PRACTICE ENGINE · CISM

CISM Practice Exam.
Free practice test — 34 verified questions, instant feedback.

Progress saves on this device — no signup
Difficulty
QUESTION 1 / 34Information Security GovernanceEasy
A candidate wants to know how the CISM exam is delivered. Which of the following correctly describes the available delivery modes?
0/0session

Know the exam before you sit it

the facts most prep sites bury
Pass rate
150
Scored questions
4h m time limit
450 on a scale of 200 to 800
Passing score
Set by the governing body
Study by section weight
The cheat sheet is built like the exam blueprint →

Every free resource for this exam

family overview →

Get a free CISM study plan

A week-by-week plan plus new practice questions, straight to your inbox.

Frequently asked questions

What is the passing score for the CISM exam, and how is it scored?

The CISM exam is not scored as a simple percentage of questions answered correctly. Instead, ISACA reports a scaled score on a common scale from 200 to 800, where 800 is a perfect score. You must receive a scaled score of 450 or higher to pass. Because the score is scaled rather than raw, you cannot simply count correct answers to know if you passed — the scaling accounts for the relative difficulty of the specific question set you receive.

How many questions are on the CISM exam and how much time do I get?

The CISM exam contains 150 multiple-choice questions and you are given 240 minutes (4 hours) to complete it. That works out to an average of about 1.6 minutes per question, so pacing matters — practice answering under timed conditions so you do not run short at the end. Every question has a stem and four answer options, and you are asked to select the single best answer, which means more than one option may be partially correct.

Which CISM domains should I focus my study time on?

The exam covers four job practice domains: Information Security Governance, Information Security Risk Management, Information Security Program, and Incident Management. They are not weighted equally. Domain 3, Information Security Program, is the largest at 33%, and Domain 4, Incident Management, is next at 30% — together these two account for 63% of the exam. Domain 2, Information Security Risk Management, is 20% and Domain 1, Information Security Governance, is 17%. A smart study plan weights your effort toward Domains 3 and 4, since nearly two-thirds of your score comes from them.

How do I register and schedule the CISM exam, and what does it cost?

You register and pay first: the registration fee is US$575.00 for ISACA members and US$760.00 for non-members. Only after you have registered and paid does ISACA email you that you are eligible to schedule your appointment on the PSI platform — PSI is ISACA's exam delivery vendor. When scheduling, you choose a delivery mode of either an in-person test center or an online remote-proctored exam. Note two deadlines: any rescheduling or cancelling must be done at least 48 hours before your appointment, and once you pass, you have 5 years to apply for the CISM certification.

Browse all questions & answers
  1. 1. A candidate wants to know how the CISM exam is delivered. Which of the following correctly describes the available delivery modes?

    • A. Only in-person at a test center, with no remote option
    • B. Candidates may choose either an in-person test center or an online remote-proctored option
    • C. Only through a mobile app with no proctoring
    • D. Exclusively through employer-sponsored on-site testing
    Show answer & explanation

    Answer: B
    Candidates select between an in-person test center delivery or an online remote-proctored exam, giving flexibility in how they sit for the CISM exam. There is a remote option, so in-person only (A) is incorrect. There is no unproctored mobile app option (C). Testing is not restricted to employer-sponsored on-site sessions (D).

  2. 2. An ISACA member and a non-member are both planning to register for the CISM exam. What is the difference in the registration fee between them?

    • A. There is no fee difference; both pay the same amount
    • B. The non-member fee is US$185 higher than the member fee (US$760 vs. US$575)
    • C. The member fee is higher because members receive additional exam attempts
    • D. The non-member fee is only US$50 higher than the member fee
    Show answer & explanation

    Answer: B
    ISACA members pay US$575 while non-members pay US$760 for CISM exam registration, a difference of US$185, reflecting the value of ISACA membership. There is a fee difference, so equal pricing (A) is incorrect. Members do not pay more (C), and the actual difference is significantly more than US$50 (D).

  3. 3. A candidate wants to understand what scaled score is needed to pass the CISM exam and how the scoring scale works. Which statement is accurate?

