Courseiva
Free · No account needed · No credit card

Certified Information Security Manager CISM Practice Test

924 questions with instant explanations, domain breakdown, and wrong-answer analysis. Built for the real exam.

Instant feedback after each answer
Full explanations included
Domain score breakdown
Real exam: 240 min
Pass mark: 450/1000

Sample questions with explanations

This is exactly what you see during practice — question, options, and a full explanation after you answer.

Q1Information Security Programhard
Full explanation →

A security manager is evaluating the effectiveness of the security program. Which of the following would be valid indicators of a mature program? (Select two.)

ANumber of security tools deployed
Risk management integrated into business processesCorrect
CLow number of security incidents
Trend of improving security metrics over timeCorrect

Risk management integrated into business processes (B) is a key indicator of a mature security program because it demonstrates that security is not a siloed function but is embedded in strategic decision-making, resource allocation, and operational workflows. This alignment ensur…Read full explanation

Q2Information Security Risk Managementhard
Full explanation →

Which TWO of the following are key components of an information risk management program, as defined by ISACA? (Select exactly two.)

ABusiness continuity plan
Risk appetite and toleranceCorrect
CData classification scheme
Risk assessment methodologyCorrect

ISACA defines risk appetite and tolerance (B) as key components because they establish the amount of risk an organization is willing to accept in pursuit of its objectives, providing the criteria against which risks are evaluated and prioritized. A risk assessment methodology (D)…Read full explanation

Q3Information Security Programhard
Full explanation →

A financial institution is developing an information security program based on the COBIT framework. The board has requested a balanced scorecard to communicate program effectiveness. Which of the following metric categories would best align with the 'Internal Processes' perspective?

ACost of security incidents as a percentage of revenue
Percentage of security incidents detected within defined SLAsCorrect
CNumber of security training hours per employee
DCustomer satisfaction survey scores on data protection

The 'Internal Processes' perspective of a balanced scorecard focuses on the efficiency and effectiveness of internal operational processes. The percentage of security incidents detected within defined SLAs directly measures the performance of the security monitoring and incident …Read full explanation

Untimed Practice

Answer at your own pace. Explanation and domain tag shown immediately after each answer.

Timed Practice

Countdown timer starts immediately. Results and domain scores shown at the end — just like the real exam.

Why practice here?

Full explanations on every question

Not just the right answer — you get exactly why each wrong option is wrong, so you learn the concept, not the answer.

Domain score breakdown

After each session see your score by exam domain so you know exactly where to focus study time.

100% free, forever

No subscription, no trial, no email wall. Start a session in under 10 seconds.

Exam-style questions

Scenario-based, precise wording, realistic distractors — written to match what you actually see on exam day.

← All CISM questionsCISM exam guideStudy guidePractice by domain