ISACA · Free Practice Questions · Last reviewed May 2026
30real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
17% of exam · 6 sample questions below
Which of the following is the PRIMARY responsibility of the board of directors regarding information security governance?
Performing technical vulnerability assessments
Approving specific security tools and technologies
Conducting daily security monitoring activities
Setting the strategic direction and oversight of the security programme
The board owns governance, not implementation. Setting strategic direction and overseeing the security programme aligns security with business objectives and risk appetite, which is the board's primary governance duty rather than operational or technical decisions.
An organization has a decentralized governance model where each business unit manages its own security. What is a key challenge of this model?
Lower cost due to elimination of central security team
Rapid decision-making due to fewer layers
Increased central control and uniformity
Inconsistent security policies and controls across units
Decentralised governance lets each business unit set its own controls, so without a central authority enforcing baselines, policies diverge in strength and coverage. That fragmentation directly satisfies the stem's challenge: inconsistent security policies and controls across units, raising gaps and complicating enterprise-wide risk reporting.
A CISO is developing a multi-year security roadmap. Which of the following should be the PRIMARY driver for prioritizing initiatives?
Ease of implementation
Availability of new technology
Alignment with business strategy and risk appetite
A multi-year roadmap consumes limited budget and resources, so initiatives must map to business strategy and the organisation's risk appetite. That alignment ensures security investment addresses the risks the business actually cares about, rather than technical preference alone.
Cost of the initiative
Which capability maturity model (CMM) level indicates that security processes are proactively measured and optimized?
Level 4 (Managed)
Level 2 (Repeatable)
Level 5 (Optimizing)
At Level 5 (Optimizing), processes are continuously improved through quantitative measurement and feedback, satisfying the stem's requirement for proactively measured and optimised security. Lower levels merely define, manage or quantitatively control processes without this continuous optimisation focus.
Level 3 (Defined)
An organization is implementing a new security policy. Which step should occur AFTER the policy is approved?
Stakeholder consultation
Gap analysis
Training and communication
An approved policy is inert until staff know and follow it. Training and communication disseminates the approved requirements to affected personnel, ensuring awareness and enabling subsequent enforcement, monitoring and compliance activities that depend on people understanding their obligations.
Legal review
Which board-level metric is MOST useful for measuring the effectiveness of the incident response process?
Mean time to respond (MTTR)
Mean time to respond measures the elapsed time from incident detection to containment or resolution, giving the board a quantifiable view of incident response effectiveness. This directly satisfies the stem's requirement for a board-level metric, unlike operational counts such as tickets closed.
Patch compliance percentage
Mean time to detect (MTTD)
Number of security incidents
Want more Information Security Governance practice?
Practice this domain30% of exam · 6 sample questions below
An organization's incident response (IR) policy should be approved by which of the following to ensure authority and accountability?
The incident response manager
The legal counsel
The IT director
The board of directors or executive management
Board or executive management approval confers enterprise-wide authority and accountability, since only top leadership can mandate compliance across all business units and commit resources. This satisfies the policy's requirement for authority and accountability by placing ownership at the highest governance level.
An organization has experienced a ransomware incident that has encrypted critical servers. The incident response team is unable to restore operations within the maximum tolerable downtime (MTD). Which action should be taken next?
Notify law enforcement
Increase the ransom payment
Escalate to activate the business continuity/disaster recovery plan
When recovery cannot meet the maximum tolerable downtime, the incident ceases to be a technical problem and becomes a continuity problem. Escalating to activate the business continuity/disaster recovery plan invokes pre-authorised alternate processing arrangements, restoring critical services through failover rather than waiting for server restoration.
Engage the forensics firm to preserve evidence
Which incident severity level requires executive notification and a 24/7 response?
P2 — High
P3 — Medium
P1 — Critical
P1 Critical denotes the highest severity, where business-critical systems or data are affected, so the plan mandates immediate round-the-clock response and escalation to executives. This satisfies the stem's requirement linking executive notification with continuous 24/7 response.
P4 — Low
Following a data breach, an organization conducts a root cause analysis using the 5 Whys technique. The analysis identifies that a misconfigured firewall allowed unauthorized access. What is the most important next step to prevent recurrence?