    • A. A raw percentage of 70% correct answers is required to pass
    • B. A scaled score of 450 or higher on a 200-800 scale is required to pass
    • C. A scaled score of 800 is the minimum passing score
    • D. Passing is determined solely by the number of questions attempted, not answered correctly
    Show answer & explanation

    Answer: B
    ISACA reports CISM scores on a common scaled range of 200 to 800, and a candidate needs a scaled score of 450 or higher to pass, which does not directly correspond to a simple raw percentage. Passing is not based on a raw 70% figure (A), since the scale is not a straight percentage conversion. A score of 800 is the maximum, not the minimum passing threshold (C). Passing depends on performance/correctness, not merely on the number of questions attempted (D).

  4. 4. Which of the following BEST demonstrates that an organization's information security strategy is aligned with business objectives?

    • A. The security budget increases every fiscal year
    • B. Security initiatives are prioritized and funded based on their support of documented business goals
    • C. The security team reports directly to the CEO
    • D. All security policies have been reviewed within the past 12 months
    Show answer & explanation

    Answer: B
    Strategic alignment means security decisions and investments are driven by business objectives, which is best evidenced by prioritization and funding tied to those goals. A growing budget (A) does not prove alignment, only spending. Reporting structure (C) may support governance but does not itself demonstrate alignment. Policy review cadence (D) reflects maintenance, not strategic linkage.

  5. 5. An information security steering committee is being formed. Which composition BEST supports effective governance oversight?

    • A. Only members of the IT department, since they understand the technical risks
    • B. Senior representatives from business units, IT, legal, HR, and risk management
    • C. External auditors exclusively, to ensure independence
    • D. The information security manager alone, to avoid conflicting priorities
    Show answer & explanation

    Answer: B
    A steering committee needs cross-functional representation from business and support functions so that security decisions reflect enterprise-wide risk appetite and objectives, which is a core governance principle. Limiting membership to IT (A) ignores business context. External auditors only (C) removes internal accountability. A single individual (D) is not a committee and lacks diverse input.

  6. 6. An organization's information security policy has not been updated in five years, though the business has since adopted cloud computing and remote work extensively. What is the GREATEST risk of this situation?

    • A. Employees may not have read the policy
    • B. The policy no longer reflects the current risk environment, leaving gaps in governance and control coverage
    • C. The policy document is a different font than newer documents
    • D. Legal counsel was not involved in the original drafting
    Show answer & explanation

    Answer: B
    Governance frameworks and policies must evolve with the business and technology landscape; an outdated policy fails to address new risk domains like cloud and remote access, creating real control gaps. Whether employees read it (A) is a separate awareness issue. Formatting (C) is irrelevant. Legal involvement in drafting (D) does not address the current relevance problem.

  7. 7. During a risk assessment, an information security manager identifies a legacy application with a known vulnerability, but the business unit refuses to fund remediation because the system will be decommissioned in six months. What is the MOST appropriate next step?

    • A. Force decommissioning immediately regardless of business needs
    • B. Document the risk, ensure it is formally accepted by an authorized business owner, and implement compensating controls if feasible
    • C. Ignore the finding since the system will soon be retired
    • D. Escalate directly to external regulators
    Show answer & explanation

    Answer: B
    Risk management requires that residual risk be formally accepted by someone with the authority to do so, and compensating controls should be applied where practical to reduce exposure in the interim. Forcing decommissioning (A) is outside the security manager's authority and may harm the business. Ignoring the finding (C) abdicates the manager's responsibility to track and report risk. Escalating to regulators (D) is disproportionate for an internally manageable risk decision.

  8. 8. When calculating risk during a quantitative risk assessment, which formula BEST represents the relationship between the key variables typically used?

