CISM Practice Test
159 free CISM practice questions with answers and explanations.
No signup required.
The CISM exam is administered by ISACA, with 150 scored questions and a time limit of 4 hours.
About these practice questions
These are original study questions written from published exam objectives—not recalled, copied, or confidential live-exam items. Always confirm current coverage with the official sources linked on this page.
Browse all questions & answers
Loading the remaining 59 questions…
Information Security Governance
30 questions1. A candidate wants to know how the CISM exam is delivered. Which of the following correctly describes the available delivery modes?
- A. Only in-person at a test center, with no remote option
- B. Candidates may choose either an in-person test center or an online remote-proctored option
- C. Only through a mobile app with no proctoring
- D. Exclusively through employer-sponsored on-site testing
Show answer & explanation
Answer: B
Candidates select between an in-person test center delivery or an online remote-proctored exam, giving flexibility in how they sit for the CISM exam. There is a remote option, so in-person only (A) is incorrect. There is no unproctored mobile app option (C). Testing is not restricted to employer-sponsored on-site sessions (D).2. Which of the following BEST demonstrates that an organization's information security strategy is aligned with business objectives?
- A. The security budget increases every fiscal year
- B. Security initiatives are prioritized and funded based on their support of documented business goals
- C. The security team reports directly to the CEO
- D. All security policies have been reviewed within the past 12 months
Show answer & explanation
Answer: B
Strategic alignment means security decisions and investments are driven by business objectives, which is best evidenced by prioritization and funding tied to those goals. A growing budget (A) does not prove alignment, only spending. Reporting structure (C) may support governance but does not itself demonstrate alignment. Policy review cadence (D) reflects maintenance, not strategic linkage.3. An information security steering committee is being formed. Which composition BEST supports effective governance oversight?
- A. Only members of the IT department, since they understand the technical risks
- B. Senior representatives from business units, IT, legal, HR, and risk management
- C. External auditors exclusively, to ensure independence
- D. The information security manager alone, to avoid conflicting priorities
Show answer & explanation
Answer: B
A steering committee needs cross-functional representation from business and support functions so that security decisions reflect enterprise-wide risk appetite and objectives, which is a core governance principle. Limiting membership to IT (A) ignores business context. External auditors only (C) removes internal accountability. A single individual (D) is not a committee and lacks diverse input.4. An organization's information security policy has not been updated in five years, though the business has since adopted cloud computing and remote work extensively. What is the GREATEST risk of this situation?
- A. Employees may not have read the policy
- B. The policy no longer reflects the current risk environment, leaving gaps in governance and control coverage
- C. The policy document is a different font than newer documents
- D. Legal counsel was not involved in the original drafting
Show answer & explanation
Answer: B
Governance frameworks and policies must evolve with the business and technology landscape; an outdated policy fails to address new risk domains like cloud and remote access, creating real control gaps. Whether employees read it (A) is a separate awareness issue. Formatting (C) is irrelevant. Legal involvement in drafting (D) does not address the current relevance problem.5. A candidate is planning their CISM certification timeline after passing the exam. Which statement about the certification application process is accurate?
- A. Candidates must apply for certification within 5 years of passing the exam
- B. Candidates must apply for certification within 30 days of passing the exam
- C. There is no time limit to apply for certification after passing
- D. Certification is granted automatically the moment the exam is passed
Show answer & explanation
Answer: A
Candidates have a five-year window from their exam pass date to submit their certification application, which is separate from the exam-eligibility registration window. A 30-day limit (B) is incorrect and far too short. There is in fact a defined limit, so it is not unlimited (C). Certification is not automatic (D); candidates must submit an application, including verified work experience, before being certified.6. An information security strategy is being developed. What should it be aligned to first?
- A. The organization's business objectives and strategy, so security investment supports what the organization is trying to achieve
- B. The security manager's professional certification syllabus
- C. The controls implemented by industry peers
- D. The latest available security technologies
Show answer & explanation
Answer: A
Alignment to business objectives is what makes a security programme defensible and fundable, because it connects each control to something the organization cares about. Technology-led or peer-led programmes produce capability that may address risks the organization does not have while leaving its actual exposures unaddressed.7. Who should own an information security policy and approve it?
- A. Senior management or the board, since a policy sets organization-wide direction that only that level can mandate
- B. The security operations team that will enforce it
- C. The internal audit function
- D. The external security consultant who drafted it
Show answer & explanation
Answer: A
A policy directs behaviour across the organization, so its authority comes from the level able to require compliance and allocate resources to it. Security operations translates policy into standards and procedures, and audit assesses compliance, so neither can own the policy without conflating direction with execution or assurance.8. How do a policy, a standard, a procedure and a guideline differ in a security documentation hierarchy?
- A. A policy states mandatory direction, a standard specifies mandatory requirements meeting it, a procedure gives step-by-step instructions, and a guideline offers recommended but optional practice
- B. All four are mandatory and differ only in length
- C. A guideline is mandatory and a standard is optional
- D. A procedure sets direction and a policy implements it
Show answer & explanation
Answer: A
The hierarchy separates enduring direction from technology-specific requirements and from the operational steps that change frequently, which is why a policy can survive a technology refresh that rewrites every standard beneath it. Mislabelling a guideline as a standard creates unenforceable expectations, and the reverse creates unnoticed non-compliance.9. A security manager must report programme status to the board. What reporting approach is most effective?
- A. Expressing status in terms of risk to business objectives, trends and decisions required, rather than technical control counts
- B. Providing the raw output of vulnerability scanning tools
- C. Reporting the number of blocked firewall connections
- D. Listing every security incident with full technical detail
Show answer & explanation
Answer: A
A board allocates resources and accepts risk, so it needs exposure relative to appetite, direction of travel and the decisions being asked of it. Volume metrics such as blocked connections measure activity rather than risk and can move in either direction without any change in the organization's actual exposure.10. What does information security governance establish that a security programme alone does not?
- A. The accountability structure, decision rights and oversight that direct the programme and hold it to account
- B. The technical configuration of security tooling
- C. The daily operational response to security alerts
- D. The vendor selection for security products
Show answer & explanation
Answer: A
Governance answers who decides, who is accountable and how performance is overseen, while the programme is the set of activities carried out within that structure. A well-run programme without governance depends on the individuals running it and lacks the mandate to resolve conflicts with business units.11. An organization must comply with multiple overlapping regulatory regimes. What approach reduces duplicated effort?
- A. A common control framework mapped to each regime's requirements, so one control implementation satisfies several obligations and is tested once
- B. A separate security programme for each regime
- C. Complying with only the strictest regime and ignoring the others
- D. Delegating all compliance to the internal audit function
Show answer & explanation
Answer: A
Requirements across regimes overlap substantially, so a mapped common control set removes duplicated implementation and testing while making coverage gaps visible. Assuming the strictest regime subsumes the others fails because regimes differ in kind rather than only in degree, with distinct notification, residency and consent requirements.12. A security manager proposes a maturity model assessment of the programme. What does it provide that a control gap analysis does not?
- A. A view of how consistently and repeatably processes operate, distinguishing a control performed ad hoc from one that is managed and measured
- B. A list of missing controls
- C. The financial cost of remediation
- D. The technical configuration of each system
Show answer & explanation
Answer: A
A gap analysis answers whether a control exists while maturity answers how dependably it operates, and a control performed inconsistently by one knowledgeable individual passes existence testing while carrying substantial key-person risk. Maturity also gives a defensible trajectory for multi-year investment rather than a binary compliance statement.13. The CISO in an organization reports administratively to the Chief Information Officer (CIO), who is also responsible for IT operations and system implementation. What is the PRIMARY governance concern with this reporting structure?
- A. Security incidents will not be reported to executive management in a timely manner.
- B. The CIO may deprioritize security initiatives that conflict with IT delivery timelines and budgets, creating a conflict of interest.
- C. The CISO may lack sufficient technical knowledge of the systems being secured.
- D. The CIO cannot approve funding for information security initiatives without board approval.
Show answer & explanation
Answer: B
Because the CIO is accountable for IT delivery, cost, and schedule, having security report through that same chain creates an inherent conflict of interest: security decisions that slow releases or add cost may be deprioritized to protect operational metrics the CIO is measured on. Independent or dual reporting lines mitigate this by preserving the objectivity needed to challenge IT priorities when warranted.14. An information security manager is preparing a business case to secure funding for a new security initiative. Which approach is MOST likely to gain executive support?
- A. Frame the initiative in terms of business risk reduction and alignment with strategic objectives.
- B. Emphasize the technical sophistication of the proposed controls.
- C. Highlight the number of vulnerabilities the initiative will remediate.
- D. Compare the initiative's cost to typical industry security budgets.
Show answer & explanation
Answer: A
Executives allocate resources based on business impact rather than technical detail. Presenting the initiative as a reduction of business risk that supports strategic goals speaks the language decision-makers use to evaluate competing investments, whereas technical depth, budget benchmarking, or raw vulnerability counts do not by themselves demonstrate value to the organization.15. An organization is selecting a governance framework (such as COBIT) to structure its information security program. What is the PRIMARY benefit of adopting a recognized framework?
