ISACA · Free Practice Questions · Last reviewed May 2026
30real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
17% of exam · 6 sample questions below
Which of the following is the PRIMARY responsibility of the board of directors regarding information security governance?
Performing technical vulnerability assessments
Approving specific security tools and technologies
Conducting daily security monitoring activities
Setting the strategic direction and oversight of the security programme
The board provides strategic direction and oversight, ensuring alignment with business goals.
An organization has a decentralized governance model where each business unit manages its own security. What is a key challenge of this model?
Lower cost due to elimination of central security team
Rapid decision-making due to fewer layers
Increased central control and uniformity
Inconsistent security policies and controls across units
Without central oversight, policies can vary widely.
A CISO is developing a multi-year security roadmap. Which of the following should be the PRIMARY driver for prioritizing initiatives?
Ease of implementation
Availability of new technology
Alignment with business strategy and risk appetite
Security must support business goals and risk tolerance.
Cost of the initiative
Which capability maturity model (CMM) level indicates that security processes are proactively measured and optimized?
Level 4 (Managed)
Level 2 (Repeatable)
Level 5 (Optimizing)
Level 5 focuses on continuous improvement and optimization based on metrics.
Level 3 (Defined)
An organization is implementing a new security policy. Which step should occur AFTER the policy is approved?
Stakeholder consultation
Gap analysis
Training and communication
After approval, the policy must be communicated and trained.
Legal review
Which board-level metric is MOST useful for measuring the effectiveness of the incident response process?
Mean time to respond (MTTR)
MTTR indicates how quickly the organization responds to incidents.
Patch compliance percentage
Mean time to detect (MTTD)
Number of security incidents
Want more Information Security Governance practice?
Practice this domain30% of exam · 6 sample questions below
An organization's incident response (IR) policy should be approved by which of the following to ensure authority and accountability?
The incident response manager
The legal counsel
The IT director
The board of directors or executive management
Senior management approval ensures policy authority and resource commitment.
During a P1 (critical) incident, the incident response manager has been providing hourly situation reports (sitreps) to executives. What is the primary reason for involving legal counsel in these communications?
To approve technical containment actions
To preserve attorney-client privilege and avoid creating damaging records
Legal counsel helps maintain privilege and prevent statements that could be used against the organization.
To coordinate with external forensics firms
To ensure compliance with regulatory notification deadlines
An organization has experienced a ransomware incident that has encrypted critical servers. The incident response team is unable to restore operations within the maximum tolerable downtime (MTD). Which action should be taken next?
Notify law enforcement
Increase the ransom payment
Escalate to activate the business continuity/disaster recovery plan
BC/DR activation is triggered when MTD is at risk, ensuring continuity of critical functions.
Engage the forensics firm to preserve evidence
Which incident severity level requires executive notification and a 24/7 response?
P2 — High
P3 — Medium
P1 — Critical
P1 incidents are critical with major business impact, requiring executive notification and 24/7 response.
P4 — Low
Following a data breach, an organization conducts a root cause analysis using the 5 Whys technique. The analysis identifies that a misconfigured firewall allowed unauthorized access. What is the most important next step to prevent recurrence?
Implement a change management process to prevent unauthorized configuration changes
Addressing the process failure that allowed the misconfiguration prevents similar issues across the organization.
Update the firewall rule base immediately
Conduct a vulnerability scan on all firewalls
Disconnect the firewall from the network
An organization's incident response plan includes playbooks for different incident types. Which playbook should be used for an incident involving unauthorized access to a user's account due to phishing?
Data breach playbook
Ransomware playbook
Credential compromise playbook
Credential compromise covers phishing, password spraying, and account takeover.
Insider threat playbook
Want more Incident Management practice?
Practice this domain17% of exam · 6 sample questions below
A CISO is evaluating the reporting structure for the information security team. Which reporting line is generally considered MOST effective for ensuring independence and organizational influence?
Report to the Chief Financial Officer (CFO)
Report to the Chief Information Officer (CIO)
Report to the board of directors or audit committee
This structure provides independence, authority, and visibility at the highest level.