    • A. Risk = Asset Value / Threat Frequency
    • B. Risk = Likelihood of a threat exploiting a vulnerability × Impact of that occurrence
    • C. Risk = Number of controls implemented
    • D. Risk = Cost of the asset minus insurance coverage
    Show answer & explanation

    Answer: B
    Risk is fundamentally a function of the likelihood that a threat will exploit a vulnerability and the resulting impact, which is the basis of both qualitative and quantitative risk models. Dividing asset value by frequency (A) is not a recognized risk formula. Counting controls (C) measures mitigation effort, not risk itself. Subtracting insurance from cost (D) relates to financial risk transfer, not the underlying risk calculation.

  9. 9. An organization decides to purchase cyber insurance to address the financial impact of a potential ransomware attack rather than investing further in prevention controls. This is an example of which risk treatment option?

    • A. Risk avoidance
    • B. Risk transfer
    • C. Risk acceptance
    • D. Risk mitigation
    Show answer & explanation

    Answer: B
    Purchasing insurance shifts the financial consequence of a risk event to a third party, which is the definition of risk transfer. Risk avoidance (A) would mean eliminating the activity that creates the risk entirely. Risk acceptance (C) means retaining the risk without further action or transfer. Risk mitigation (D) involves reducing likelihood or impact through controls, which the organization explicitly chose not to do further.

  10. 10. A risk register lists a high-likelihood, high-impact risk with no assigned owner or treatment plan. What is the BEST immediate action for the information security manager?

    • A. Delete the entry since it lacks an owner
    • B. Assign an accountable risk owner and drive development of a treatment plan with a target date
    • C. Wait until the next annual risk assessment cycle
    • D. Transfer the risk to the audit department by default
    Show answer & explanation

    Answer: B
    A high-likelihood, high-impact risk without ownership represents a governance gap that must be closed by assigning accountability and driving a concrete treatment plan promptly, given the severity. Deleting the entry (A) hides the risk rather than managing it. Waiting a full cycle (C) is inappropriate given the severity. Defaulting ownership to audit (D) is inappropriate since audit provides independent assurance, not risk ownership.

  11. 11. Which of the following is the MOST important reason to perform periodic reassessment of previously identified and accepted risks?

    • A. To satisfy an arbitrary documentation requirement
    • B. Because the threat landscape, asset value, and control environment can change, altering the risk's likelihood or impact over time
    • C. To reduce the size of the risk register
    • D. Because auditors always require it regardless of business context
    Show answer & explanation

    Answer: B
    Risk is dynamic; changes in threats, business context, asset criticality, or controls can shift a previously acceptable risk into an unacceptable one, so periodic reassessment ensures acceptance decisions remain valid. Documentation for its own sake (A) misses the substantive purpose. Reducing register size (C) is not a legitimate driver of reassessment. Framing it purely as an audit requirement (D) ignores the risk-management rationale that underlies the practice.

  12. 12. An organization is evaluating two risk treatment options for a vulnerable legacy system: patching it now for a moderate cost, or replacing it next year at a much higher cost with lower risk reduction in the interim. What should PRIMARILY drive this decision?

    • A. The personal preference of the IT manager
    • B. A cost-benefit analysis comparing the risk reduction achieved against the cost and timing of each option
    • C. Whichever option requires less paperwork
    • D. The vendor offering the largest discount
    Show answer & explanation

    Answer: B
    Risk treatment decisions should be grounded in a cost-benefit analysis that weighs the reduction in risk exposure against implementation cost and timeline, ensuring resources are allocated efficiently. Personal preference (A) is subjective and unaccountable. Minimizing paperwork (C) is an administrative convenience, not a risk-based criterion. Vendor discounts (D) should not override a proper risk-based evaluation.

  13. 13. A company's risk appetite statement specifies that it will not accept any risk with the potential for regulatory fines exceeding a defined threshold. A newly identified risk exceeds this threshold but is inexpensive to remediate. What should the information security manager recommend?