- A. It provides a structured set of processes and controls that can be consistently measured and audited over time.
- B. It eliminates the need for a dedicated information security manager.
- C. It guarantees compliance with all applicable laws and regulations.
- D. It removes the need for board-level oversight of the security program.
Show answer & explanation
Answer: A
A recognized governance framework gives the organization a common, well-tested structure of processes, roles, and controls that can be applied consistently and assessed for maturity or audited over time, rather than relying on an ad hoc approach. It does not replace dedicated security leadership, guarantee legal compliance on its own, or reduce the need for oversight, since frameworks still require capable people and governance to be effective.16. Senior executives visibly comply with security policies and reference security priorities in company communications. What is this PRIMARILY an example of?
- A. Establishing a security-conscious organizational culture through tone at the top.
- B. Regulatory compliance enforcement.
- C. Risk transfer.
- D. Segregation of duties.
Show answer & explanation
Answer: A
When senior leaders visibly model compliance and communicate security as a priority, they set the 'tone at the top,' which is one of the most influential factors in shaping an organization's security culture because employees tend to mirror the behaviors and priorities they see modeled by leadership, more so than policy documents alone can achieve.17. A new data protection regulation in the organization's operating jurisdiction introduces mandatory breach notification requirements. What should the information security manager do FIRST?
- A. Immediately notify all customers of the new regulatory requirement.
- B. Purchase additional cyber insurance to cover potential fines.
- C. Wait until a breach occurs before determining notification obligations.
- D. Assess current incident response and governance processes against the new requirement to identify gaps.
Show answer & explanation
Answer: D
Before any specific incident occurs, the security manager needs to understand how the organization's existing governance and incident response processes measure up against the new legal obligation so that gaps in roles, timelines, and documentation can be closed proactively. Waiting for a breach to occur, or reacting only through insurance or premature customer notice, does not address the underlying gap between current practice and the new legal requirement.18. An information security manager wants to add leading indicators to a governance dashboard that currently only reports incident counts and audit findings. Which metric BEST serves as a leading indicator?
- A. Percentage of critical systems with overdue vulnerability patches.
- B. Total financial loss attributed to past breaches.
- C. Number of audit findings closed in the prior year.
- D. Number of security incidents reported last quarter.
Show answer & explanation
Answer: A
Leading indicators measure conditions that predict future risk before an adverse event occurs, such as the backlog of unpatched vulnerabilities on critical systems, which signals exposure that could lead to an incident. Incident counts, historical losses, and closed audit findings all describe events that have already happened and therefore function as lagging indicators rather than predictive ones.19. A global organization with autonomous regional business units is deciding between a centralized and a federated information security governance model. Which factor MOST strongly favors a federated approach?
- A. Significant differences in regulatory requirements and risk profiles across regions.
- B. A desire to minimize the total number of security staff employed.
- C. A preference for uniform security metrics across all regions.
- D. The need to reduce the overall cost of the security program.
Show answer & explanation
Answer: A
A federated governance model allows regional units to tailor policies and controls to local regulatory and risk conditions while still operating under a shared overarching framework, which is most valuable when regions differ significantly in legal requirements or threat exposure. Cost reduction, staffing minimization, and metric uniformity are generally better served by a centralized model, since federation typically increases coordination overhead rather than reducing it.20. A business unit requests a formal exception to a mandatory security policy due to a legacy application that cannot support required controls. What should the information security manager ensure is part of the exception process?
- A. The exception is granted permanently once approved to avoid repeated requests.
- B. The business unit is exempted from all related policies going forward.
- C. The exception includes documented compensating controls, an owner, and a defined expiration or review date.
- D. The exception is kept informal to expedite business operations.
Show answer & explanation
Answer: C
A properly governed exception process requires documented compensating controls to offset the unmet requirement, a clearly assigned owner accountable for the residual risk, and a review or expiration date so the exception does not become a permanent, unmonitored gap. Granting an open-ended or informal exception removes accountability and allows risk to persist unchecked over time.21. An organization is establishing an enterprise architecture function. What is the PRIMARY reason information security governance should have formal input into this function?
- A. To eliminate the need for separate security reviews of new technology projects.
- B. To ensure the enterprise architecture team reports directly to the information security manager.
- C. To reduce the overall headcount required for the architecture function.
- D. To ensure security requirements are embedded into technology decisions from the earliest design stages.
Show answer & explanation
Answer: D
When security governance has formal input into enterprise architecture, security requirements can be built into standards, reference architectures, and technology roadmaps from the outset rather than being bolted on after systems are already designed or deployed, which is both more effective and less costly. This input does not remove the need for security review of individual projects nor does it require organizational reporting changes.22. A business unit leader overrules a security control recommendation from the information security manager, citing operational impact, and proceeds without documented risk acceptance. What is the MOST appropriate governance response?
- A. Accept the business unit leader's decision without further action since they own the operational risk.
- B. Escalate the unresolved risk to the appropriate governance body, such as a steering committee, for formal risk acceptance.
- C. Implement the control unilaterally despite the business unit's objection.
- D. Document the disagreement informally and take no further action.
Show answer & explanation
Answer: B
When a business decision-maker overrides a security recommendation without going through a formal risk acceptance process, governance structures exist precisely to resolve this kind of impasse by escalating the decision to a body with the authority and accountability to formally accept or reject the residual risk on behalf of the organization. Simply deferring, documenting informally, or unilaterally imposing the control bypasses the governance mechanism designed for this situation.23. An information security manager is documenting who is Responsible, Accountable, Consulted, and Informed for a new access review process. What is the PRIMARY value of this exercise?
- A. It clarifies ownership and prevents gaps or overlaps in responsibility for the process.
- B. It replaces the need for a written procedure.
- C. It guarantees that the access review will detect all inappropriate access.
- D. It eliminates the need for periodic audits of the process.
Show answer & explanation
Answer: A
A RACI exercise clarifies exactly who performs a task, who is ultimately accountable for its outcome, who must be consulted, and who simply needs to stay informed, which prevents the common problem of tasks falling through the cracks because multiple people assumed someone else was responsible. It does not substitute for documented procedures, guarantee detection effectiveness, or remove the need for independent audit.24. Within an information security governance structure, which activity is MOST appropriately reserved for the board of directors rather than delegated to security management?
- A. Configuring firewall rule sets for the perimeter network.
- B. Selecting a specific vulnerability scanning tool.
- C. Assigning incident response duties during a live security event.
- D. Approving the organization's overall risk appetite for information security.
Show answer & explanation
Answer: D
Setting the organization's risk appetite is a strategic governance decision that defines how much risk the organization is willing to accept in pursuit of its objectives, and it properly belongs at the board level because it shapes decisions across the entire enterprise, not just information security. Operational activities such as tool selection, configuration, and incident duty assignment are management-level responsibilities delegated to security staff.25. A governance committee is reviewing two competing security investments with similar cost but different expected outcomes: one reduces the likelihood of a low-impact, high-frequency risk, and the other reduces the impact of a low-frequency, catastrophic risk. Absent other constraints, which consideration should MOST influence the committee's prioritization?
- A. The investment that is easiest to implement technically.
- B. The organization's documented risk appetite and tolerance for catastrophic versus recurring losses.
- C. The investment that has been requested most recently by staff.
- D. The investment with the shorter vendor contract term.
Show answer & explanation
Answer: B
Because both investments cost roughly the same but address fundamentally different risk profiles, the governance committee should prioritize based on how the organization has defined its appetite for catastrophic, low-frequency events versus recurring, lower-impact ones, since this appetite reflects the organization's strategic tolerance for different loss patterns. Ease of implementation, recency of request, or contract term are operational or administrative factors that do not reflect the organization's actual risk priorities.26. An information security strategy was approved eighteen months ago. The organization has since undergone a merger and entered new markets. What should trigger a formal review of the security strategy?
- A. The passage of exactly twelve months since the last review.
- B. A request from the IT help desk for additional staffing.
- C. The renewal date of the cyber insurance policy.
- D. Material changes to the business, such as a merger or new market entry, that alter the risk and threat landscape.
Show answer & explanation
Answer: D
Security strategy should be reviewed whenever significant business changes occur that alter the organization's risk profile, threat landscape, or objectives, such as a merger or expansion into new markets, because the existing strategy may no longer reflect the assets, regulatory exposure, or priorities that need protecting. A fixed calendar interval, staffing requests, or insurance renewal dates are not reliable triggers for reassessing whether the strategy still fits the business.27. An organization's governance framework requires that critical third-party service providers be subject to periodic security oversight. What is the PRIMARY reason this oversight should be governed at the enterprise level rather than left to individual business units?
- A. It ensures consistent risk criteria and accountability are applied across all vendor relationships regardless of which unit engages them.
- B. It eliminates the need for contractual security clauses.
- C. It reduces the total number of vendors the organization can use.
- D. It transfers all security liability to the third party.