Report to the Chief Operating Officer (COO)
An organization is implementing a security controls framework and needs to prioritize which controls to implement first. According to CIS Controls v8, which approach aligns with the principle of 'implementation groups'?
Focus only on controls that address the greatest risks regardless of group
Implement IG3 controls first as they are the most advanced
Start with all controls from IG1, then move to IG2 and IG3 as resources allow
IG1 represents basic cyber hygiene controls that are essential for all organizations.
Implement controls from all groups simultaneously to achieve comprehensive coverage
During a third-party risk assessment, the security team discovers that a critical vendor's sub-supplier (nth party) has access to sensitive data. The vendor contract does not address nth-party risk. What is the BEST course of action?
Accept the risk because the vendor is contractually responsible
Revise the contract to require the vendor to flow down security requirements to sub-suppliers
This ensures the vendor manages nth-party risks contractually.
Perform an on-site assessment of the sub-supplier
Request that the vendor terminate the sub-supplier relationship
Which of the following is a LEADING indicator of security performance?
Cost of a data breach
Mean time to detect (MTTD)
Number of security incidents
Patch compliance percentage
Patch compliance is a leading indicator of vulnerability management effectiveness.
An information security manager is designing a security awareness program. Which approach BEST addresses the different learning needs of various employee groups?
Use only phishing simulations as training
Focus training only on high-risk groups such as system administrators
Provide the same annual training to all employees to ensure consistency
Deliver role-based training: secure coding for developers, social engineering for executives, and basic awareness for all
Role-based training addresses specific risks associated with each role.
A security manager needs to justify an increase in the security budget. Which metric is MOST compelling to demonstrate the value of security investments to the board?
Number of phishing simulations conducted
Percentage of IT budget allocated to security
Return on investment (ROI) from avoided breach costs
ROI shows the financial benefit of security spending.
Number of security tools deployed
Want more Information Security Programme practice?
Practice this domain16% of exam · 6 sample questions below
An organization's information security program has been in place for two years. During a recent audit, several findings indicated that security controls are not consistently applied across business units. The CISO has been asked to improve the program. Which of the following should the CISO do FIRST?
Automate security compliance monitoring across all business units.
Update the information security policy to mandate compliance.
Conduct a risk assessment to identify gaps and prioritize remediation.
A risk assessment provides the basis for prioritizing controls and ensuring consistent application based on risk.
Implement additional security controls across all business units.
A multinational corporation is designing its information security program and must decide how to balance security with business agility. The company operates in highly regulated industries with varying legal requirements. Which of the following approaches BEST aligns with industry best practices for such an environment?
Implement the strictest regulatory requirements globally to ensure compliance everywhere.
Adopt a baseline of controls that meet the lowest common denominator of all regulations.
Develop a risk-based framework that allows for tailored controls based on local risk assessments.
A risk-based approach provides flexibility while ensuring that controls are appropriate for the risks.
Allow each business unit to define its own security controls based on local requirements.
An organization is developing a new information security program and wants to ensure it aligns with business objectives. Which of the following is the MOST critical first step?
Develop a security awareness training program.
Identify business strategy and risk appetite.
Aligning with business strategy ensures security enables rather than hinders the business.
Design the security architecture based on industry frameworks.
Conduct a comprehensive risk assessment.
During a merger, two companies with different information security programs are being integrated. The combined entity must maintain compliance with PCI DSS and GDPR. The CISO is concerned about gaps in coverage due to differing maturity levels. Which of the following is the BEST approach to harmonize the programs?
Adopt the more stringent security program from the acquirer across the entire entity.
Merge the two programs by combining all controls from each.
Implement a completely new framework that meets both regulations.
Perform a gap analysis against the requirements and prioritize remediation.
A gap analysis provides a clear picture of what is missing and allows for efficient resource allocation.
Which TWO of the following are key components of an information security program governance structure? (Select TWO.)
A steering committee that includes senior management and business unit leaders.
A steering committee ensures alignment with business strategy and provides oversight.