    • A. Accept the risk since remediation cost is a separate consideration
    • B. Remediate the risk to bring it within the defined risk appetite
    • C. Escalate to the board only if the fine is actually imposed
    • D. Transfer all responsibility to the compliance department without further security involvement
    Show answer & explanation

    Answer: B
    When a risk exceeds the organization's documented risk appetite, and remediation is feasible and low-cost, treatment should be pursued to bring the risk within acceptable bounds, which is the direct purpose of a risk appetite statement. Accepting it anyway (A) violates the organization's own stated risk tolerance. Waiting for an actual fine (C) is reactive rather than proactive risk management. Fully offloading responsibility (D) ignores the security manager's role in risk treatment recommendations.

  14. 14. An information security program is being designed for a mid-sized organization. Which of the following BEST reflects a properly structured security program?

    • A. A single antivirus product deployed across all endpoints
    • B. A set of coordinated policies, standards, processes, and controls aligned to the security strategy and risk appetite
    • C. An annual penetration test with no other ongoing activity
    • D. A dedicated incident response team with no supporting policies
    Show answer & explanation

    Answer: B
    An information security program is the coordinated set of policies, standards, processes, and controls that implement the strategy and manage risk to an acceptable level; it is holistic, not a single tool or event. A single antivirus deployment (A) is one control, not a program. An isolated annual pen test (C) is a point-in-time activity, not an ongoing program. A response team without governing policies (D) lacks the structural foundation a program requires.

  15. 15. Which of the following is the PRIMARY purpose of a security awareness training program within an information security program?

    • A. To satisfy a checkbox requirement for annual audits
    • B. To reduce human-related risk by ensuring employees understand their security responsibilities and recognize common threats
    • C. To replace the need for technical controls
    • D. To provide a source of revenue through internal training fees
    Show answer & explanation

    Answer: B
    Awareness training exists to reduce the human element of risk by equipping staff to recognize threats like phishing and understand their security obligations, directly supporting the program's risk-reduction goals. Treating it as a mere audit checkbox (A) misses its substantive purpose. It does not replace technical controls (C); it complements them. Internal revenue generation (D) is not a legitimate program objective.

  16. 16. An information security manager is selecting metrics to report program performance to the board. Which characteristic is MOST important for these metrics to have?

    • A. They should be highly technical to demonstrate the team's expertise
    • B. They should be meaningful to a business audience and tied to risk reduction or business impact
    • C. They should change every quarter to appear dynamic
    • D. They should focus solely on the number of security incidents, regardless of severity
    Show answer & explanation

    Answer: B
    Board-level metrics must translate security activity into business-relevant terms, such as risk reduction or impact avoidance, so non-technical leadership can make informed decisions. Overly technical metrics (A) fail to communicate to the intended audience. Constantly changing metrics (C) prevent meaningful trend analysis. Raw incident counts without severity context (D) can be misleading and do not convey actual risk posture.

  17. 17. A security program includes a control requiring segregation of duties between developers and production system administrators. What is the PRIMARY security benefit of this control?

    • A. It reduces the number of employees needed
    • B. It reduces the risk of unauthorized or unreviewed changes being introduced into production
    • C. It eliminates the need for change management processes
    • D. It guarantees compliance with all data privacy regulations
    Show answer & explanation

    Answer: B
    Segregation of duties between development and production administration prevents a single individual from introducing and deploying unreviewed or malicious changes, reducing fraud and error risk. It does not reduce headcount needs (A) as a security rationale. It does not eliminate change management (C); rather it complements it. It also does not guarantee full regulatory compliance (D), which depends on many other controls.

  18. 18. An organization is implementing a data classification scheme as part of its security program. What is the MOST important reason for classifying data BEFORE applying protective controls?

    • A. Classification is required only for marketing purposes
    • B. It ensures that controls are proportionate to the sensitivity and value of the data, avoiding both under- and over-protection
    • C. It allows the organization to charge different prices for data storage
    • D. It removes the need for encryption on all data
    Show answer & explanation

    Answer: B
    Classification allows security resources and controls to be applied proportionately, protecting highly sensitive data appropriately while avoiding wasteful over-controlling of low-sensitivity data. It has no marketing purpose (A). It is not a billing mechanism (C). It does not remove the need for encryption (D); rather it helps determine where encryption and other controls are most necessary.