Show answer & explanation
Answer: A
Enterprise-level governance of third-party oversight ensures that every business unit applies the same risk assessment criteria and accountability standards when engaging vendors, preventing inconsistent or weaker practices in units that manage their own vendor relationships without central oversight. It does not reduce vendor options, shift legal liability entirely to the third party, or remove the need for security clauses in contracts.28. A parent company with a conservative risk appetite acquires a subsidiary operating in a jurisdiction where local competitors normally accept far higher levels of cyber risk to remain price-competitive. The subsidiary's leadership resists adopting the parent's security requirements, citing competitive disadvantage. What is the MOST appropriate governance approach for the information security manager to recommend?
- A. Allow the subsidiary to define its own independent risk appetite separate from the parent company.
- B. Mandate immediate, uniform application of all parent company controls regardless of local business impact.
- C. Engage subsidiary and parent governance stakeholders to reconcile risk appetite differences through a documented, risk-based exception and phased-adoption plan.
- D. Defer the decision entirely to the subsidiary's local IT department.
Show answer & explanation
Answer: C
Reconciling a genuine conflict between an acquired subsidiary's competitive realities and the parent organization's risk appetite requires structured governance engagement that documents where controls must be phased in and where formal, time-bound exceptions with compensating measures are appropriate, rather than either abandoning parent oversight entirely or imposing controls without regard to legitimate business impact. Leaving the decision to local IT or letting the subsidiary set an entirely independent risk appetite undermines the enterprise governance structure the parent company is accountable for.29. An information security manager conducts a maturity assessment and finds the organization's security processes are performed but not consistently documented or repeatable across teams. According to common maturity models, this level is BEST characterized as which stage?
- A. Nonexistent, where no processes are performed at all.
- B. Optimized, where processes are continuously improved using metrics.
- C. Managed and measured, where processes are quantitatively controlled.
- D. Repeatable but informal, where processes are performed and produce results but are not consistently documented or standardized across teams.
Show answer & explanation
Answer: D
Maturity models generally describe a stage where activities are being performed and produce results, but without consistent documentation or repeatability across teams — a repeatable-but-informal stage, distinct from both the earliest stage where nothing is done at all and the higher stages where processes are formally defined, measured, or continuously optimized. Recognizing this stage accurately helps the security manager target standardization and documentation as the next improvement priority rather than jumping to advanced metrics-driven optimization.30. An organization has passed all required regulatory compliance audits for the past three years but has experienced two significant security incidents caused by control gaps that fell outside the scope of the audited requirements. What does this scenario BEST illustrate?
- A. The compliance audits were performed incorrectly.
- B. Compliance with regulatory requirements is necessary but not sufficient for effective security governance, which must address risk beyond the minimum mandated baseline.
- C. Regulatory requirements are always sufficient to prevent security incidents.
- D. The organization should discontinue compliance audits since they did not prevent incidents.
Show answer & explanation
Answer: B
Regulatory compliance establishes a minimum legally required baseline, but effective security governance must identify and address risks beyond that baseline based on the organization's actual threat landscape, since compliance frameworks are not designed to cover every possible risk an organization faces. The incidents in this scenario demonstrate exactly this gap, not that the audits were flawed or should be abandoned, since compliance remains necessary even though it is insufficient alone.
Information Security Risk Management
28 questions31. During a risk assessment, an information security manager identifies a legacy application with a known vulnerability, but the business unit refuses to fund remediation because the system will be decommissioned in six months. What is the MOST appropriate next step?
- A. Force decommissioning immediately regardless of business needs
- B. Document the risk, ensure it is formally accepted by an authorized business owner, and implement compensating controls if feasible
- C. Ignore the finding since the system will soon be retired
- D. Escalate directly to external regulators
Show answer & explanation
Answer: B
Risk management requires that residual risk be formally accepted by someone with the authority to do so, and compensating controls should be applied where practical to reduce exposure in the interim. Forcing decommissioning (A) is outside the security manager's authority and may harm the business. Ignoring the finding (C) abdicates the manager's responsibility to track and report risk. Escalating to regulators (D) is disproportionate for an internally manageable risk decision.32. When calculating risk during a quantitative risk assessment, which formula BEST represents the relationship between the key variables typically used?
- A. Risk = Asset Value / Threat Frequency
- B. Risk = Likelihood of a threat exploiting a vulnerability × Impact of that occurrence
- C. Risk = Number of controls implemented
- D. Risk = Cost of the asset minus insurance coverage
Show answer & explanation
Answer: B
Risk is fundamentally a function of the likelihood that a threat will exploit a vulnerability and the resulting impact, which is the basis of both qualitative and quantitative risk models. Dividing asset value by frequency (A) is not a recognized risk formula. Counting controls (C) measures mitigation effort, not risk itself. Subtracting insurance from cost (D) relates to financial risk transfer, not the underlying risk calculation.33. An organization decides to purchase cyber insurance to address the financial impact of a potential ransomware attack rather than investing further in prevention controls. This is an example of which risk treatment option?
- A. Risk avoidance
- B. Risk transfer
- C. Risk acceptance
- D. Risk mitigation
Show answer & explanation
Answer: B
Purchasing insurance shifts the financial consequence of a risk event to a third party, which is the definition of risk transfer. Risk avoidance (A) would mean eliminating the activity that creates the risk entirely. Risk acceptance (C) means retaining the risk without further action or transfer. Risk mitigation (D) involves reducing likelihood or impact through controls, which the organization explicitly chose not to do further.34. A risk register lists a high-likelihood, high-impact risk with no assigned owner or treatment plan. What is the BEST immediate action for the information security manager?
- A. Delete the entry since it lacks an owner
- B. Assign an accountable risk owner and drive development of a treatment plan with a target date
- C. Wait until the next annual risk assessment cycle
- D. Transfer the risk to the audit department by default
Show answer & explanation
Answer: B
A high-likelihood, high-impact risk without ownership represents a governance gap that must be closed by assigning accountability and driving a concrete treatment plan promptly, given the severity. Deleting the entry (A) hides the risk rather than managing it. Waiting a full cycle (C) is inappropriate given the severity. Defaulting ownership to audit (D) is inappropriate since audit provides independent assurance, not risk ownership.35. Which of the following is the MOST important reason to perform periodic reassessment of previously identified and accepted risks?
- A. To satisfy an arbitrary documentation requirement
- B. Because the threat landscape, asset value, and control environment can change, altering the risk's likelihood or impact over time
- C. To reduce the size of the risk register
- D. Because auditors always require it regardless of business context
Show answer & explanation
Answer: B
Risk is dynamic; changes in threats, business context, asset criticality, or controls can shift a previously acceptable risk into an unacceptable one, so periodic reassessment ensures acceptance decisions remain valid. Documentation for its own sake (A) misses the substantive purpose. Reducing register size (C) is not a legitimate driver of reassessment. Framing it purely as an audit requirement (D) ignores the risk-management rationale that underlies the practice.36. An organization is evaluating two risk treatment options for a vulnerable legacy system: patching it now for a moderate cost, or replacing it next year at a much higher cost with lower risk reduction in the interim. What should PRIMARILY drive this decision?
- A. The personal preference of the IT manager
- B. A cost-benefit analysis comparing the risk reduction achieved against the cost and timing of each option
- C. Whichever option requires less paperwork
- D. The vendor offering the largest discount
Show answer & explanation
Answer: B
Risk treatment decisions should be grounded in a cost-benefit analysis that weighs the reduction in risk exposure against implementation cost and timeline, ensuring resources are allocated efficiently. Personal preference (A) is subjective and unaccountable. Minimizing paperwork (C) is an administrative convenience, not a risk-based criterion. Vendor discounts (D) should not override a proper risk-based evaluation.37. A company's risk appetite statement specifies that it will not accept any risk with the potential for regulatory fines exceeding a defined threshold. A newly identified risk exceeds this threshold but is inexpensive to remediate. What should the information security manager recommend?
- A. Accept the risk since remediation cost is a separate consideration
- B. Remediate the risk to bring it within the defined risk appetite
- C. Escalate to the board only if the fine is actually imposed
- D. Transfer all responsibility to the compliance department without further security involvement
Show answer & explanation
Answer: B
When a risk exceeds the organization's documented risk appetite, and remediation is feasible and low-cost, treatment should be pursued to bring the risk within acceptable bounds, which is the direct purpose of a risk appetite statement. Accepting it anyway (A) violates the organization's own stated risk tolerance. Waiting for an actual fine (C) is reactive rather than proactive risk management. Fully offloading responsibility (D) ignores the security manager's role in risk treatment recommendations.38. An organization is evaluating whether to launch a new product feature that would require processing highly sensitive data in a jurisdiction with weak data protection enforcement and no feasible compensating controls. Which risk treatment option is the organization applying if it decides not to launch the feature at all?
- A. Risk mitigation.
- B. Risk acceptance.
- C. Risk avoidance.
- D. Risk transfer.
Show answer & explanation
Answer: C
Choosing not to proceed with an activity because the associated risk cannot be adequately reduced or offset is the definition of risk avoidance, which eliminates the risk by eliminating the activity itself rather than reducing its likelihood or impact, shifting it to another party, or knowingly retaining it. This differs from mitigation, which would involve implementing controls to reduce the risk while still launching the feature.39. Two independent risk assessments of the same critical system, conducted using different methodologies, produce materially different risk ratings: one rates the system as high risk and the other as moderate risk. Executive leadership is preparing to make a funding decision based on these results. What should the information security manager do FIRST?
