Courseiva
Back to Certified Information Security Manager CISM questions

Scenario-based practice

Select Two (Multi-Select) Questions

Practise Certified Information Security Manager CISM practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
CISM
exam code
ISACA
vendor

Scenario guide

How to approach select two (multi-select) questions

Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.

Quick answer

Select Two (Multi-Select) Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related CISM topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1mediummulti select
Full question →

An organization experiences a data breach involving personal information. Which TWO actions should be taken as part of incident response? (Choose two.)

Question 2easymulti select
Full question →

Which THREE of the following are typical roles in an incident response team?

Question 3hardmulti select
Full question →

Which TWO of the following are incident categories in an incident management programme?

Question 4hardmulti select
Full question →

An organization is implementing an identity and access management (IAM) program. Which THREE of the following are key components of a mature IAM program?

Question 5hardmulti select
Full question →

An organization is designing a policy exception management process. Which THREE elements are critical for this process to be effective?

Question 6hardmulti select
Full question →

An organization is designing its information security program and needs to ensure it supports business continuity. Which TWO of the following should be integrated into the program?

Question 7hardmulti select
Full question →

Which THREE of the following are challenges in implementing information security governance in a decentralized organization?

Question 8hardmulti select
Full question →

A security manager is evaluating the effectiveness of the security program. Which of the following would be valid indicators of a mature program? (Select two.)

Question 9hardmulti select
Full question →

Which THREE of the following are appropriate members of a crisis management team (CMT) for a major cybersecurity incident? (Select three.)

Question 10mediummulti select
Full question →

Which THREE of the following are common challenges in incident response? (Select exactly 3)

Question 11mediummulti select
Full question →

Which TWO actions are essential during the detection and analysis phase of incident response?

Question 12mediummulti select
Full question →

Which TWO of the following are key components of an information security program governance structure? (Select TWO.)

Question 13mediummulti select
Full question →

A security awareness program includes phishing simulations. Which THREE factors should be considered when designing the simulation frequency and difficulty? (Select THREE)

Question 14mediummulti select
Full question →

An information security manager is developing a security program for a multinational organization. Which of the following should be considered when defining the program scope? (Select THREE)

Question 15mediummulti select
Full question →

Which of the following are key components of an information security program's strategic plan? (Select two.)

Question 16hardmulti select
Full question →

Which THREE are valid sources for threat intelligence that can be used during incident response? (Choose three.)

Question 17hardmulti select
Full question →

Which THREE of the following are common challenges when implementing a risk management program in an organization? (Choose three.)

Question 18mediummulti select
Full question →

An information security manager is designing a security program for a multinational organization. Which factors should be considered when developing the program governance structure? (Select 3)

Question 19mediummulti select
Full question →

A security manager is measuring the security culture of the organization. Which three metrics are most appropriate?

Question 20hardmulti select
Full question →

An organization is updating its security governance framework. Which three elements are essential for ensuring board-level oversight?

These CISM practice questions are part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style CISM questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.