  19. 19. A vulnerability management program consistently identifies critical vulnerabilities that remain unpatched for over six months due to competing IT priorities. What is the BEST course of action for the information security manager?

    • A. Accept the delays as normal since IT is busy
    • B. Work with IT leadership to establish and enforce risk-based remediation SLAs tied to vulnerability severity
    • C. Personally patch the systems without IT involvement
    • D. Stop scanning for vulnerabilities to avoid generating findings IT cannot address
    Show answer & explanation

    Answer: B
    Establishing enforceable, risk-based service level agreements for remediation aligns IT priorities with actual risk severity and creates accountability, addressing the root cause of chronic delays. Simply accepting delays (A) allows unacceptable risk exposure to persist. Bypassing IT to patch directly (C) violates change control and role boundaries. Stopping scans (D) hides risk rather than managing it and is a serious governance failure.

  20. 20. When integrating security requirements into the systems development life cycle (SDLC), at which phase is it MOST cost-effective to identify and address security requirements?

    • A. During production after deployment
    • B. During the requirements and design phases, before development begins
    • C. Only during user acceptance testing
    • D. During the post-incident review after a breach
    Show answer & explanation

    Answer: B
    Addressing security requirements early, during requirements gathering and design, is the most cost-effective point because defects and gaps are far cheaper to fix before code is written than after deployment. Fixing issues in production (A) is significantly more expensive and risky. Limiting security review to UAT (C) misses architectural issues that are hard to retrofit. Waiting for a post-incident review (D) means damage has already occurred.

  21. 21. An information security manager is developing key performance indicators (KPIs) for the vulnerability management process. Which KPI provides the MOST meaningful insight into program effectiveness?

    • A. Total number of vulnerability scans run per month
    • B. Average time to remediate critical vulnerabilities compared to defined SLA targets
    • C. Number of security tools purchased for scanning
    • D. Number of employees on the vulnerability management team
    Show answer & explanation

    Answer: B
    Time-to-remediate against SLA targets directly measures whether the organization is closing high-risk exposures promptly, which is the actual goal of vulnerability management. Scan counts (A) measure activity, not outcomes. Tool purchases (C) and headcount (D) are inputs/resources, not indicators of program effectiveness.

  22. 22. Which of the following BEST describes the role of an information security program in supporting business continuity?

    • A. The security program is entirely separate from business continuity and should not interact with it
    • B. The security program provides controls and processes, such as backup protection and access continuity, that support the organization's ability to maintain and recover critical operations
    • C. Business continuity planning is solely the responsibility of facilities management
    • D. Security controls should be disabled during a declared disaster to speed up recovery
    Show answer & explanation

    Answer: B
    An effective security program integrates with business continuity by protecting the confidentiality, integrity, and availability of the resources and processes needed for recovery, such as securing backups and ensuring continued access controls. Treating the two as unrelated (A) ignores this necessary integration. Continuity planning is a cross-functional responsibility, not exclusively facilities' domain (C). Disabling controls during a disaster (D) increases risk exactly when the organization is most vulnerable.

  23. 23. Which of the following is the MOST important consideration when selecting security controls to include in an information security program?

    • A. Selecting the newest technology available regardless of fit
    • B. Ensuring controls are proportionate to identified risks and aligned with business and regulatory requirements
    • C. Selecting controls solely based on vendor marketing claims
    • D. Choosing the least expensive controls available
    Show answer & explanation

    Answer: B
    Controls should be selected based on a proportionate response to actual identified risks and must satisfy applicable business and regulatory requirements, ensuring resources are well spent and compliance obligations are met. Chasing the newest technology (A) without a risk basis wastes resources. Relying on vendor marketing (C) is not a sound evaluation method. Choosing purely on cost (D) ignores whether the control actually addresses the risk.

  24. 24. During an active ransomware incident, which action should the incident response team take FIRST after detecting the compromise?