- A. Present both ratings to leadership and let them choose which one to believe.
- B. Reconcile the differences by examining the underlying assumptions, scope, and data of each assessment before presenting a unified recommendation.
- C. Discard both assessments and postpone the funding decision indefinitely.
- D. Adopt the higher rating automatically, since it represents the more conservative outcome.
Show answer & explanation
Answer: B
When two assessments of the same system disagree, the underlying cause is almost always a difference in scope, assumptions, threat data, or methodology, and understanding that discrepancy is essential before presenting leadership with a reliable, unified view; simply picking the higher rating by default, letting leadership arbitrate a methodological dispute, or postponing the decision indefinitely all avoid the analytical work needed to produce a defensible, accurate recommendation for a critical funding decision.40. An organization defines its risk appetite. What role does it play in security decisions?
- A. It sets the threshold above which risk must be treated rather than accepted, making treatment decisions consistent across the organization
- B. It specifies which security products must be purchased
- C. It determines the security team's headcount
- D. It eliminates the need for individual risk assessments
Show answer & explanation
Answer: A
Without a stated appetite, each treatment decision is made on the judgment of whoever is present, producing inconsistency that is invisible until an accepted risk materializes. Appetite gives a common reference point, while tolerance expresses the acceptable variation around it for a specific risk or objective.41. A risk assessment produces an inherent risk rating and a residual risk rating. What is the difference?
- A. Inherent risk is the exposure before considering controls, while residual risk is what remains after existing controls operate as designed
- B. Inherent risk is the risk after treatment and residual is before
- C. Inherent risk applies to external threats and residual to internal ones
- D. The two are the same measure at different points in time
Show answer & explanation
Answer: A
The pairing shows how much protection existing controls actually provide, which is what justifies their cost and identifies where further treatment is needed. Reporting only residual risk hides the dependency on controls whose failure would restore the inherent exposure, which matters when a control is being decommissioned.42. Which risk treatment option is being applied when an organization buys cyber insurance?
- A. Transfer or sharing, since the financial consequence moves to another party while the operational risk remains
- B. Mitigation, since the likelihood of an incident falls
- C. Acceptance, since no action was taken
- D. Avoidance, since the risk no longer applies
Show answer & explanation
Answer: A
Insurance moves financial consequence but leaves likelihood, operational disruption and reputational harm entirely with the organization, which is why it complements rather than replaces controls. The four options are avoid, mitigate, transfer and accept, and clarity about which is being used prevents an insured organization from believing it is protected.43. A quantitative risk analysis estimates annualized loss expectancy. What does that figure represent?
- A. The expected loss per year from a risk, combining the loss per occurrence with how often occurrences are expected
- B. The worst-case loss from a single occurrence
- C. The cost of the controls addressing the risk
- D. The insurance premium for the exposure
Show answer & explanation
Answer: A
Annualized loss expectancy is single loss expectancy multiplied by annualized rate of occurrence, which converts a severity figure and a frequency estimate into a comparable annual number. Comparing it to the annual cost of a control gives a defensible basis for investment, though the frequency estimate is usually the weakest input.44. A control costs more per year than the annualized loss expectancy of the risk it addresses. What does this suggest?
- A. The control is not cost-justified on that risk alone, though qualitative factors such as regulatory obligation or reputational harm may still justify it
- B. The control should always be implemented regardless of cost
- C. The risk assessment must be wrong
- D. The risk should be transferred automatically
Show answer & explanation
Answer: A
Spending more than the expected loss destroys value on a purely financial basis, which is why the comparison is a useful discipline against controls justified by discomfort alone. The qualification matters because regulatory penalties, safety consequences and reputational harm are frequently underrepresented in the loss figure.45. A risk register entry has no named owner. Why is this a significant weakness?
- A. Because without an accountable owner no one is responsible for treating the risk or for the consequences of accepting it, so the entry documents rather than manages it
- B. Because a register cannot be maintained without owners
- C. Because owners are required by all security standards
- D. Because unowned risks are automatically the security manager's
Show answer & explanation
Answer: A
Ownership converts a documented observation into a managed item with someone answerable for the decision taken. The last option is the common failure mode in practice: risks default to the security function, which usually lacks the authority or budget to treat risks arising in business processes it does not control.46. A newly identified threat is added to the risk assessment. What should trigger reassessment of existing risks?
- A. Material change in the threat landscape, business processes, technology or regulation, in addition to a periodic cycle
- B. Only the annual review date
- C. Only a security incident
- D. Only a request from internal audit
Show answer & explanation
Answer: A
A purely calendar-driven assessment is stale by the time it is used in a fast-moving environment, so event-driven triggers must supplement the cycle. Waiting for an incident makes the process reactive by definition, since the incident is the materialization of the risk the assessment was supposed to surface in advance.47. An organization needs to assess risk for a new initiative but lacks reliable historical loss data and cannot easily estimate financial impact in dollar terms. Which risk assessment approach is MOST appropriate?
- A. A purely quantitative approach using annualized loss expectancy calculations.
- B. No formal risk assessment is needed since data is unavailable.
- C. A qualitative approach using risk ratings such as high, medium, and low based on expert judgment.
- D. A purely statistical approach based on industry-wide breach cost averages.
Show answer & explanation
Answer: C
When reliable historical loss data is unavailable, a qualitative approach that relies on structured expert judgment to rate likelihood and impact allows the organization to prioritize risks meaningfully without requiring precise financial inputs that do not exist. Forcing a quantitative calculation without valid data produces false precision, while skipping assessment altogether or relying solely on generic industry averages ignores the organization's specific context.48. An information security manager wants to improve the accuracy of likelihood estimates used in the organization's risk assessments. Which action would MOST directly improve this?
- A. Incorporating current threat intelligence relevant to the organization's industry and technology environment.
- B. Increasing the frequency of employee security awareness training.
- C. Reducing the number of risk categories tracked in the risk register.
- D. Outsourcing the entire risk assessment process to a single vendor.
Show answer & explanation
Answer: A
Likelihood estimates are strengthened when they are grounded in current, relevant threat intelligence about the actors, techniques, and campaigns actually targeting the organization's industry and technology stack, rather than relying on generic or outdated assumptions. Awareness training, reducing risk categories, or full outsourcing may have other benefits but do not directly sharpen the accuracy of likelihood estimation the way relevant threat data does.49. After implementing a set of security controls, the residual risk for a critical system remains above the organization's documented risk appetite. What is the MOST appropriate next step for the information security manager?
- A. Consider the risk treatment complete since controls were implemented.
- B. Identify and implement additional controls, or escalate the residual risk for formal acceptance by an authorized party.
- C. Remove the risk from the risk register since it has already been treated.
- D. Transfer full responsibility for the residual risk to the system's end users.
Show answer & explanation
Answer: B
When residual risk remains above the organization's stated appetite even after treatment, the security manager must either pursue further risk reduction through additional controls or formally escalate the gap so an authorized party can knowingly accept the excess risk with documented accountability; simply considering the matter closed or removing it from tracking leaves an unmanaged exposure that exceeds what the organization has said it is willing to tolerate.50. How does a business impact analysis (BIA) relate to an information security risk assessment?
- A. A BIA replaces the need for a risk assessment entirely.
- B. A BIA is only relevant to physical security, not information security.
- C. A BIA identifies the criticality and impact of business processes, informing which assets and risks the risk assessment should prioritize.
- D. A BIA and a risk assessment measure identical variables and produce redundant results.
Show answer & explanation
Answer: C
A business impact analysis identifies which business processes and supporting assets are most critical to the organization and quantifies the impact of their disruption, and this information feeds directly into a risk assessment by helping prioritize which assets and scenarios warrant the closest scrutiny. The two are complementary rather than redundant or interchangeable, and a BIA does not eliminate the need for a separate risk assessment covering threats and vulnerabilities.51. Individually, ten systems each carry a 'low' risk rating, but they share a common underlying vulnerability in a widely used software component. What risk consideration does this scenario illustrate?
- A. Low individual risk ratings can always be safely ignored regardless of scale.
- B. Risk ratings for individual systems should never be compared to one another.
- C. Aggregated risk across multiple assets can be significantly higher than any single asset's individual rating suggests.
- D. Shared vulnerabilities only matter if the systems are physically co-located.
Show answer & explanation
Answer: C
When many assets share a common vulnerability, an exploit affecting that shared component can compromise all of them simultaneously, meaning the true organizational exposure is better represented by the aggregate or portfolio risk than by looking at any single system's rating in isolation, since a single low individual score can mask a much larger cumulative exposure. This illustrates why risk assessments should consider cross-asset dependencies rather than evaluating systems purely in isolation.52. An organization is rapidly adopting generative AI tools across business units without a formal risk assessment process for new technology adoption. What is the GREATEST concern with this approach?
- A. Generative AI tools cannot be used for legitimate business purposes.
- B. Employees will become overly reliant on AI for routine tasks.