Implement a change management process to prevent unauthorized configuration changes
The 5 Whys exposed a governance gap: unauthorised firewall configuration changes were possible. Change management enforces approval, testing and documentation for configuration alterations, directly addressing that root cause. Patching or monitoring alone would not prevent recurrence of the underlying control weakness.
Update the firewall rule base immediately
Conduct a vulnerability scan on all firewalls
Disconnect the firewall from the network
An organization's incident response plan includes playbooks for different incident types. Which playbook should be used for an incident involving unauthorized access to a user's account due to phishing?
Data breach playbook
Ransomware playbook
Credential compromise playbook
Phishing that yields unauthorised account access is credential compromise, so the credential compromise playbook prescribes password resets, session revocation, MFA enforcement and account monitoring. A malware or data breach playbook would not address the stolen-credential vector that enabled the intrusion.
Insider threat playbook
Which of the following is typically a member of the crisis management team (CMT) during a major cybersecurity incident?
Chief executive officer (CEO)
The CEO sits on the crisis management team because major incidents demand strategic decisions on business continuity, regulatory disclosure, and resource authorisation that exceed operational authority. Their presence satisfies the stem's requirement for executive-level command during a major cybersecurity incident.
Security operations center (SOC) analyst
Help desk manager
External forensics investigator
Want more Incident Management practice?
Practice this domain17% of exam · 6 sample questions below
A CISO is evaluating the reporting structure for the information security team. Which reporting line is generally considered MOST effective for ensuring independence and organizational influence?
Report to the Chief Financial Officer (CFO)
Report to the Chief Information Officer (CIO)
Report to the board of directors or audit committee
Reporting to the board or audit committee gives security direct access to governing authority, free from operational conflicts inherent in reporting through IT or finance. This structural independence enables escalation, budget influence and objective oversight of management's risk decisions.
Report to the Chief Operating Officer (COO)
An organization is implementing a security controls framework and needs to prioritize which controls to implement first. According to CIS Controls v8, which approach aligns with the principle of 'implementation groups'?
Focus only on controls that address the greatest risks regardless of group
Implement IG3 controls first as they are the most advanced
Start with all controls from IG1, then move to IG2 and IG3 as resources allow
CIS Controls v8 defines Implementation Group 1 as foundational cyber hygiene, with IG2 and IG3 adding maturity. This satisfies the stem by sequencing IG1 controls first, then progressing as resources allow, matching the defined implementation group structure.
Implement controls from all groups simultaneously to achieve comprehensive coverage
During a third-party risk assessment, the security team discovers that a critical vendor's sub-supplier (nth party) has access to sensitive data. The vendor contract does not address nth-party risk. What is the BEST course of action?
Accept the risk because the vendor is contractually responsible
Revise the contract to require the vendor to flow down security requirements to sub-suppliers
Contractual flow-down clauses extend security requirements to sub-suppliers, closing the nth-party gap the existing agreement leaves open. This addresses the root cause — absent contractual control — rather than merely monitoring a vendor that has no obligation to enforce sub-supplier security.
Perform an on-site assessment of the sub-supplier
Request that the vendor terminate the sub-supplier relationship
Which of the following is a LEADING indicator of security performance?
Cost of a data breach
Mean time to detect (MTTD)
Number of security incidents
Patch compliance percentage
Patch compliance percentage measures control execution before breaches occur, making it predictive rather than retrospective. Unlike incident counts, which record past failures, it signals whether vulnerability exposure is being actively reduced, so it functions as a leading indicator.
An information security manager is designing a security awareness program. Which approach BEST addresses the different learning needs of various employee groups?
Use only phishing simulations as training
Focus training only on high-risk groups such as system administrators
Provide the same annual training to all employees to ensure consistency
Deliver role-based training: secure coding for developers, social engineering for executives, and basic awareness for all
Role-based delivery matches content to each group's actual risk exposure: developers need secure coding, executives need social engineering awareness, and everyone needs baseline awareness. This satisfies the stem's constraint of addressing differing learning needs across employee groups simultaneously.
A security manager needs to justify an increase in the security budget. Which metric is MOST compelling to demonstrate the value of security investments to the board?