An incident response plan that defines roles and procedures.
Regular reporting to the board of directors on security metrics and risks.
Reporting to the board ensures visibility and accountability.
A vulnerability scanning schedule and remediation SLAs.
A firewall policy that specifies allowed and denied traffic.
Refer to the exhibit. An analyst observes the network traffic between three internal hosts and a web server. Which of the following is the MOST likely interpretation of this traffic?
A SYN flood attack is in progress.
A single host is using multiple IP addresses to scan the server.
Multiple users are accessing the web server normally.
The logs show successful TCP connections followed by HTTP requests.
A distributed denial-of-service (DDoS) attack is occurring.
Want more Information Security Program practice?
Practice this domain20% of exam · 6 sample questions below
A financial institution is implementing a new online banking platform. The risk assessment identified that the authentication module has a high likelihood of exploitation due to weak password policies. The risk owner has decided to implement multi-factor authentication (MFA) to reduce the risk. This is an example of which risk response strategy?
Risk avoidance
Risk mitigation
MFA reduces the likelihood or impact of the risk, which is the definition of risk mitigation.
Risk acceptance
Risk transfer
An organization has a risk appetite that allows for a maximum residual risk level of 'medium' for all operational risks. A new project introduces a risk with inherent risk level 'high' and control effectiveness rated as 'partially effective'. The risk owner proposes to accept the risk. As the CISM, what is the best course of action?
Accept the risk since the risk owner has agreed.
Transfer the risk to an insurance company.
Insist on additional controls to reduce residual risk to at least 'medium'.
This ensures residual risk aligns with appetite, which is the correct risk management approach.
Recommend revising the risk appetite to accommodate this risk.
During a risk assessment, a CISM identifies that the organization's data backup process has a single point of failure. The backup server is located in the same data center as the primary server. Which risk response is most appropriate?
Mitigate by moving the backup server to a geographically separate location.
This reduces the likelihood of both servers being lost simultaneously.
Transfer the risk by purchasing business interruption insurance.
Avoid the risk by discontinuing the backup process.
Accept the risk because the cost of mitigation is high.
A multinational corporation is assessing the risk of data breaches from third-party vendors. The CISM is tasked with selecting a risk treatment strategy. The organization has a low risk appetite for data breaches. Which strategy should be prioritized?
Mitigate the risk by conducting regular vendor audits.
Avoid the risk by not engaging vendors that cannot meet security requirements.
Avoidance eliminates the risk entirely, fitting low appetite.
Transfer the risk by requiring vendors to have cyber insurance.
Accept the risk because third-party risks are unavoidable.
In a risk assessment, a CISM calculates the annualized loss expectancy (ALE) for a specific threat. The single loss expectancy (SLE) is $50,000 and the annualized rate of occurrence (ARO) is 0.2. What is the ALE, and which risk response is most cost-effective if a control costs $12,000 per year and reduces ARO to 0.05?
Accept the risk because the control is not cost-justified.
The cost of control is greater than the risk reduction benefit, so acceptance is appropriate.
Accept the risk because ALE after control is only $2,500.
Implement the control because it reduces ALE to $2,500.
Implement the control because ALE is $10,000, and control cost is only $12,000.
A company is evaluating its risk management process. The CISM notices that risks are being assessed based on qualitative scales (low, medium, high) but decisions require quantitative data. What is the most effective action to improve the process?
Switch to a fully quantitative risk assessment methodology.
Use a hybrid approach that includes both qualitative and quantitative assessments.
Provides comprehensive risk information for decision-making.
Replace qualitative scales with precise monetary values.
Continue using qualitative method since it is simpler.
Want more Information Security Risk Management practice?
Practice this domainThe CISM exam has 150 questions and must be completed in 240 minutes. The passing score is 450/1000.
Scenario-based management questions on information security governance, risk management, programme development, and incident response.
The exam covers 5 domains: Information Security Governance, Incident Management, Information Security Programme, Information Security Program, Information Security Risk Management. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official ISACA CISM exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.