Courseiva
← Back to Certified Information Security Manager CISM questions

Scenario-based practice

Select Two (Multi-Select) Questions

Practise Certified Information Security Manager CISM practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
CISM
exam code
ISACA
vendor

Scenario guide

How to approach select two (multi-select) questions

Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.

Quick answer

Select Two (Multi-Select) Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related CISM topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1mediummulti select
Full question →

After a data breach involving customer PII, the incident response team is conducting a root cause analysis. Which THREE factors should be examined according to CISM best practices? (Select THREE.)

Question 2mediummulti select
Full question →

An organization experiences a data breach involving personal information. Which TWO actions should be taken as part of incident response? (Choose two.)

Question 3easymulti select
Full question →

Which THREE are components of the Plan phase in a security program lifecycle (e.g., ISO 27001 PDCA)?

Question 4mediummulti select
Full question →

An organization is updating its incident response plan. Which TWO components should be included to ensure effective evidence handling? (Select TWO.)

Question 5mediummulti select
Full question →

Which TWO of the following are appropriate criteria for escalating an incident to the crisis management team (CMT)? (Select TWO.)

Question 6mediummulti select
Full question →

Which TWO of the following are key components of an information security program governance structure? (Select TWO.)

Question 7easymulti select
Full question →

Which THREE of the following are components of a security operations center (SOC)?

Question 8mediummulti select
Full question →

A security manager is measuring the security culture of the organization. Which three metrics are most appropriate?

Question 9easymulti select
Full question →

Which TWO of the following are indicators of a potential security incident?

Question 10mediummulti select
Full question →

Which THREE of the following are key components of an incident response plan? (Select THREE)

Question 11mediummulti select
Full question →

An information security manager is designing a security program for a multinational organization. Which factors should be considered when developing the program governance structure? (Select 3)

Question 12mediummulti select
Full question →

An information security manager is building a risk register for a newly formed risk management program. Which TWO of the following elements are essential components of each documented risk entry? (Choose two.)

Question 13mediummulti select
Full question →

Which TWO of the following are key components of a security operations center (SOC)? (Select TWO)

Question 14hardmulti select
Full question →

An incident response team is analyzing a phishing email that successfully compromised a user's credentials. Which TWO indicators of compromise (IOCs) should the team prioritize collecting? (Choose two.)

Question 15mediummulti select
Full question →

A security awareness program includes phishing simulations. Which THREE factors should be considered when designing the simulation frequency and difficulty? (Select THREE)

Question 16hardmulti select
Full question →

An organization is implementing a vendor tiering program for third-party risk management. Which TWO criteria should be used to classify vendors into high, medium, or low risk tiers? (Select TWO)

Question 17mediummulti select
Full question →

Which TWO of the following are essential components of an incident response (IR) plan? (Select TWO)

Question 18easymulti select
Read the full Ansible explanation →

An incident response team is creating playbooks for different incident types. Which TWO incident types should have a dedicated playbook? (Select TWO.)

Question 19mediummulti select
Full question →

Which TWO are common challenges in incident management?

Question 20hardmulti select
Full question →

Which of the following are key components of a mature information security program? (Select 2)

These CISM practice questions are part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style CISM questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.