Number of phishing simulations conducted
Percentage of IT budget allocated to security
Return on investment (ROI) from avoided breach costs
ROI from avoided breach costs translates security spending into financial terms the board already uses for capital decisions. This satisfies the stem by expressing value as quantifiable monetary return, making the budget request directly comparable to other investment proposals.
Number of security tools deployed
Want more Information Security Programme practice?
Practice this domain16% of exam · 6 sample questions below
An organization's information security program has been in place for two years. During a recent audit, several findings indicated that security controls are not consistently applied across business units. The CISO has been asked to improve the program. Which of the following should the CISO do FIRST?
Automate security compliance monitoring across all business units.
Update the information security policy to mandate compliance.
Conduct a risk assessment to identify gaps and prioritize remediation.
A risk assessment establishes which control gaps matter most and their business impact, giving the CISO evidence to prioritise remediation across business units. Acting on audit findings without this analysis risks misallocating limited resources to lower-impact issues.
Implement additional security controls across all business units.
A multinational corporation is designing its information security program and must decide how to balance security with business agility. The company operates in highly regulated industries with varying legal requirements. Which of the following approaches BEST aligns with industry best practices for such an environment?
Implement the strictest regulatory requirements globally to ensure compliance everywhere.
Adopt a baseline of controls that meet the lowest common denominator of all regulations.
Develop a risk-based framework that allows for tailored controls based on local risk assessments.
A risk-based framework lets the corporation apply controls proportionate to assessed local risk, accommodating differing legal requirements across regulated jurisdictions while preserving business agility. Uniform or purely compliance-driven controls cannot flex to each region's distinct regulatory and risk profile.
Allow each business unit to define its own security controls based on local requirements.
An organization is developing a new information security program and wants to ensure it aligns with business objectives. Which of the following is the MOST critical first step?
Develop a security awareness training program.
Identify business strategy and risk appetite.
Aligning security with business objectives requires first understanding the organisation's strategic direction and its tolerance for risk. Identifying business strategy and risk appetite establishes the foundation on which all subsequent security decisions, controls and priorities are built.
Design the security architecture based on industry frameworks.
Conduct a comprehensive risk assessment.
During a merger, two companies with different information security programs are being integrated. The combined entity must maintain compliance with PCI DSS and GDPR. The CISO is concerned about gaps in coverage due to differing maturity levels. Which of the following is the BEST approach to harmonize the programs?
Adopt the more stringent security program from the acquirer across the entire entity.
Merge the two programs by combining all controls from each.
Implement a completely new framework that meets both regulations.
Perform a gap analysis against the requirements and prioritize remediation.
A gap analysis against PCI DSS and GDPR requirements identifies where each legacy programme falls short, letting the CISO prioritise remediation by risk and compliance impact. This harmonises differing maturity levels using a common control baseline rather than adopting one company's programme wholesale.
Which TWO of the following are key components of an information security program governance structure? (Select TWO.)
A steering committee that includes senior management and business unit leaders.
A steering committee ensures alignment with business strategy and provides oversight.
An incident response plan that defines roles and procedures.
Regular reporting to the board of directors on security metrics and risks.
Reporting to the board ensures visibility and accountability.
A vulnerability scanning schedule and remediation SLAs.
A firewall policy that specifies allowed and denied traffic.
Refer to the exhibit. An analyst observes the network traffic between three internal hosts and a web server. Which of the following is the MOST likely interpretation of this traffic?
A SYN flood attack is in progress.
A single host is using multiple IP addresses to scan the server.
Multiple users are accessing the web server normally.
Traffic from three internal hosts to one web server, using standard HTTP/HTTPS ports with normal request-response patterns and no scanning or spoofing signatures, indicates routine browsing. Multiple clients reaching the same server is expected behaviour, so the traffic reflects ordinary user access rather than an attack.
A distributed denial-of-service (DDoS) attack is occurring.
Want more Information Security Program practice?
Practice this domain20% of exam · 6 sample questions below
A financial institution is implementing a new online banking platform. The risk assessment identified that the authentication module has a high likelihood of exploitation due to weak password policies. The risk owner has decided to implement multi-factor authentication (MFA) to reduce the risk. This is an example of which risk response strategy?
