Courseiva
← Back to Certified Information Security Manager CISM questions

Scenario-based practice

Refer to the Exhibit Practice Questions

Practise Certified Information Security Manager CISM practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

12
scenario questions
CISM
exam code
ISACA
vendor

Scenario guide

How to approach refer to the exhibit practice questions

Practise exhibit-style questions that ask you to read a topology, table, command output or diagram before choosing the best answer.

Quick answer

Exhibit-style questions test whether you can read a topology, command output, diagram or table before choosing the best answer.

How to extract the relevant detail from an exhibit.

How topology, command output or routing information affects the answer.

How to avoid answering from memory before reading the evidence.

How to map the exhibit back to the exam objective.

Related practice questions

Related CISM topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1mediummultiple choice
Full question →

Based on the exhibit, what is the MOST likely scenario?

Exhibit

Refer to the exhibit.

Exhibit:

Event Log Entry:
Time: 2023-10-05 14:23:17
Event ID: 4625
Source: Security
User: SYSTEM
Logon Type: 3
Account Name: jdoe
Account Domain: CORP
Failure Reason: Unknown user name or bad password.
Workstation Name: WS-001
IP Address: 192.168.1.50

Event Log Entry:
Time: 2023-10-05 14:24:05
Event ID: 4624
Source: Security
User: SYSTEM
Logon Type: 3
Account Name: jdoe
Account Domain: CORP
Workstation Name: WS-001
IP Address: 192.168.1.50

Event Log Entry:
Time: 2023-10-05 14:25:10
Event ID: 4648
Source: Security
User: jdoe
Logon Type: 2
Account Name: jdoe
Account Domain: CORP
Target Server: FILE-SRV-01
Additional Info: A logon was attempted using explicit credentials.
Workstation Name: WS-001
IP Address: 192.168.1.50
Question 2hardmultiple choice
Full question →

Refer to the exhibit. An organization uses these firewall rules. After a breach, the IR team finds that the attacker gained access via SSH from an external IP. Which rule is most likely misconfigured?

Exhibit

Firewall Rule (inbound): allow tcp any any 22 (SSH) log
Firewall Rule (inbound): allow tcp 10.0.0.0/24 any 3389 (RDP) log
Firewall Rule (inbound): allow tcp any any 80 (HTTP) log
Firewall Rule (inbound): allow tcp any any 443 (HTTPS) log
Firewall Rule (inbound): allow tcp 10.0.0.0/24 any 3306 (MySQL) log
Question 3mediummultiple choice
Full question →

Based on the exhibit, what is the most significant security gap in this configuration?

Exhibit

Refer to the exhibit.

Exhibit:
```
{
  "securityControls": {
    "firewall": {
      "state": "active",
      "rules": [
        {"action": "allow", "src": "any", "dst": "web-servers", "port": 443},
        {"action": "allow", "src": "web-servers", "dst": "db-servers", "port": 3306},
        {"action": "deny", "src": "any", "dst": "any", "port": "any"}
      ]
    },
    "intrusionDetection": {
      "state": "active",
      "signatures": ["critical", "high"],
      "action": "alert"
    },
    "vendorBaseline": "CIS Level 1"
  }
}
```
This JSON policy is for a web application environment. The db-servers network is considered internal.
Question 4mediummultiple choice
Full question →

Refer to the exhibit. An information security manager reviews the risk register and sees that Risk ID R001 has a residual risk of High with a treatment of Accept. Which of the following best explains why this situation may indicate a governance failure?

Exhibit

Refer to the exhibit.

```
Risk Register Excerpt:
Risk ID: R001
Risk Description: Unauthorized disclosure of sensitive customer data due to weak encryption.
Inherent Risk: High
Control Effectiveness: Partially effective
Residual Risk: High
Risk Owner: CISO
Risk Treatment: Accept
```
Question 5hardmultiple choice
Full question →

Based on the exhibit, which role is missing from the governance policy that would be essential for enforcing accountability?

Exhibit

Refer to the exhibit.

```
$ cat governance_policy.json
{
  "policyName": "Information Security Governance Policy",
  "version": "2.0",
  "scope": "All business units and subsidiaries",
  "roles": {
    "board": "Approve risk appetite and review security performance quarterly",
    "ceo": "Provide strategic direction and resources",
    "ciso": "Develop and implement security program",
    "businessManagers": "Ensure compliance within their units",
    "internalAudit": "Independent assurance on governance effectiveness"
  },
  "processes": {
    "riskAssessment": "Annual risk assessment and quarterly updates",
    "strategyAlignment": "Annual review of security strategy with business strategy",
    "reporting": "Quarterly dashboard to board, monthly to management"
  }
}
```
Question 6easymultiple choice
Full question →

Given the exhibit, what is the MOST significant governance gap in the described architecture?

