CISM Exam Prep Free practice test →

Free CISM Practice Questions

10 free, exam-style Certified Information Security Manager (CISM) practice questions with answers and explanations. No signup required. Work through them below, then take the full free CISM practice test to study every exam domain.

Question 1

Which of the following BEST describes the purpose of information security governance?

  1. To implement technical security controls
  2. To align security strategy with business objectives
  3. To manage day-to-day security operations
  4. To conduct security awareness training
Show answer & explanation

Correct answer: B - To align security strategy with business objectives

Governance exists to ensure the security strategy supports what the business is trying to achieve. Controls, operations, and training are how the program gets executed - they are outcomes of governance, not its purpose.

Question 2

What is the PRIMARY benefit of conducting regular risk assessments?

  1. To eliminate all security risks
  2. To ensure compliance with regulations
  3. To enable informed risk-based decisions
  4. To reduce security budgets
Show answer & explanation

Correct answer: C - To enable informed risk-based decisions

Risk assessments give management current information to prioritize and decide. Risk can never be eliminated entirely, compliance is a by-product, and budgets may go up or down depending on what the assessment finds.

Question 3

Which activity should be performed FIRST when developing an information security program?

  1. Implement security controls
  2. Conduct a risk assessment
  3. Establish security policies
  4. Hire security staff
Show answer & explanation

Correct answer: B - Conduct a risk assessment

Before you can write meaningful policies, choose controls, or size the team, you need to know what you are protecting and from what. The risk assessment provides that foundation, so it comes first.

Question 4

During incident response, what is the FIRST priority?

  1. Preservation of evidence
  2. Containment of the incident
  3. Notification of management
  4. Root cause analysis
Show answer & explanation

Correct answer: B - Containment of the incident

Stopping the damage from spreading comes first. Evidence handling and notifications happen alongside or right after containment per the plan, and root cause analysis is a post-incident activity.

Question 5

Which of the following is the MOST important factor for the success of an information security program?

  1. Advanced security technology
  2. Large security budget
  3. Senior management support
  4. Extensive security policies
Show answer & explanation

Correct answer: C - Senior management support

Without visible senior management support, the program loses funding, authority, and organizational cooperation. Technology, budget, and policies all flow from that commitment - CISM consistently rewards this answer pattern.

Question 6

What is the PRIMARY purpose of a risk register?

  1. To document security incidents
  2. To track identified risks and their treatment
  3. To record security policies
  4. To list security controls
Show answer & explanation

Correct answer: B - To track identified risks and their treatment

The risk register is the living inventory of identified risks, their owners, ratings, and treatment decisions. Incidents, policies, and controls are tracked in other artifacts.

Question 7

Which metric would BEST help measure the effectiveness of security awareness training?

  1. Number of training sessions conducted
  2. Percentage of employees who attended
  3. Reduction in security incidents caused by human error
  4. Amount spent on training materials
Show answer & explanation

Correct answer: C - Reduction in security incidents caused by human error

Effectiveness is measured by outcomes, not activity. Sessions held, attendance, and spend prove effort was made; fewer human-error incidents proves behavior actually changed.

Question 8

What is the PRIMARY objective of an incident response plan?

  1. To prevent all security incidents
  2. To minimize business impact of incidents
  3. To identify incident root causes
  4. To comply with regulations
Show answer & explanation

Correct answer: B - To minimize business impact of incidents

Incidents will happen - the plan exists to limit their impact on the business. Prevention is a control objective, root cause analysis is one step in the process, and compliance is secondary.

Question 9

When should risk treatment decisions be reviewed?

  1. Only when incidents occur
  2. Annually during budget planning
  3. When there are significant changes to the risk landscape
  4. Every five years
Show answer & explanation

Correct answer: C - When there are significant changes to the risk landscape

Risk treatment must stay aligned with the current risk landscape, so it is reviewed whenever significant change occurs - new threats, new systems, new business direction - not on an arbitrary calendar.

Question 10

Which of the following is MOST important when implementing a new security control?

  1. It uses the latest technology
  2. It is the least expensive option
  3. It effectively mitigates the identified risk
  4. It is easy to implement
Show answer & explanation

Correct answer: C - It effectively mitigates the identified risk

A control only has value if it reduces the risk it was selected for. Cost, convenience, and technology choices matter, but effectiveness against the identified risk is the deciding factor.

Ready for the real thing?

Practice hundreds more CISM questions with instant scoring, weak-area drills, and full exam simulations.

Start the free practice test See pricing