Risk avoidance
Risk mitigation
Implementing MFA reduces the likelihood of exploitation by adding a second authentication factor, lowering the inherent risk while retaining the activity. Mitigation treats risk through controls rather than transferring, avoiding or accepting it, matching the risk owner's decision.
Risk acceptance
Risk transfer
An organization has a risk appetite that allows for a maximum residual risk level of 'medium' for all operational risks. A new project introduces a risk with inherent risk level 'high' and control effectiveness rated as 'partially effective'. The risk owner proposes to accept the risk. As the CISM, what is the best course of action?
Accept the risk since the risk owner has agreed.
Transfer the risk to an insurance company.
Insist on additional controls to reduce residual risk to at least 'medium'.
Residual risk equals inherent risk adjusted by control effectiveness. Partially effective controls on a high inherent risk likely leave residual risk above the mandated medium ceiling, so acceptance breaches risk appetite and additional controls are required.
Recommend revising the risk appetite to accommodate this risk.
During a risk assessment, a CISM identifies that the organization's data backup process has a single point of failure. The backup server is located in the same data center as the primary server. Which risk response is most appropriate?
Mitigate by moving the backup server to a geographically separate location.
Relocating the backup server to a geographically separate location removes the shared data-centre failure domain, so a site-wide incident cannot destroy both primary and backup copies simultaneously. This mitigation directly addresses the identified single point of failure, restoring recoverability.
Transfer the risk by purchasing business interruption insurance.
Avoid the risk by discontinuing the backup process.
Accept the risk because the cost of mitigation is high.
In a risk assessment, a CISM calculates the annualized loss expectancy (ALE) for a specific threat. The single loss expectancy (SLE) is $50,000 and the annualized rate of occurrence (ARO) is 0.2. What is the ALE, and which risk response is most cost-effective if a control costs $12,000 per year and reduces ARO to 0.05?
Accept the risk because the control is not cost-justified.
ALE equals SLE multiplied by ARO: $50,000 × 0.2 = $10,000. The control costs $12,000 annually while reducing expected loss to $2,500, a $7,500 benefit, so it is not cost-justified. Accepting the risk is therefore the most cost-effective response.
Accept the risk because ALE after control is only $2,500.
Implement the control because it reduces ALE to $2,500.
Implement the control because ALE is $10,000, and control cost is only $12,000.
A company is evaluating its risk management process. The CISM notices that risks are being assessed based on qualitative scales (low, medium, high) but decisions require quantitative data. What is the most effective action to improve the process?
Switch to a fully quantitative risk assessment methodology.
Use a hybrid approach that includes both qualitative and quantitative assessments.
A hybrid approach keeps qualitative scales for rapid triage while adding quantitative values, such as monetary loss ranges or probabilities, that support cost-benefit and risk-appetite decisions. This closes the gap where qualitative ratings alone cannot feed quantitative analysis.
Replace qualitative scales with precise monetary values.
Continue using qualitative method since it is simpler.
Which TWO of the following are key components of an information risk management program, as defined by ISACA? (Select exactly two.)
Business continuity plan
Risk appetite and tolerance
ISACA defines risk appetite and tolerance as core programme components: they express how much risk the organisation is willing to pursue or retain, and they bound every subsequent assessment, treatment and acceptance decision within the risk management framework.
Data classification scheme
Risk assessment methodology
A structured risk assessment methodology is a core ISACA component because it defines how assets, threats and vulnerabilities are identified, analysed and evaluated against defined risk criteria. This satisfies the stem's requirement for a key program component by ensuring consistent, repeatable risk determination that underpins subsequent treatment decisions across the organisation.
Vulnerability scanning process
Want more Information Security Risk Management practice?
Practice this domainThe CISM exam has 150 questions and must be completed in 240 minutes. The passing score is 450/1000.
Scenario-based management questions on information security governance, risk management, programme development, and incident response.
The exam covers 5 domains: Information Security Governance, Incident Management, Information Security Programme, Information Security Program, Information Security Risk Management. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official ISACA CISM exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.