    • A. Immediately notify all customers before understanding the scope
    • B. Contain the affected systems to prevent further spread while preserving evidence
    • C. Wait for the next scheduled incident review meeting
    • D. Restore from backups without investigating the cause
    Show answer & explanation

    Answer: B
    Containment is the priority immediately after detection, to stop lateral spread and limit damage, while also preserving evidence for forensic analysis and root-cause determination. Notifying customers before scope is understood (A) risks inaccurate or premature communication. Waiting for a scheduled meeting (C) delays a time-critical response. Restoring from backups without investigation (D) risks reintroducing the same vulnerability or malware.

  25. 25. An organization's incident response plan has not been tested in three years. What is the GREATEST risk this poses?

    • A. The plan document may use outdated formatting
    • B. Response roles, contact information, and procedures may be outdated or ineffective when a real incident occurs
    • C. The plan will automatically expire and become legally invalid
    • D. Employees will refuse to follow the plan regardless of its content
    Show answer & explanation

    Answer: B
    Untested plans risk containing outdated contact details, obsolete procedures, or unaddressed changes to systems and personnel, meaning the response team may be unprepared or ineffective during an actual incident. Formatting (A) is a cosmetic concern. Plans do not have automatic legal expiration (C). Employee willingness to follow the plan (D) is unrelated to whether the plan's content itself has become stale.

  26. 26. Which of the following BEST defines the purpose of a post-incident review (lessons learned) process?

    • A. To assign blame to individuals involved in the incident
    • B. To identify root causes and process improvements to reduce the likelihood or impact of similar future incidents
    • C. To close the incident ticket as quickly as possible without further analysis
    • D. To satisfy a public relations requirement only
    Show answer & explanation

    Answer: B
    Post-incident reviews exist to identify root causes and drive process, control, or training improvements that reduce recurrence or impact of similar incidents, feeding continuous improvement of the program. Assigning blame (A) undermines a constructive review culture and discourages honest reporting. Rushing to close tickets (C) forfeits the value of the analysis. Treating it as merely a PR exercise (D) misses its operational purpose.

  27. 27. During incident response, which of the following is MOST important for maintaining the integrity of digital evidence that may later support legal action?

    • A. Allowing any staff member to access and copy the evidence as needed
    • B. Maintaining a documented chain of custody for all evidence collected
    • C. Deleting evidence once the incident is resolved to save storage space
    • D. Storing evidence on the affected system itself for convenience
    Show answer & explanation

    Answer: B
    A documented chain of custody establishes who handled evidence, when, and how, which is essential to prove the evidence has not been altered and is admissible in legal proceedings. Unrestricted access (A) risks tampering or contamination. Deleting evidence (C) destroys material that may be needed later. Storing evidence on the compromised system (D) risks further tampering or loss and is poor forensic practice.

  28. 28. An organization experiences a data breach involving customer personal information. Which factor is MOST important in determining the appropriate notification timeline and recipients?

    • A. The personal preference of the CEO
    • B. Applicable legal and regulatory breach notification requirements based on the data and jurisdictions involved
    • C. Whichever timeline is easiest for the marketing department
    • D. The size of the IT budget for the current year
    Show answer & explanation

    Answer: B
    Breach notification obligations are governed by specific legal and regulatory requirements that vary by data type and jurisdiction, and these requirements dictate timelines and required recipients, making compliance the primary driver. Executive preference (A), marketing convenience (C), and budget size (D) are not valid bases for determining legally mandated notification obligations.

  29. 29. Which of the following is the PRIMARY benefit of classifying incidents by severity level as part of an incident management process?

    • A. It allows the security team to ignore lower severity events entirely
    • B. It ensures response resources, escalation, and communication are proportionate to the incident's actual business impact
    • C. It reduces the total number of incidents that occur
    • D. It eliminates the need for a formal incident response plan
    Show answer & explanation

    Answer: B
    Severity classification allows the organization to allocate response effort, escalation paths, and communication proportionately, ensuring critical incidents get appropriate urgency while minor ones do not consume excessive resources. It does not mean ignoring lower-severity events (A), which still require some response. It has no effect on the actual occurrence rate of incidents (C). It also does not replace the need for a formal response plan (D); rather, severity levels are typically defined within that plan.