Exhibit

Refer to the exhibit.

```
NETWORK ARCHITECTURE DESCRIPTION
- Internet edge: Firewall cluster (active-active) with IPS
- DMZ: Web servers, external-facing applications
- Internal network segregated into VLANs by business unit
- Management network for system administrators
- Security Operations Center (SOC) monitors all traffic
- Remote access via VPN with multi-factor authentication
- Data centers: Tier 3 physical security and environmental controls
```
Question 7mediummultiple choice
Full question →

According to the exhibit, which role is responsible for conducting forensic analysis?

Exhibit

Refer to the exhibit.
[Incident Response Plan Roles]
Role: Incident Manager - Coordinates response
Role: Technical Lead - Performs analysis
Role: Communication Lead - Handles communications
Role: Legal Counsel - Provides legal guidance
Question 8mediummultiple choice
Read the full Ansible explanation →

Refer to the exhibit. During a ransomware incident, the response team discovers that the backup server is also encrypted. Which phase of the playbook is MOST impacted?

Exhibit

Refer to the exhibit.

---
Incident Response Playbook: Ransomware
Phase 1: Identification - Confirm ransomware via user reports and endpoint alerts.
Phase 2: Containment - Disconnect affected systems from the network. Do not power off.
Phase 3: Eradication - Remove malware using approved tools; reimage if necessary.
Phase 4: Recovery - Restore data from clean backups; verify integrity.
Phase 5: Post-Incident - Conduct lessons learned.
---
Question 9hardmultiple choice
Full question →

Based on the exhibit, what is the MOST likely issue?

Exhibit

Refer to the exhibit.

Exhibit:

Firewall Log:
Date Time Source IP Destination IP Port Protocol Action
2023-10-05 10:00:00 10.0.0.15 203.0.113.5 443 TCP ALLOW
2023-10-05 10:01:00 10.0.0.15 203.0.113.5 443 TCP ALLOW
2023-10-05 10:02:00 10.0.0.15 203.0.113.5 443 TCP ALLOW
... (repeated every minute)
2023-10-05 12:00:00 10.0.0.15 203.0.113.5 443 TCP ALLOW

IDS Alert:
Signature: ET TROJAN Win32/Malicious Beacon
Source IP: 10.0.0.15
Destination IP: 203.0.113.5
Time: 2023-10-05 10:00:00
Severity: High
Question 10hardmultiple choice
Full question →

Refer to the exhibit. An audit reveals that 20% of privileged accounts were approved by the same manager without secondary review. Which control deficiency is MOST relevant to this finding?

Exhibit

Access Control Policy:
- Users must be provisioned within 24 hours of request.
- Access reviews are conducted quarterly.
- Privileged accounts require manager approval.
- Default deny for all new accounts.
- Audit logs retained for 90 days.
Question 11easymultiple choice
Full question →

Refer to the exhibit. The security analyst observes these alerts. What is the MOST likely sequence of events?

Exhibit

Refer to the exhibit.

---
Incident Log:
[2025-03-20 08:15:23] ALERT: Multiple failed logins for user 'jsmith' from IP 10.0.0.45
[2025-03-20 08:16:01] ALERT: Successful login for user 'jsmith' from IP 10.0.0.45
[2025-03-20 08:20:45] ALERT: Unusual outbound connection from host 10.0.0.45 to 198.51.100.10:4444
[2025-03-20 08:22:30] ALERT: Large data transfer from host 10.0.0.45 to 198.51.100.10
---
Question 12easymultiple choice
Full question →

Refer to the exhibit. A security manager notices that several contractors have been granted access to a financial system without documented exceptions. Based on the policy, what is the most likely governance deficiency?

Exhibit

Refer to the exhibit.

```
Policy: Access Control
Effective Date: 2024-01-01
Review Date: 2024-12-31
Owner: CISO
Scope: All employees and contractors

Statement: Access to internal systems must be granted based on the principle of least privilege. Exceptions must be approved by the data owner and documented.
```

These CISM practice questions are part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style CISM questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.