impact data to avoid false precision, so when such data is unavailable and time is short, structured qualitative ratings of likelihood and impact give a defensible first-pass prioritisation that can be refined quantitatively as data matures.

Why A is wrong: This is tempting because monetary figures look authoritative, but without occurrence and loss data the annual loss expectancy values would rest on guessed inputs, producing false precision rather than a defensible ranking.

Why B is wrong: Monte Carlo simulation still needs credible input distributions drawn from data or calibrated estimates; running it on unfounded assumptions multiplies uncertainty rather than removing it, and it is unlikely to be defensible in two weeks.

Why C is correct: With no historical or industry frequency data and a short deadline, qualitative analysis lets subject-matter experts rank scenarios using structured likelihood and impact scales, which is the appropriate first step when the inputs for credible quantification do not yet exist.

Why D is wrong: Waiting for data leaves the new product unmanaged during its most exposed period; the manager can and should prioritise risks now using qualitative methods rather than declining to assess at all.

Free sampleInformation Security Risk Managementmedium

A healthcare provider has accelerated adoption of an unfamiliar generative artificial intelligence platform across clinical teams, creating attack vectors the security programme has not previously assessed. The information security manager wants to keep the organisation's view of the threat landscape current as this technology spreads. Which approach is most effective for maintaining an accurate view of the evolving threat landscape?

  • AMandate that all generative artificial intelligence use cease until a full control framework has been documented
  • BSchedule a one-off penetration test of the generative artificial intelligence platform and treat the findings as definitive
  • CEstablish continuous monitoring of relevant threat intelligence sources and periodically reassess the associated attack vectors Correct
  • DRely on the platform vendor's published security assurances and review them when the contract is renewed
An accurate, current view of an evolving threat landscape comes from continuous intelligence monitoring plus periodic reassessment of attack vectors, not one-off events. The threat landscape around a fast-spreading technology shifts continuously, so a point-in-time test, a vendor attestation, or an outright ban cannot keep the organisation's understanding current. Ongoing monitoring of intelligence sources paired with periodic reassessment of the associated attack vectors keeps risk decisions aligned with reality.

Why A is wrong: A blanket ban appears to remove the exposure, but it drives the technology underground, ignores business need, and does nothing to keep the organisation's threat understanding current.

Why B is wrong: A penetration test surfaces real weaknesses and feels concrete, but a single point-in-time test cannot track a threat landscape that shifts as the technology and its attack vectors evolve.

Why C is correct: Continuous monitoring of threat intelligence combined with periodic reassessment of attack vectors keeps the organisation's view current as new risks from the technology emerge.

Why D is wrong: Vendor assurances offer some comfort and reduce effort, but they reflect the supplier's interests and a renewal cycle is far too slow to track a rapidly changing threat landscape.

Free sampleInformation Security Risk Managementhard

An information security manager is quantifying the annual loss expectancy for a customer database exposed to ransomware. The asset is valued at 4,000,000 pounds, the exposure factor for a successful ransomware event is estimated at 25 per cent, and historical and threat-intelligence data suggest such an event is likely twice per year. What is the annual loss expectancy that should be reported to support the business case for additional controls?

  • A1,000,000 pounds, calculated as the asset value multiplied by the exposure factor for a single occurrence.
  • B2,000,000 pounds, calculated as the single loss expectancy multiplied by the annualised rate of occurrence. Correct
  • C8,000,000 pounds, calculated as the asset value multiplied by the annualised rate of occurrence.
  • D500,000 pounds, calculated as the single loss expectancy divided by the annualised rate of occurrence.
Compute annual loss expectancy as single loss expectancy multiplied by the annualised rate of occurrence, where single loss expectancy is asset value times exposure factor. Annual loss expectancy expresses the expected yearly cost of a risk by chaining two steps: single loss expectancy captures the loss from one event as asset value times exposure factor, then the annualised rate of occurrence scales that single-event loss to the frequency expected over a year.

Why A is wrong: This is the single loss expectancy, not the annual loss expectancy; it ignores the annualised rate of occurrence of two events per year, so it understates the expected yearly loss.

Why B is correct: Single loss expectancy is 4,000,000 multiplied by 0.25, giving 1,000,000, and annual loss expectancy is the single loss expectancy multiplied by the annualised rate of occurrence of two, giving 2,000,000, which is the correct expected annual loss.

Why C is wrong: This multiplies the full asset value by the rate of occurrence and omits the exposure factor, which treats every event as a total loss of the asset and badly overstates the annual loss expectancy.

Why D is wrong: Dividing rather than multiplying by the rate of occurrence inverts the relationship; a higher event frequency must raise, not lower, the annual loss expectancy, so this is wrong.

Information Security Governance (17% of the exam)

Free sampleInformation Security Governancehard

Midway through the financial year, an unforeseen regulatory change forces the information security manager to fund an urgent data-protection project that was not in the approved budget. The annual security budget is already fully committed and the board has frozen requests for additional funds until the next cycle. Which action best reflects sound resource allocation in this situation?

  • ADefer the regulatory project to the next budget cycle and formally document the resulting compliance exposure as an accepted risk.
  • BRe-prioritise the existing portfolio and reallocate funds from lower-risk initiatives to the regulatory project after assessing the impact. Correct
  • CReduce the scope of every active initiative by an equal percentage to free the funds the regulatory project needs.
  • DFund the regulatory project from operational contingency without informing the board until the year-end budget review.
Under a frozen budget, sound resource allocation re-prioritises committed funds toward the highest risk based on an impact assessment. Resource management means continuously steering finite funds toward the greatest risk reduction. Reallocating from lower-risk initiatives, supported by an impact assessment, meets the regulatory obligation without breaching governance, whereas deferral accepts an avoidable breach, equal cuts ignore relative risk, and drawing contingency in secret bypasses board oversight.