- C. Sensitive data may be exposed to external AI providers or embedded in outputs without appropriate risk evaluation and controls.
- D. AI tools are inherently more expensive than traditional software.
Show answer & explanation
Answer: C
Adopting new technology such as generative AI without a formal risk assessment process means data handling, third-party exposure, and output-related risks are not evaluated before sensitive information is potentially shared with external providers or surfaced inappropriately in generated outputs, leaving the organization exposed to risks it has not consciously assessed or accepted. Concerns about cost or overreliance are secondary business considerations rather than the primary security risk in this scenario.53. An information security manager facilitates risk assessments and maintains the risk register, but a specific risk in the register concerns a business application owned by a department director. Who should be assigned as the risk owner for that item?
- A. The department director, since they have the authority and accountability to make decisions about that application's risk.
- B. The information security manager, since they maintain the risk register.
- C. The organization's external auditor.
- D. No owner is required as long as the risk is documented.
Show answer & explanation
Answer: A
Risk ownership belongs with the individual who has the authority and business context to make decisions about accepting, treating, or escalating a specific risk, which in this case is the department director accountable for the application, not the security manager who facilitates the risk process or an external party with no operational authority. Leaving a risk without an assigned owner undermines accountability regardless of how well it is documented.54. Before onboarding a new cloud service provider that will store regulated customer data, the information security manager is designing a vendor risk assessment approach. Which approach BEST ensures resources are focused appropriately?
- A. Skip formal assessment for vendors offering the lowest contract price.
- B. Tier vendors by the sensitivity of data and level of system access involved, applying deeper scrutiny to higher-tier vendors.
- C. Rely exclusively on the vendor's self-attestation without independent verification for any vendor.
- D. Apply the identical, most rigorous assessment to every vendor regardless of the data or access involved.
Show answer & explanation
Answer: B
Tiering vendors based on the sensitivity of the data they will handle and the level of access they require allows the organization to apply deeper, more resource-intensive scrutiny where the potential impact is greatest, while using lighter-touch review for lower-risk engagements, which is a more sustainable and defensible use of limited assessment resources than treating every vendor identically or skipping assessment based on price. Relying solely on unverified self-attestation for any vendor, regardless of risk tier, leaves material gaps in assurance.55. A project team plans to launch a new customer-facing application in eight weeks and requests that the risk assessment be skipped to meet the deadline, citing that a similar application was assessed two years ago. What is the MOST appropriate response from the information security manager?
- A. Perform a scoped risk assessment for the new application, since the threat landscape and application design may have changed materially since the prior assessment.
- B. Approve skipping the assessment since a similar application was already assessed previously.
- C. Delay the launch indefinitely until a full enterprise-wide risk assessment is completed.
- D. Allow the project team to self-certify that no significant risks exist.
Show answer & explanation
Answer: A
A prior assessment of a different, similar application two years ago does not account for changes in the threat landscape, the specific design and data flows of the new application, or new vulnerabilities that may have emerged since then, so a scoped, timely risk assessment focused on this application is warranted rather than skipping the step entirely, delaying the launch indefinitely, or relying on the project team's self-certification, which lacks independent verification.56. An organization has limited resources to perform risk assessments. How should the information security manager PRIMARILY determine the frequency of reassessment for different systems?
- A. Assess every system on the same fixed annual schedule regardless of criticality.
- B. Assess systems in alphabetical order as time permits.
- C. Assess higher-risk and more critical systems more frequently than lower-risk, less critical systems.
- D. Assess only systems that have experienced a prior security incident.
Show answer & explanation
Answer: C
With limited assessment resources, prioritizing more frequent reassessment of systems that carry higher risk or greater business criticality ensures that the areas of greatest potential impact receive the closest and most current scrutiny, which is a more effective use of resources than a uniform schedule, incident-triggered-only approach, or an arbitrary ordering that ignores actual risk levels.57. An information security manager needs to explain a complex technical vulnerability to a group of business executives with no technical background. What is the MOST effective communication approach?
- A. Present the full technical details, including exploit mechanics, to ensure completeness.
- B. Translate the vulnerability into business terms, describing potential business impact and recommended decisions needed.
- C. Delegate the explanation entirely to a third-party consultant.
- D. Postpone the discussion until the executives acquire technical training.
Show answer & explanation
Answer: B
Executives are best equipped to make decisions when technical risk is translated into business terms, such as potential financial, operational, or reputational impact and the specific decision or resource commitment being requested, rather than being given exploit-level technical detail they are not positioned to evaluate. Postponing the conversation or fully outsourcing it to a consultant does not serve the immediate need for informed executive decision-making.58. How does risk tolerance differ from risk appetite in the context of an information security risk management program?
- A. Risk appetite is set by IT staff, while risk tolerance is set by external auditors.
- B. Risk tolerance and risk appetite are interchangeable terms with no meaningful distinction.
- C. Risk tolerance applies only to financial risk, while risk appetite applies only to security risk.
- D. Risk appetite is the broad level of risk the organization is willing to pursue, while risk tolerance is the acceptable variation around that level for specific objectives.
Show answer & explanation
Answer: D
Risk appetite describes the overall amount and type of risk an organization is willing to accept in pursuit of its objectives, while risk tolerance defines the acceptable range of variation around specific targets or metrics within that broader appetite, giving more granular boundaries for day-to-day decisions. Treating the two terms as identical, or misattributing who sets each, obscures this useful distinction between strategic-level and operational-level risk boundaries.
Information Security Program
22 questions59. An information security program is being designed for a mid-sized organization. Which of the following BEST reflects a properly structured security program?
- A. A single antivirus product deployed across all endpoints
- B. A set of coordinated policies, standards, processes, and controls aligned to the security strategy and risk appetite
- C. An annual penetration test with no other ongoing activity
- D. A dedicated incident response team with no supporting policies
Show answer & explanation
Answer: B
An information security program is the coordinated set of policies, standards, processes, and controls that implement the strategy and manage risk to an acceptable level; it is holistic, not a single tool or event. A single antivirus deployment (A) is one control, not a program. An isolated annual pen test (C) is a point-in-time activity, not an ongoing program. A response team without governing policies (D) lacks the structural foundation a program requires.60. Which of the following is the PRIMARY purpose of a security awareness training program within an information security program?
- A. To satisfy a checkbox requirement for annual audits
- B. To reduce human-related risk by ensuring employees understand their security responsibilities and recognize common threats
- C. To replace the need for technical controls
- D. To provide a source of revenue through internal training fees
Show answer & explanation
Answer: B
Awareness training exists to reduce the human element of risk by equipping staff to recognize threats like phishing and understand their security obligations, directly supporting the program's risk-reduction goals. Treating it as a mere audit checkbox (A) misses its substantive purpose. It does not replace technical controls (C); it complements them. Internal revenue generation (D) is not a legitimate program objective.61. An information security manager is selecting metrics to report program performance to the board. Which characteristic is MOST important for these metrics to have?
- A. They should be highly technical to demonstrate the team's expertise
- B. They should be meaningful to a business audience and tied to risk reduction or business impact
- C. They should change every quarter to appear dynamic
- D. They should focus solely on the number of security incidents, regardless of severity
Show answer & explanation
Answer: B
Board-level metrics must translate security activity into business-relevant terms, such as risk reduction or impact avoidance, so non-technical leadership can make informed decisions. Overly technical metrics (A) fail to communicate to the intended audience. Constantly changing metrics (C) prevent meaningful trend analysis. Raw incident counts without severity context (D) can be misleading and do not convey actual risk posture.62. A security program includes a control requiring segregation of duties between developers and production system administrators. What is the PRIMARY security benefit of this control?
- A. It reduces the number of employees needed
- B. It reduces the risk of unauthorized or unreviewed changes being introduced into production
- C. It eliminates the need for change management processes
- D. It guarantees compliance with all data privacy regulations
Show answer & explanation
Answer: B
Segregation of duties between development and production administration prevents a single individual from introducing and deploying unreviewed or malicious changes, reducing fraud and error risk. It does not reduce headcount needs (A) as a security rationale. It does not eliminate change management (C); rather it complements it. It also does not guarantee full regulatory compliance (D), which depends on many other controls.63. An organization is implementing a data classification scheme as part of its security program. What is the MOST important reason for classifying data BEFORE applying protective controls?
- A. Classification is required only for marketing purposes
- B. It ensures that controls are proportionate to the sensitivity and value of the data, avoiding both under- and over-protection
- C. It allows the organization to charge different prices for data storage
- D. It removes the need for encryption on all data
Show answer & explanation
Answer: B
Classification allows security resources and controls to be applied proportionately, protecting highly sensitive data appropriately while avoiding wasteful over-controlling of low-sensitivity data. It has no marketing purpose (A). It is not a billing mechanism (C). It does not remove the need for encryption (D); rather it helps determine where encryption and other controls are most necessary.64. A vulnerability management program consistently identifies critical vulnerabilities that remain unpatched for over six months due to competing IT priorities. What is the BEST course of action for the information security manager?
