About the Exam

ISACA’s CISM certification validates expertise in information security governance, program development and management, incident management, and risk management. The exam is intended for mid- to advanced-career IT professionals who are pursuing senior management roles in IT security and control. Passing the exam demonstrates knowledge of the four CISM job practice domains and is a required step toward certification.

Exam Topics

  • Information Security Governance17%
  • Information Security Risk Management20%
  • Information Security Program33%
  • Incident Management30%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated July 13, 2026 at 3:40 AM

Topic filter
Retired questions
Question sort
Questions per page

QuestionQ1

Information Security Program

During which of the following development phases is it MOST difficult to implement security controls?

Explanation

Implementing security controls after deployment often requires retrofitting an existing system, changing established architecture and configurations, retesting functionality, and potentially disrupting operations. Security is more effectively built into the design and development phases.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

Information Security Risk Management

An organization is concerned about the possibility that vulnerabilities in its server systems could be exploited. Which of the following is the BEST control for mitigating the related risk?

Explanation

Enforcing standard system configurations based on secure configuration benchmarks hardens servers by disabling unnecessary services, applying secure settings, and reducing common misconfigurations that attackers can exploit. Monitoring, logging, and host-based IDS provide detection or investigation capabilities but do not prevent the underlying vulnerabilities from being exposed.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

Information Security Program

Which of the following is the first step in developing a business continuity plan (BCP)?

Explanation

Business continuity planning starts by identifying critical business processes so the organization can assess their disruption impact and establish recovery priorities. Recovery strategies, resource requirements, and application recovery objectives follow from that analysis.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

Information Security Risk Management

Which of the following is the MOST important outcome of effective risk treatment?

Explanation

Effective risk treatment requires the implementation of corrective actions or other selected measures to address identified risk. Risk is managed to an acceptable level rather than necessarily eliminated.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

Information Security Risk Management

An organization’s marketing department wants to use an online collaboration service that does not comply with the information security policy. A risk assessment has been performed, and risk acceptance is being sought. Who should approve the risk acceptance?

Explanation

Acceptance of residual risk for a business use that does not comply with security policy requires authorization by senior business management, because that level is accountable for accepting risk to organizational operations. Security, compliance, and risk officers provide assessment, oversight, or advice rather than assuming the business risk. NIST describes authorization as a senior-official decision to explicitly accept organizational risk.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!
Know a question that should be here? Contribute to this exam
Back home