Why A is wrong: Tempting because it respects the funding freeze and uses formal risk acceptance, but accepting a known regulatory breach when reallocation is possible is poor stewardship and the manager rarely has authority to accept that level of risk alone.

Why B is correct: Correct because re-prioritising within the committed budget directs scarce resources to the highest-risk obligation while a documented impact assessment keeps the deferred work visible, which is disciplined resource management under constraint.

Why C is wrong: Tempting because spreading the cut feels even-handed, but uniform reductions ignore the relative risk of each initiative and can weaken high-value controls, which is the opposite of risk-based allocation.

Why D is wrong: Tempting because contingency exists for surprises, but quietly drawing it down and bypassing governance for a material regulatory matter breaches transparency and undermines the board's oversight of the budget.

Free sampleInformation Security Governancemedium

A retailer expanding into several jurisdictions wants a single framework to organise its security programme around outcomes, profile its current versus target state, and communicate risk posture to non-technical executives without committing to a certifiable audit regime. Which framework most directly meets these stated needs?

  • AISO/IEC 27001, because certification gives executives an externally verified statement of security posture.
  • BCOBIT, because its maturity and capability levels are the only way to express current versus target state.
  • CISO/IEC 27005, because it provides the risk management process needed to brief executives on posture.
  • DThe NIST Cybersecurity Framework, because its functions and tiers let the organisation profile current and target states and communicate posture in business terms. Correct
Match a framework to stated needs by recognising that the NIST CSF supports outcome profiles and executive communication without mandating certification. The NIST CSF organises security around functions and uses profiles and tiers to compare current and target states, giving a business-readable view of posture that does not depend on an audited certification.

Why A is wrong: Certification is attractive to executives, but the retailer explicitly does not want a certifiable audit regime, and ISO/IEC 27001 centres on a management system rather than current-versus-target outcome profiling.

Why B is wrong: COBIT does offer capability levels, but the absolute claim that it is the only way to express state is false, and its focus is enterprise governance rather than the outcome profiling and executive risk communication the retailer described.

Why C is wrong: ISO/IEC 27005 guides information security risk management, which is relevant to risk briefings, but it is a risk process standard, not a programme-wide framework offering current and target profiling of outcomes.

Why D is correct: The NIST CSF is built around outcome-based functions and supports current and target profiles plus implementation tiers, which lets the programme show posture to executives without requiring certification.

Free sampleInformation Security Governancehard

An information security manager has built a business case to renew an annual threat-intelligence subscription. The case states that the service helped block several attacks last year and that competitors all subscribe to similar services. The investment committee rejects the case as unconvincing. Which improvement would most strengthen the case for the next submission?

  • AQuantify the risk the service reduces and express the expected benefit relative to its cost in measurable terms. Correct
  • BAdd detailed technical specifications of the threat-intelligence feeds and the integrations the service supports.
  • CEmphasise that staying current with competitor practice avoids reputational damage from being seen as a laggard.
  • DSecure a multi-year contract that lowers the headline annual price through a volume discount commitment.
A persuasive security business case quantifies the risk reduced and expresses benefit relative to cost in measurable terms. Investment committees fund security when the benefit, expressed as quantified risk reduction set against cost, is demonstrable. Anecdotes of blocked attacks and peer-parity arguments lack measurable value, which is why the case failed; quantifying the risk reduction and the benefit-to-cost relationship supplies the evidence the committee needs to approve the spend.

Why A is correct: Correct because tying the spend to a quantified reduction in risk and a measurable benefit-to-cost relationship gives the committee the value-versus-cost evidence a business case exists to provide, addressing why the case was rejected.

Why B is wrong: Tempting because technical depth signals rigour, but a committee evaluates value and risk, not feed formats, so more specifications address a question the committee did not ask and do not justify the spend.

Why C is wrong: Tempting because peer pressure can move a committee, but a herd argument is the weakness that contributed to the rejection and offers no organisation-specific evidence of value or risk reduction.

Why D is wrong: Tempting because a lower price improves affordability, but reducing cost does not demonstrate that the service delivers value, so a cheaper subscription with an unproven benefit is still an unjustified case.

Want the full bank?

298 CISM questions, every one with a worked explanation and a per-option rationale. No sign-up to start.

Practise CISM free

Frequently asked questions

Are these CISM practice questions free?

Yes. Every CISM question on this page is free to read with no sign-up, and each one carries a worked explanation and a rationale for every option. The full bank of 298 questions is on Examworthy.

Do the questions explain why the wrong answers are wrong?

Yes, and that is the point. Each option, correct or not, has its own rationale, so you learn to rule out the tempting wrong answer, not just recognise the right one. That is the reasoning the CISM tests.

Are these real CISM exam questions?

No. These are original, blueprint-aligned practice questions written to the public ISACA content outline. We never reproduce live exam items. They mirror the format and difficulty of the real exam.

How many questions are on the real CISM?

The CISM is 150 questions in 240 minutes, with a pass mark of 450 / 800. For the full domain-by-domain breakdown and a study plan, read the study guide.

Examworthy is not affiliated with or endorsed by ISACA. All questions are original, blueprint-aligned practice material. We never reproduce live exam items. CISM and related marks belong to their respective owners.