- A. Accept the delays as normal since IT is busy
- B. Work with IT leadership to establish and enforce risk-based remediation SLAs tied to vulnerability severity
- C. Personally patch the systems without IT involvement
- D. Stop scanning for vulnerabilities to avoid generating findings IT cannot address
Show answer & explanation
Answer: B
Establishing enforceable, risk-based service level agreements for remediation aligns IT priorities with actual risk severity and creates accountability, addressing the root cause of chronic delays. Simply accepting delays (A) allows unacceptable risk exposure to persist. Bypassing IT to patch directly (C) violates change control and role boundaries. Stopping scans (D) hides risk rather than managing it and is a serious governance failure.65. When integrating security requirements into the systems development life cycle (SDLC), at which phase is it MOST cost-effective to identify and address security requirements?
- A. During production after deployment
- B. During the requirements and design phases, before development begins
- C. Only during user acceptance testing
- D. During the post-incident review after a breach
Show answer & explanation
Answer: B
Addressing security requirements early, during requirements gathering and design, is the most cost-effective point because defects and gaps are far cheaper to fix before code is written than after deployment. Fixing issues in production (A) is significantly more expensive and risky. Limiting security review to UAT (C) misses architectural issues that are hard to retrofit. Waiting for a post-incident review (D) means damage has already occurred.66. An information security manager is developing key performance indicators (KPIs) for the vulnerability management process. Which KPI provides the MOST meaningful insight into program effectiveness?
- A. Total number of vulnerability scans run per month
- B. Average time to remediate critical vulnerabilities compared to defined SLA targets
- C. Number of security tools purchased for scanning
- D. Number of employees on the vulnerability management team
Show answer & explanation
Answer: B
Time-to-remediate against SLA targets directly measures whether the organization is closing high-risk exposures promptly, which is the actual goal of vulnerability management. Scan counts (A) measure activity, not outcomes. Tool purchases (C) and headcount (D) are inputs/resources, not indicators of program effectiveness.67. Which of the following BEST describes the role of an information security program in supporting business continuity?
- A. The security program is entirely separate from business continuity and should not interact with it
- B. The security program provides controls and processes, such as backup protection and access continuity, that support the organization's ability to maintain and recover critical operations
- C. Business continuity planning is solely the responsibility of facilities management
- D. Security controls should be disabled during a declared disaster to speed up recovery
Show answer & explanation
Answer: B
An effective security program integrates with business continuity by protecting the confidentiality, integrity, and availability of the resources and processes needed for recovery, such as securing backups and ensuring continued access controls. Treating the two as unrelated (A) ignores this necessary integration. Continuity planning is a cross-functional responsibility, not exclusively facilities' domain (C). Disabling controls during a disaster (D) increases risk exactly when the organization is most vulnerable.68. Which of the following is the MOST important consideration when selecting security controls to include in an information security program?
- A. Selecting the newest technology available regardless of fit
- B. Ensuring controls are proportionate to identified risks and aligned with business and regulatory requirements
- C. Selecting controls solely based on vendor marketing claims
- D. Choosing the least expensive controls available
Show answer & explanation
Answer: B
Controls should be selected based on a proportionate response to actual identified risks and must satisfy applicable business and regulatory requirements, ensuring resources are well spent and compliance obligations are met. Chasing the newest technology (A) without a risk basis wastes resources. Relying on vendor marketing (C) is not a sound evaluation method. Choosing purely on cost (D) ignores whether the control actually addresses the risk.69. A new employee is granted access rights matching only the specific systems and data needed to perform their job duties, rather than broad administrative access. This reflects which security principle?
- A. Least privilege.
- B. Defense in depth.
- C. Non-repudiation.
- D. Separation of environments.
Show answer & explanation
Answer: A
Granting access limited strictly to what is necessary to perform a specific role is the definition of the least privilege principle, which reduces the potential impact of a compromised account or insider misuse by minimizing the scope of access any single user holds, unlike defense in depth, which concerns layered controls, or non-repudiation, which concerns the ability to prove an action occurred.70. A security monitoring tool generates a very high volume of alerts, the vast majority of which analysts determine are false positives after investigation. What is the MOST significant operational risk this creates?
- A. The organization will need to purchase additional monitoring licenses.
- B. Alert fatigue may cause analysts to overlook or delay response to a genuine security event among the noise.
- C. The tool will automatically be disabled by the vendor.
- D. False positives always indicate the tool is fundamentally unsuitable for use.
Show answer & explanation
Answer: B
A high volume of false positives creates alert fatigue, where analysts become desensitized to the constant noise and may delay, deprioritize, or entirely miss a genuine security event buried among the false alarms, which is a significant operational risk to the program's actual detection capability. This calls for tuning the tool's rules and thresholds rather than assuming it is unusable or expecting the vendor to disable it.71. An organization allows the same individual to both request and approve their own changes to a production firewall configuration. What control principle does this violate?
- A. Data classification.
- B. Segregation of duties, since a single individual should not both initiate and approve a sensitive change without independent oversight.
- C. Least privilege.
- D. Defense in depth.
Show answer & explanation
Answer: B
Segregation of duties requires that critical actions, such as requesting and approving a sensitive production change, be divided between different individuals so that no single person can both initiate and authorize an action without independent review, reducing the risk of unauthorized or erroneous changes going unchecked. While related to least privilege, this scenario specifically concerns the separation of initiating and approving roles rather than the scope of access granted.72. A security programme is being built. What should determine the controls selected?
- A. The risk assessment results and the organization's risk appetite, so controls address assessed exposures at proportionate cost
- B. A complete implementation of every control in a chosen framework
- C. The controls the previous security manager preferred
- D. The products the organization already owns licences for
Show answer & explanation
Answer: A
Frameworks provide a catalogue and a common language, but implementing them exhaustively without reference to assessed risk spends the budget uniformly rather than where exposure is greatest. Existing licences legitimately influence how a control is implemented but should not determine which risks get addressed.73. How do preventive, detective and corrective controls differ in function?
- A. Corrective controls operate before an event
- B. Preventive controls are technical and detective controls are administrative
- C. Detective controls are always stronger than preventive ones
- D. Preventive controls stop an event occurring, detective controls identify that it occurred, and corrective controls restore the state afterward
Show answer & explanation
Answer: D
The three form a defensive sequence, and a programme relying only on prevention has no way of knowing when prevention failed, which is how compromises persist undetected for long periods. Each type appears in technical, administrative and physical forms, so the functional classification is independent of the implementation category.74. A security awareness programme is measured by completion rates. What is the limitation of that metric?
- A. It measures participation rather than behaviour change, so it can be high while susceptibility to social engineering remains unchanged
- B. It cannot be collected reliably
- C. It is prohibited by privacy regulation
- D. It applies only to technical staff
Show answer & explanation
Answer: A
Completion is an input metric and the outcome the programme exists to change is behaviour, which is better approximated by simulated phishing susceptibility, reporting rates and incidents attributable to user action. Measuring only completion produces a programme optimized for attendance.75. A security manager wants to reduce the risk of insider data theft. Which combination addresses it most completely?
- A. Least privilege and segregation of duties, monitoring of sensitive data access, and defined joiner-mover-leaver processes
- B. Perimeter firewall rules and intrusion prevention alone
- C. Antivirus deployment across all endpoints
- D. Annual penetration testing of external systems
Show answer & explanation
Answer: A
Insider risk originates inside the perimeter with legitimate credentials, so perimeter and malware controls are largely irrelevant to it. The effective measures constrain what an insider can reach, detect abnormal access to sensitive data and remove access promptly when roles change or employment ends.76. A security manager introduces a control that materially slows a revenue-generating process. What is the appropriate course?
- A. Quantify the risk reduction against the business impact and present the trade-off to the accountable business owner for a decision
- B. Implement the control regardless, since security takes precedence
- C. Abandon the control, since business operations take precedence
- D. Implement the control without informing the business
Show answer & explanation
Answer: A
Neither function unilaterally outranks the other, and the accountable owner of the business objective is the party positioned to weigh the trade-off. A security manager who imposes controls without that conversation loses influence over the decisions where it matters most, while one who abandons controls at the first objection provides no assurance at all.77. A third-party supplier will process sensitive data. What should the security manager ensure before onboarding?
- A. Due diligence proportionate to the risk, contractual security requirements including breach notification and audit rights, and defined ongoing monitoring
- B. That the supplier holds any security certification, without reviewing its scope
- C. That the supplier is larger than the organization
- D. That procurement has obtained the lowest price
Show answer & explanation
Answer: A
Supplier risk is managed across the lifecycle rather than at a single gate, so pre-contract diligence, contractual obligations and ongoing monitoring all have a part. A certification with a scope excluding the service being purchased provides no relevant assurance, which is why reading the scope statement matters more than noting the certificate exists.78. A security programme reports a declining number of detected incidents. How should this be interpreted?
- A. Cautiously, since it may indicate improved prevention or degraded detection, and the two require different responses
- B. As unambiguous evidence that security has improved
- C. As evidence that the security budget should be reduced
- D. As evidence that reporting should be discontinued
Show answer & explanation
Answer: A
Detected incident counts measure detection capability as much as underlying incidence, so a fall is ambiguous without corroborating measures such as detection coverage, mean time to detect and external notifications. Treating the decline as success and reducing investment can accelerate the degradation that produced it.79. A security manager inherits a programme with no asset inventory. Why is this the priority to address?
