Practice questions · Cybersecurity
CISM (ISACA): Practice Questions
Ten original concept-check questions on core CISM ideas. Choose an answer to reveal the explanation. Answer as a risk-focused security manager, not a technician.
Answered 0 · Correct 0
-
Compared with CISSP, CISM is most focused on:
Correct answer: D. CISM is a management certification centred on governance, risk and running a security programme, even more than CISSP. -
The primary goal of information security governance is to:
Correct answer: C. Governance exists to ensure security supports and aligns with the organisation's business goals and risk appetite. -
'Risk appetite' is best described as:
Correct answer: C. Risk appetite is how much risk the organisation is willing to take on; tolerance is the acceptable variation around it. -
When an identified risk exceeds the organisation's risk appetite, the security manager should FIRST:
Correct answer: B. The manager assesses options and escalates a recommended response through the governance process rather than acting unilaterally. -
The primary purpose of a Business Impact Analysis (BIA) is to:
Correct answer: B. A BIA identifies critical business functions and the impact of disruption, informing recovery priorities (RTO/RPO). -
A Key Risk Indicator (KRI) differs from a Key Performance Indicator (KPI) in that a KRI:
Correct answer: A. A KRI is a forward-looking signal of increasing risk; a KPI measures how well something is performing. -
'Residual risk' is the risk that remains:
Correct answer: D. Residual risk is what is left after controls reduce inherent risk; management decides whether to accept it. -
When establishing a new security programme, the BEST first step is to:
Correct answer: C. An effective programme starts from business alignment and management commitment, which direct everything that follows. -
During a serious incident, the security manager's priority is to:
Correct answer: B. Incident management follows a plan: contain, eradicate and recover, with communication and lessons learned afterwards. -
Third-party (vendor) risk should be managed by:
Correct answer: C. Vendors extend your attack surface, so their security must be assessed and managed through due diligence and contracts. -
An information security strategy should be aligned primarily with:
Correct answer: A. Security must support business goals to add value. Helpdesk schedules, chasing new tech, or auditor preferences are not the basis for strategy. -
For an information security programme to succeed, ultimate sponsorship should come from:
Correct answer: B. Executive sponsorship provides authority and resources. Administrators, vendors and end users cannot drive enterprise-wide commitment. -
A security policy differs from a standard in that a policy:
Correct answer: B. A policy states high-level intent and direction, while a standard sets the mandatory specifics. 'Lists exact product settings' describes a standard or procedure, 'is optional guidance only' understates a policy's authority, and 'is identical to a standard' ignores the difference altogether. -
The MOST important reason to align security with a recognised framework (ISO 27001, NIST CSF) is to:
Correct answer: C. A framework gives structure and measurability. It does not remove audits, replace staff, or exist mainly for marketing. -
'Due diligence' for a security manager means:
Correct answer: D. Due diligence means taking reasonable, ongoing steps to identify risks and verify that controls work. Buying insurance only, ignoring low-rated risks, and delegating all responsibility are not due diligence and would leave risk unmanaged. -
Qualitative risk analysis differs from quantitative analysis in that qualitative analysis:
Correct answer: A. Qualitative analysis uses relative ratings such as high/medium/low, while quantitative analysis assigns monetary values. 'Always uses precise dollar figures' describes quantitative analysis, and 'ignores likelihood' and 'is only for compliance' are both false of qualitative analysis. -
When valuing an asset for risk purposes, the security manager should consider:
Correct answer: D. Asset value reflects business impact, not just cost. Weight and brand are irrelevant; purchase price alone understates impact. -
Risk treatment options include accept, mitigate, transfer and:
Correct answer: C. The fourth standard option is avoid (eliminate the activity). Ignoring, hiding or delaying are not formal treatments. -
Annual Loss Expectancy (ALE) is calculated as:
Correct answer: D. ALE = SLE x ARO. The other formulas are incorrect. -
A control that detects an incident after it occurs (e.g., log review or an IDS) is a:
Correct answer: C. Detective controls identify events after they happen. Preventive controls stop them, corrective controls fix them, and directive controls instruct behaviour. -
A security awareness programme's primary objective is to:
Correct answer: B. Awareness targets human behaviour, complementing (not replacing) technical controls and reaching all staff, not just IT. -
The security manager should measure programme effectiveness mainly through:
Correct answer: A. Effectiveness is shown by outcome metrics linked to goals, not activity counts, spend or tool inventory. -
Segregation (separation) of duties primarily reduces the risk of:
Correct answer: D. Separation of duties splits a sensitive process so no single person can commit and conceal fraud or error alone. Patch frequency, network latency and hardware cost are unrelated to this control. -
When selecting controls, the security manager should prioritise based on:
Correct answer: A. Controls are justified by cost-effective risk reduction, not novelty, popularity or arbitrary order. -
Proper encryption key management matters because:
Correct answer: A. Encryption is only as strong as its key management. Keys are unrelated to CPU speed or storage and are not email-specific. -
During an incident, the response plan's FIRST priority is usually to:
Correct answer: B. Containment limits harm first. Blame, press and purchases are not the immediate priority. -
The difference between an event and an incident is that an incident:
Correct answer: B. An incident is an event that has, or may have, an adverse impact on security, whereas an event is any observable occurrence. 'Is identical to an event' erases the distinction, and 'is always minor' or 'is always caused externally' add conditions that are not true. -
A post-incident review (lessons learned) mainly aims to:
Correct answer: A. Reviews drive improvement and prevention, not punishment, speed or cost-cutting. -
The Recovery Time Objective (RTO) defines:
Correct answer: A. The Recovery Time Objective is the target time to restore a process after a disruption. The acceptable amount of data loss is the RPO, not the RTO; the total cost of the incident and the number of backups kept are unrelated measures. -
Third-party (vendor) risk is best reduced by:
Correct answer: D. Vendor risk needs assessment and contractual controls. Marketing, avoidance and price alone do not manage the risk.
Practice questions FAQ
- Are these real CISM exam questions?
- No. These are original study questions written to test understanding. They are not real exam questions, exam dumps, or copied from any provider.
- How should I use these practice questions?
- Answer each one, read the explanation (including why the wrong options are wrong), and use the per-domain score below to focus your revision on weak areas. Revisit before exam day.
- How many questions should I do before the exam?
- Enough to score consistently across every domain, alongside full-length practice from official or reputable providers. Understanding why each answer is right matters more than raw volume.
- What score means I am ready?
- A good signal is consistently scoring around 80% or higher across all domains on questions you have not seen before, and being able to explain why the wrong options are wrong.
- Should I use exam dumps?
- No. Dumps (real or leaked questions) breach provider policy, can void your certification, and do not build the understanding the exam actually tests.