Practice questions · Cybersecurity

CISM (ISACA): Practice Questions

advanced 30 questions

Ten original concept-check questions on core CISM ideas. Choose an answer to reveal the explanation. Answer as a risk-focused security manager, not a technician.

By The Exam Atlas Editorial Team · Verified 2026-05-31 · ~38 min

  1. Information Security Governance easy

    Compared with CISSP, CISM is most focused on:

  2. Information Security Governance easy

    The primary goal of information security governance is to:

  3. Information Security Risk Management medium

    'Risk appetite' is best described as:

  4. Information Security Risk Management medium

    When an identified risk exceeds the organisation's risk appetite, the security manager should FIRST:

  5. Information Security Risk Management medium

    The primary purpose of a Business Impact Analysis (BIA) is to:

  6. Information Security Governance medium

    A Key Risk Indicator (KRI) differs from a Key Performance Indicator (KPI) in that a KRI:

  7. Information Security Risk Management medium

    'Residual risk' is the risk that remains:

  8. Information Security Program medium

    When establishing a new security programme, the BEST first step is to:

  9. Incident Management medium

    During a serious incident, the security manager's priority is to:

  10. Information Security Risk Management medium

    Third-party (vendor) risk should be managed by:

  11. Information Security Governance medium

    An information security strategy should be aligned primarily with:

  12. Information Security Governance medium

    For an information security programme to succeed, ultimate sponsorship should come from:

  13. Information Security Governance medium

    A security policy differs from a standard in that a policy:

  14. Information Security Governance hard

    The MOST important reason to align security with a recognised framework (ISO 27001, NIST CSF) is to:

  15. Information Security Governance easy

    'Due diligence' for a security manager means:

  16. Information Security Risk Management medium

    Qualitative risk analysis differs from quantitative analysis in that qualitative analysis:

  17. Information Security Risk Management medium

    When valuing an asset for risk purposes, the security manager should consider:

  18. Information Security Risk Management medium

    Risk treatment options include accept, mitigate, transfer and:

  19. Information Security Risk Management hard

    Annual Loss Expectancy (ALE) is calculated as:

  20. Information Security Risk Management medium

    A control that detects an incident after it occurs (e.g., log review or an IDS) is a:

  21. Information Security Program medium

    A security awareness programme's primary objective is to:

  22. Information Security Program medium

    The security manager should measure programme effectiveness mainly through:

  23. Information Security Program medium

    Segregation (separation) of duties primarily reduces the risk of:

  24. Information Security Program hard

    When selecting controls, the security manager should prioritise based on:

  25. Information Security Program medium

    Proper encryption key management matters because:

  26. Incident Management medium

    During an incident, the response plan's FIRST priority is usually to:

  27. Incident Management medium

    The difference between an event and an incident is that an incident:

  28. Incident Management medium

    A post-incident review (lessons learned) mainly aims to:

  29. Incident Management hard

    The Recovery Time Objective (RTO) defines:

  30. Information Security Risk Management medium

    Third-party (vendor) risk is best reduced by:

Practice questions FAQ

Are these real CISM exam questions?
No. These are original study questions written to test understanding. They are not real exam questions, exam dumps, or copied from any provider.
How should I use these practice questions?
Answer each one, read the explanation (including why the wrong options are wrong), and use the per-domain score below to focus your revision on weak areas. Revisit before exam day.
How many questions should I do before the exam?
Enough to score consistently across every domain, alongside full-length practice from official or reputable providers. Understanding why each answer is right matters more than raw volume.
What score means I am ready?
A good signal is consistently scoring around 80% or higher across all domains on questions you have not seen before, and being able to explain why the wrong options are wrong.
Should I use exam dumps?
No. Dumps (real or leaked questions) breach provider policy, can void your certification, and do not build the understanding the exam actually tests.

Sources