- A. Because controls, risk assessment, vulnerability management and incident scoping all depend on knowing what exists and who owns it
- B. Because inventories are required for software licensing compliance
- C. Because it determines the security team's budget
- D. Because it is the easiest deliverable to complete quickly
Show answer & explanation
Answer: A
Every downstream security activity is bounded by the inventory, since an unknown asset is not patched, monitored, assessed or included in incident scoping. It is also rarely the easiest deliverable, because building and maintaining it requires cooperation from across the organization rather than effort within the security function.80. A vulnerability management programme reports thousands of open findings. How should remediation be prioritized?
- A. By risk to the organization, combining severity with exploitability, exposure and the criticality of the affected asset
- B. By the technical severity score alone, highest first
- C. By the age of the finding, oldest first
- D. By the ease of remediation, simplest first
Show answer & explanation
Answer: A
A high-severity vulnerability on an isolated non-critical system can matter less than a moderate one on an internet-facing system holding sensitive data, so severity scores are an input rather than the ranking. Prioritizing by ease produces a falling count while the genuinely dangerous findings remain open.
Incident Management
20 questions81. During an active ransomware incident, which action should the incident response team take FIRST after detecting the compromise?
- A. Immediately notify all customers before understanding the scope
- B. Contain the affected systems to prevent further spread while preserving evidence
- C. Wait for the next scheduled incident review meeting
- D. Restore from backups without investigating the cause
Show answer & explanation
Answer: B
Containment is the priority immediately after detection, to stop lateral spread and limit damage, while also preserving evidence for forensic analysis and root-cause determination. Notifying customers before scope is understood (A) risks inaccurate or premature communication. Waiting for a scheduled meeting (C) delays a time-critical response. Restoring from backups without investigation (D) risks reintroducing the same vulnerability or malware.82. An organization's incident response plan has not been tested in three years. What is the GREATEST risk this poses?
- A. The plan document may use outdated formatting
- B. Response roles, contact information, and procedures may be outdated or ineffective when a real incident occurs
- C. The plan will automatically expire and become legally invalid
- D. Employees will refuse to follow the plan regardless of its content
Show answer & explanation
Answer: B
Untested plans risk containing outdated contact details, obsolete procedures, or unaddressed changes to systems and personnel, meaning the response team may be unprepared or ineffective during an actual incident. Formatting (A) is a cosmetic concern. Plans do not have automatic legal expiration (C). Employee willingness to follow the plan (D) is unrelated to whether the plan's content itself has become stale.83. Which of the following BEST defines the purpose of a post-incident review (lessons learned) process?
- A. To assign blame to individuals involved in the incident
- B. To identify root causes and process improvements to reduce the likelihood or impact of similar future incidents
- C. To close the incident ticket as quickly as possible without further analysis
- D. To satisfy a public relations requirement only
Show answer & explanation
Answer: B
Post-incident reviews exist to identify root causes and drive process, control, or training improvements that reduce recurrence or impact of similar incidents, feeding continuous improvement of the program. Assigning blame (A) undermines a constructive review culture and discourages honest reporting. Rushing to close tickets (C) forfeits the value of the analysis. Treating it as merely a PR exercise (D) misses its operational purpose.84. During incident response, which of the following is MOST important for maintaining the integrity of digital evidence that may later support legal action?
- A. Allowing any staff member to access and copy the evidence as needed
- B. Maintaining a documented chain of custody for all evidence collected
- C. Deleting evidence once the incident is resolved to save storage space
- D. Storing evidence on the affected system itself for convenience
Show answer & explanation
Answer: B
A documented chain of custody establishes who handled evidence, when, and how, which is essential to prove the evidence has not been altered and is admissible in legal proceedings. Unrestricted access (A) risks tampering or contamination. Deleting evidence (C) destroys material that may be needed later. Storing evidence on the compromised system (D) risks further tampering or loss and is poor forensic practice.85. An organization experiences a data breach involving customer personal information. Which factor is MOST important in determining the appropriate notification timeline and recipients?
- A. The personal preference of the CEO
- B. Applicable legal and regulatory breach notification requirements based on the data and jurisdictions involved
- C. Whichever timeline is easiest for the marketing department
- D. The size of the IT budget for the current year
Show answer & explanation
Answer: B
Breach notification obligations are governed by specific legal and regulatory requirements that vary by data type and jurisdiction, and these requirements dictate timelines and required recipients, making compliance the primary driver. Executive preference (A), marketing convenience (C), and budget size (D) are not valid bases for determining legally mandated notification obligations.86. Which of the following is the PRIMARY benefit of classifying incidents by severity level as part of an incident management process?
- A. It allows the security team to ignore lower severity events entirely
- B. It ensures response resources, escalation, and communication are proportionate to the incident's actual business impact
- C. It reduces the total number of incidents that occur
- D. It eliminates the need for a formal incident response plan
Show answer & explanation
Answer: B
Severity classification allows the organization to allocate response effort, escalation paths, and communication proportionately, ensuring critical incidents get appropriate urgency while minor ones do not consume excessive resources. It does not mean ignoring lower-severity events (A), which still require some response. It has no effect on the actual occurrence rate of incidents (C). It also does not replace the need for a formal response plan (D); rather, severity levels are typically defined within that plan.87. An organization wants to reduce the mean time to detect (MTTD) security incidents. Which investment would MOST directly support this goal?
- A. Increasing the frequency of security awareness training sessions only
- B. Implementing centralized log monitoring and correlation through a SIEM with defined use cases
- C. Reducing the number of firewalls in the network
- D. Publishing the incident response plan on the company intranet
Show answer & explanation
Answer: B
Centralized log monitoring and correlation, such as through a SIEM with tuned detection use cases, directly improves the organization's ability to detect anomalous or malicious activity faster, reducing MTTD. Awareness training alone (A) helps prevent certain incidents but does not directly improve technical detection speed. Reducing firewalls (C) would likely increase risk, not improve detection. Publishing the plan (D) supports response readiness but does not improve detection capability itself.88. During a multi-day incident affecting critical systems, business executives are demanding hourly technical updates that are consuming significant analyst time needed for containment. What is the BEST way for the incident manager to address this?
- A. Refuse to provide any updates until the incident is fully resolved
- B. Designate a dedicated communications liaison to provide scheduled executive updates, freeing technical staff to focus on response
- C. Allow executives to directly interrupt analysts whenever they want an update
- D. Shut down the incident response effort until executive demands subside
Show answer & explanation
Answer: B
Establishing a dedicated communications liaison role is a standard incident management practice that satisfies stakeholder information needs on a predictable schedule while protecting technical responders' focus on containment and eradication. Refusing all updates (A) damages stakeholder trust and violates governance expectations. Allowing direct interruptions (C) worsens the productivity problem. Halting response efforts (D) is an unacceptable escalation that increases organizational harm.89. Which of the following BEST illustrates the difference between an information security incident and a disaster recovery (DR) event?
- A. An incident always requires invoking the full DR plan
- B. An incident is a security-relevant event requiring investigation and response, while DR specifically addresses recovery of IT services after significant disruption
- C. There is no meaningful difference between the two terms
- D. DR events are always caused by malicious actors, while incidents are always accidental
Show answer & explanation
Answer: B
An information security incident is any event that threatens confidentiality, integrity, or availability requiring investigation and response, whereas disaster recovery specifically addresses restoring IT services after a significant disruption, which may or may not stem from a security incident. Not every incident requires full DR invocation (A); many are handled without disrupting service. The terms are not interchangeable (C). DR events are not always malicious, nor are incidents always accidental (D); both can stem from a range of causes.90. An information security manager is defining recovery time objectives (RTOs) for critical systems as part of incident and continuity planning. What should PRIMARILY determine the RTO for a given system?
- A. The preference of the system administrator
- B. The maximum tolerable downtime the business can withstand before unacceptable impact occurs
- C. The age of the hardware supporting the system
- D. The number of support tickets filed for the system last year
Show answer & explanation
Answer: B
RTO should be derived from a business impact analysis reflecting the maximum period the business can tolerate the system being unavailable before harm becomes unacceptable, ensuring recovery planning matches actual business need. Administrator preference (A) is subjective and not risk-based. Hardware age (C) may affect feasibility of recovery but does not define the acceptable downtime threshold. Historical ticket volume (D) reflects support demand, not business criticality.91. An incident response plan defines phases. What is the purpose of the containment phase?
- A. To notify regulators of the breach
- B. To limit the incident's spread and damage while preserving evidence, before eradication of the cause begins
- C. To identify the root cause of the incident
- D. To restore all systems to normal operation
Show answer & explanation
Answer: B
Containment stops the bleeding while retaining the forensic material that eradication and later analysis depend on, which is why hasty rebuilding of a compromised host can destroy the evidence needed to find the other compromised hosts. Eradication removes the cause and recovery restores service, each after containment has bounded the damage.92. During an incident, a responder wants to reboot a compromised server immediately. What is the concern?