  30. 30. An organization wants to reduce the mean time to detect (MTTD) security incidents. Which investment would MOST directly support this goal?

    • A. Increasing the frequency of security awareness training sessions only
    • B. Implementing centralized log monitoring and correlation through a SIEM with defined use cases
    • C. Reducing the number of firewalls in the network
    • D. Publishing the incident response plan on the company intranet
    Show answer & explanation

    Answer: B
    Centralized log monitoring and correlation, such as through a SIEM with tuned detection use cases, directly improves the organization's ability to detect anomalous or malicious activity faster, reducing MTTD. Awareness training alone (A) helps prevent certain incidents but does not directly improve technical detection speed. Reducing firewalls (C) would likely increase risk, not improve detection. Publishing the plan (D) supports response readiness but does not improve detection capability itself.

  31. 31. During a multi-day incident affecting critical systems, business executives are demanding hourly technical updates that are consuming significant analyst time needed for containment. What is the BEST way for the incident manager to address this?

    • A. Refuse to provide any updates until the incident is fully resolved
    • B. Designate a dedicated communications liaison to provide scheduled executive updates, freeing technical staff to focus on response
    • C. Allow executives to directly interrupt analysts whenever they want an update
    • D. Shut down the incident response effort until executive demands subside
    Show answer & explanation

    Answer: B
    Establishing a dedicated communications liaison role is a standard incident management practice that satisfies stakeholder information needs on a predictable schedule while protecting technical responders' focus on containment and eradication. Refusing all updates (A) damages stakeholder trust and violates governance expectations. Allowing direct interruptions (C) worsens the productivity problem. Halting response efforts (D) is an unacceptable escalation that increases organizational harm.

  32. 32. Which of the following BEST illustrates the difference between an information security incident and a disaster recovery (DR) event?

    • A. An incident always requires invoking the full DR plan
    • B. An incident is a security-relevant event requiring investigation and response, while DR specifically addresses recovery of IT services after significant disruption
    • C. There is no meaningful difference between the two terms
    • D. DR events are always caused by malicious actors, while incidents are always accidental
    Show answer & explanation

    Answer: B
    An information security incident is any event that threatens confidentiality, integrity, or availability requiring investigation and response, whereas disaster recovery specifically addresses restoring IT services after a significant disruption, which may or may not stem from a security incident. Not every incident requires full DR invocation (A); many are handled without disrupting service. The terms are not interchangeable (C). DR events are not always malicious, nor are incidents always accidental (D); both can stem from a range of causes.

  33. 33. An information security manager is defining recovery time objectives (RTOs) for critical systems as part of incident and continuity planning. What should PRIMARILY determine the RTO for a given system?

    • A. The preference of the system administrator
    • B. The maximum tolerable downtime the business can withstand before unacceptable impact occurs
    • C. The age of the hardware supporting the system
    • D. The number of support tickets filed for the system last year
    Show answer & explanation

    Answer: B
    RTO should be derived from a business impact analysis reflecting the maximum period the business can tolerate the system being unavailable before harm becomes unacceptable, ensuring recovery planning matches actual business need. Administrator preference (A) is subjective and not risk-based. Hardware age (C) may affect feasibility of recovery but does not define the acceptable downtime threshold. Historical ticket volume (D) reflects support demand, not business criticality.

  34. 34. A candidate is planning their CISM certification timeline after passing the exam. Which statement about the certification application process is accurate?

    • A. Candidates must apply for certification within 5 years of passing the exam
    • B. Candidates must apply for certification within 30 days of passing the exam
    • C. There is no time limit to apply for certification after passing
    • D. Certification is granted automatically the moment the exam is passed
    Show answer & explanation

    Answer: A
    Candidates have a five-year window from their exam pass date to submit their certification application, which is separate from the exam-eligibility registration window. A 30-day limit (B) is incorrect and far too short. There is in fact a defined limit, so it is not unlimited (C). Certification is not automatic (D); candidates must submit an application, including verified work experience, before being certified.