Skip to content

CISM Certified Information Security Manager (CISM) Practice Questions

Prepare for CISM with more than an answer.

1,758 questions in the full set20 sample questionsUpdated Jan 27, 2026
Exam fee
$760 USD
Level
Professional
Valid for
3 years
Domains covered on the exam 4
  1. Information Security Governance17%
  2. Information Security Risk Management20%
  3. Information Security Program33%
  4. Incident Management30%
  1. 1

    Which of the following is MOST appropriate for inclusion in an information security strategy?

    Show answer details

    Correct answer: B

    Explanation: A set of security objectives, processes, methods, tools and techniques together constitute a security strategy. Although IT and business governance are intertwined, business controls may not be included in a security strategy. Budgets will generally not be included in an information security strategy. Additionally, until information security strategy is formulated and implemented, specific tools will not be identified and specific cost estimates will not be available. Firewall rule sets, network defaults and intrusion detection system (IDS) settings are technical details subject to periodic change, and are not appropriate content for a strategy document.

  2. 2

    Senior management commitment and support for information security will BEST be attained by an information security manager by emphasizing:

    Show answer details

    Correct answer: A

    Explanation: Information security exists to help the organization meet its objectives. The information security manager should identify information security needs based on organizational needs. Organizational or business risk should always take precedence. Involving each organizational unit in information security and establishing metrics to measure success will be viewed favorably by senior management after the overall organizational risk is identified.

  3. 3

    Which of the following roles would represent a conflict of interest for an information security manager?

    Show answer details

    Correct answer: C

    Explanation: Since management is ultimately responsible for information security, it should approve information security policy statements; the information security manager should not have final approval.
    Evaluation of third parties requesting access, assessment of disaster recovery plans and monitoring of compliance with physical security controls are acceptable practices and do not present any conflicts of interest.

  4. 4

    Which of the following situations must be corrected FIRST to ensure successful information security governance within an organization?

    Show answer details

    Correct answer: D

    Explanation: A steering committee should be in place to approve all security projects. The fact that the data center manager has final signoff for all security projects indicates that a steering committee is not being used and that information security is relegated to a subordinate place in the organization. This would indicate a failure of information security governance. It is not inappropriate for an
    oversight or steering committee to meet quarterly. Similarly, it may be desirable to have the chief information officer (CIO) approve the security policy due to the size of the organization and frequency of updates. Difficulty in filling vacancies is not uncommon due to the shortage of good, qualified information security professionals.

  5. 5

    A company is integrating security into its software development life cycle (SDLC). The CISM wants to implement a process that proactively identifies potential security flaws at the earliest possible stage. Which of the following would be the MOST effective process to implement during the design and architecture phase?

    flowchart TD A[Start Design] --> B{Decompose Application} B --> C[Identify Entry Points & Trust Boundaries] C --> D[Model Potential Threats] D --> E{Identify Vulnerabilities} E --> F[Define Mitigations] F --> G[Finalize Secure Design]
    Show answer details

    Correct answer: B

    Threat modeling is a structured process performed during the design phase to identify and evaluate potential threats and vulnerabilities from an attacker's perspective. It allows security to be 'built-in' rather than 'bolted-on'. As depicted in the diagram, it involves decomposing the application, identifying threats (e.g., using STRIDE), and defining mitigations before any code is written. SAST, DAST, and penetration testing are performed later in the SDLC, making them reactive rather than proactive design tools.

  6. 6

    Which of the following should be the FIRST step in developing an information security plan?

    Show answer details

    Correct answer: B

    Explanation: Prior to assessing technical vulnerabilities or levels of security awareness, an information security manager needs to gain an understanding of the current business strategy and direction. A business impact analysis should be performed prior to developing a business continuity plan, but this would not be an appropriate first step in developing an information security strategy because it focuses on availability.

  7. 7

    Senior management commitment and support for information security can BEST be obtained through presentations that:

    Show answer details

    Correct answer: D

    Explanation: Senior management seeks to understand the business justification for investing in security. This can best be accomplished by tying security to key business objectives. Senior management will not be as interested in technical risks or examples of successful attacks if they are not tied to the impact on business environment and objectives. Industry best practices are important to senior management but, again, senior management will give them the right level of importance when they are presented in terms of key business objectives.

  8. 8

    The MOST appropriate role for senior management in supporting information security is the:

    Show answer details

    Correct answer: C

    Explanation: Since the members of senior management are ultimately responsible for information security, they are the ultimate decision makers in terms of governance and direction. They are responsible for approval of major policy statements and requests to fund the information security practice.
    Evaluation of vendors, assessment of risks and monitoring compliance with regulatory requirements are day-to-day responsibilities of the information security manager; in some organizations, business management is involved in these other activities, though their primary role is direction and governance.

  9. 9

    Which of the following would BEST ensure the success of information security governance within an organization?

    Show answer details

    Correct answer: A

    Explanation: The existence of a steering committee that approves all security projects would be an indication of the existence of a good governance program. Compliance with laws and regulations is part of the responsibility of the steering committee but it is not a full answer. Awareness training is important at all levels in any medium, and also an indicator of good governance. However, it must be guided and approved as a security project by the steering committee.

  10. 10

    Information security governance is PRIMARILY driven by:

    Show answer details

    Correct answer: D

    Explanation: Governance is directly tied to the strategy and direction of the business. Technology constraints, regulatory requirements and litigation potential are all important factors, but they are necessarily in line with the business strategy.

Create an account to continue.