- A. Rebooting would alert the attacker
- B. There is no concern, since disk evidence is sufficient
- C. Volatile evidence in memory and active connections would be lost, potentially destroying the only record of how the compromise occurred and what else it reached
- D. The server would take too long to restart
Show answer & explanation
Answer: C
Memory contains running processes, injected code, network connections and often credentials or keys that exist nowhere on disk, and it is lost on power cycle. Order of volatility guides collection, taking the most perishable evidence first, and premature rebuilding is one of the most common ways an investigation loses the ability to scope the compromise.93. An incident response plan requires a communication protocol. Why is this a distinct element?
- A. Because regulatory notification is never time-bound
- B. Because who says what to regulators, customers, staff and media, and when, must be decided in advance rather than improvised under pressure
- C. Because communication is optional in most incidents
- D. Because technical responders should handle all external communication
Show answer & explanation
Answer: B
Communication failures during an incident cause damage independent of the technical event, through contradictory statements, premature assurances later retracted or missed notification deadlines. Predefined spokespeople, approval paths and holding statements are what make coherent communication possible while the facts are still uncertain.94. After an incident is resolved, a post-incident review is held. What is its principal purpose?
- A. To identify what allowed the incident and what impeded the response, producing improvements to controls and to the plan itself
- B. To determine which individual was at fault
- C. To calculate the exact financial loss for accounting
- D. To formally close the incident ticket
Show answer & explanation
Answer: A
The review's value lies in feeding both control improvements and response improvements back into the programme, and a review that stops at the technical cause misses the response friction that determined how bad the incident became. A blame-focused review reliably suppresses the candid information the process depends on.95. How do incident response and business continuity planning relate?
- A. They are alternative names for the same plan
- B. Incident response replaces business continuity for cyber events
- C. Business continuity applies only to natural disasters
- D. Incident response addresses the security event itself while business continuity maintains critical operations, and a severe incident invokes both
Show answer & explanation
Answer: D
The two answer different questions, one about handling the attack and one about continuing to operate while it is handled, and a ransomware event demonstrates why both are needed simultaneously. Plans that are not cross-referenced produce conflicting instructions at exactly the moment coordination matters most.96. An organization measures mean time to detect and mean time to respond. What do these indicate?
- A. The number of incidents occurring per month
- B. How long an adversary operates undetected and how quickly the organization acts once aware, both of which bound the damage an incident causes
- C. The cost of the security operations function
- D. The technical severity of each incident
Show answer & explanation
Answer: B
Dwell time and response latency determine how far an intrusion progresses, which is why they are more actionable than incident counts that reflect threat activity outside the organization's control. Improving them is within the organization's power, making them appropriate programme performance measures.97. An incident may involve criminal activity and potential litigation. What does this require of evidence handling?
- A. A documented chain of custody and forensically sound acquisition, so the evidence remains admissible and its integrity demonstrable
- B. Immediate deletion of affected data to prevent further exposure
- C. Analysis performed only on the original media
- D. Restricting all documentation to verbal briefings
Show answer & explanation
Answer: A
Admissibility depends on demonstrating that evidence was not altered, which requires documented custody and analysis performed on verified copies rather than originals. Involving legal counsel early also matters because privilege and preservation obligations attach before the technical investigation concludes.98. A security manager is asked whether an incident constitutes a reportable breach. What primarily determines this?
- A. The applicable legal and regulatory definitions against the facts established, including the data involved and the jurisdictions of affected individuals
- B. The organization's internal severity rating alone
- C. Whether the media has reported the incident
- D. Whether the attacker has been identified
Show answer & explanation
Answer: A
Reportability is a legal determination made against statutory definitions, which differ in what triggers notification, the deadline and to whom, and multiple regimes can apply where affected individuals span jurisdictions. Internal severity ratings inform response prioritization but have no bearing on statutory obligations.99. A tabletop exercise is run for the incident response team. What does it validate that a technical drill does not?
- A. Decision-making, escalation paths and coordination between technical, legal, communications and executive participants under scenario pressure
- B. The throughput of the detection tooling
- C. The patch level of production systems
- D. The accuracy of the asset inventory
Show answer & explanation
Answer: A
Most incident response failures are decision and coordination failures rather than technical ones, and a tabletop is the only cheap way to surface unclear authority, missing escalation paths and conflicting assumptions between functions. Technical drills validate capability but involve a narrower set of participants.100. What criteria should PRIMARILY determine when an information security incident can formally be closed?
- A. When exactly 30 days have passed since detection, regardless of remediation status.
- B. When the incident response team simply runs out of available time to continue working it.
- C. When the affected business unit stops asking for status updates.
- D. When containment, eradication, and recovery actions are verified complete, the root cause is addressed, and any required documentation and notifications are finished.
Show answer & explanation
Answer: D
An incident should be formally closed only once containment, eradication, and recovery have been verified as complete, the underlying root cause has been addressed to prevent recurrence, and any required documentation or regulatory and stakeholder notifications have been completed, rather than being closed based on an arbitrary elapsed time period, waning attention from the business, or the response team simply moving on to other priorities.
2026 statistics
Key facts: CISM exam
- Questions
- 150
- Time limit
- 4h
- Passing score
- 450 on a scale of 200 to 800
- Exam fee
- $760
- Governing body
- ISACA
This free CISM practice test has 159 original questions written to ISACA's official content outline, last checked against it on July 18, 2026, 100 of them listed on this page and the rest loaded by the drill. Every question shows a worked explanation, and nothing here requires a signup.
The questions are grouped under four outline areas: Information Security Governance, Information Security Risk Management, Information Security Program and Incident Management.
As of 2026, the CISM exam fee is $760 (non-members; $575 ISACA members).
How the CISM practice bank covers the outline
159 questions across 4 outline areas — the same areas the page's sections use.
Counts are the live question bank, grouped by the outline area each question was written to.
Exam format and study resources
More in this family
ISACA certifications
In the same family
More in this category
- ISC2 Certified in Cybersecurity (CC)Practice questions →
- Project Management Professional (PMP)Practice questions →
- Microsoft Certified: Power BI Data Analyst Associate (Exam PL-300)Practice questions →
- Salesforce Certified Platform AdministratorPractice questions →
- HashiCorp Certified: Terraform Associate (004)Practice questions →
- AWS Certified AI PractitionerPractice questions →
- AWS Certified Cloud PractitionerPractice questions →
- AWS Certified Developer - AssociatePractice questions →
- AWS Certified Solutions Architect – AssociatePractice questions →
- Microsoft Certified: Azure Administrator Associate (Exam AZ-104)Practice questions →
- Microsoft Azure AI FundamentalsPractice questions →
Get a free CISM study plan
A week-by-week plan plus new practice questions, straight to your inbox.
Official sources
Primary documents used to verify the exam details shown on this page.
- ISACA Certification Exam Candidate GuideISACAisaca.org
- CISM Exam Content OutlineISACAisaca.org
- CISM Certification OverviewISACAisaca.org
- ISACA (CISA/CRISC/CISM/CGEIT) Scheduling GuidePSIproctor2.psionline.com
- CISA/CRISC/CISM/CGEIT/CDPSE Exam Scheduling GuideISACAisaca.org
Last verified against the official exam content outline:
Frequently asked questions
What is the passing score for the CISM exam, and how is it scored?
The CISM exam is not scored as a simple percentage of questions answered correctly. Instead, ISACA reports a scaled score on a common scale from 200 to 800, where 800 is a perfect score. You must receive a scaled score of 450 or higher to pass. Because the score is scaled rather than raw, you cannot simply count correct answers to know if you passed — the scaling accounts for the relative difficulty of the specific question set you receive.
How many questions are on the CISM exam and how much time do I get?
The CISM exam contains 150 multiple-choice questions and you are given 240 minutes (4 hours) to complete it. That works out to an average of about 1.6 minutes per question, so pacing matters — practice answering under timed conditions so you do not run short at the end. Every question has a stem and four answer options, and you are asked to select the single best answer, which means more than one option may be partially correct.
Which CISM domains should I focus my study time on?
The exam covers four job practice domains: Information Security Governance, Information Security Risk Management, Information Security Program, and Incident Management. They are not weighted equally. Domain 3, Information Security Program, is the largest at 33%, and Domain 4, Incident Management, is next at 30% — together these two account for 63% of the exam. Domain 2, Information Security Risk Management, is 20% and Domain 1, Information Security Governance, is 17%. A smart study plan weights your effort toward Domains 3 and 4, since nearly two-thirds of your score comes from them.
How do I register and schedule the CISM exam, and what does it cost?
You register and pay first: the registration fee is US$575.00 for ISACA members and US$760.00 for non-members. Only after you have registered and paid does ISACA email you that you are eligible to schedule your appointment on the PSI platform — PSI is ISACA's exam delivery vendor. When scheduling, you choose a delivery mode of either an in-person test center or an online remote-proctored exam. Note two deadlines: any rescheduling or cancelling must be done at least 48 hours before your appointment, and once you pass, you have 5 years to apply for the CISM certification.