ISACA

Free CISM Practice Test & Questions

The CISM - Certified Information Security Manager exam is up to 150 questions in 240 minutes, and the voucher costs $575. CertCrush provides 375 syllabus-aligned practice questions across all 4 exam domains, each with a full explanation. Free to try, no account required.

The Certified Information Security Manager (CISM) exam validates a professional’s ability to design, implement, and manage an enterprise information security program aligned with business objectives, focusing on governance, risk management, incident management, and security program development.

Practice content last updated · Independently written and aligned to ISACA’s published exam objectives.

10

Sample questions

240 min

Exam time limit

70%

Practice pass mark

$575

Exam voucher

About the CISM - Certified Information Security Manager Exam

The Certified Information Security Manager (CISM) is ISACA's premier certification for information security management professionals, and one of the most respected credentials a security manager or CISO can hold. Unlike technical certifications, CISM focuses on governance, programme management, risk management, and incident response — the strategic and managerial dimensions of information security. It is designed for professionals who manage, design, oversee, or assess an organisation's information security function. CISM requires five years of information security work experience, with at least three years in information security management across at least two of the four CISM domains. The credential is widely required for senior security management roles, internal audit, and compliance-facing positions, and is recognised by regulators and employers globally. CertCrush gets you exam-ready with free CISM practice test sessions, realistic practice questions and full mock exams, each answer backed by a clear explanation.

Exam Domains Covered

Information Security Governance · 17%Information Security Risk Management · 20%Information Security Program · 33%Incident Management · 30%

Exam Format & Details

The CISM exam consists of 150 multiple-choice questions over a 4-hour time limit. The passing score is 450 on a scale of 200–800. The exam covers four domains: Information Security Governance (17%), Information Risk Management (20%), Information Security Programme (33%), and Incident Management (30%). The exam is delivered through PSI test centres and online proctoring. Exam registration costs $575 USD for ISACA members and $760 for non-members. After passing, candidates must submit evidence of their work experience before the CISM designation is formally awarded.

Why Practice Questions Matter

CISM requires you to think as a security manager accountable to the board and business stakeholders — not as a hands-on practitioner. The exam consistently asks what a CISO or security manager should do first, approve, or prioritise in a given situation, with distractors that appeal to technical instinct rather than governance thinking. Candidates who have not practised extensively often choose operationally correct but strategically wrong answers. CertCrush CISM questions are designed to build the ISACA management mindset, with explanations that explain not just what the correct answer is, but why the governance principle makes it so.

Back to home
Free Sample

Try CISM - Certified Information Security Manager

Get a taste before you commit — no account needed. Then a free account unlocks 25 questions with readiness tracking, no card required.

Get full access to CISM - Certified Information Security Manager

All questions, timed exams, flashcards, PDF study guide download & progress tracking.

This course

$9.99

one-time

Buy Course

Monthly

$12.99

per month · all courses

Monthly Plan
Best value

Annual

$79.99

Save 49% · all courses

Annual Plan

Takes 30 seconds — create a free account, then straight to checkout. Already have an account? Sign in

Sample Practice Questions

The following questions are a preview of the type of syllabus-aligned questions you will practise in CertCrush. They reflect the format and reasoning style of the CISM - Certified Information Security Manager exam — not actual exam content.

Q1.During an active security incident, the containment team must decide between two strategies: isolating the compromised segment immediately, which will disrupt a critical business process for approximately 4 hours; or implementing a targeted containment that takes longer but maintains partial business operations. Which factor should MOST influence this decision?

  • A.The number of incident response team members currently available
  • B.The preference of the legal counsel regarding potential liability
  • C.Whether the incident occurred during business hours or after hours
  • D.The rate at which the threat is actively spreading and the scope of ongoing damage

Domain: Incident Management

Q2.A multinational corporation is implementing a cross-border data transfer mechanism to move employee data from its EU subsidiary to its US headquarters. The information security manager must advise on the MOST appropriate legal mechanism following the invalidation of the EU-US Privacy Shield. What should be recommended?

  • A.Implement Standard Contractual Clauses supplemented by a Transfer Impact Assessment
  • B.Continue relying on the EU-US Privacy Shield framework
  • C.Establish Binding Corporate Rules as the sole transfer mechanism
  • D.Encrypt all data before transfer and consider the legal basis satisfied

Domain: Information Security Governance

Q3.An organization is mapping its security controls to the NIST Cybersecurity Framework (CSF) to improve communication with regulators and business partners. The security team asks which benefit is MOST significant from adopting a recognized control framework.

  • A.Providing a common language and structured methodology for assessing and communicating security posture
  • B.Reducing the total number of controls the organization must implement
  • C.Guaranteeing compliance with all applicable regulations automatically
  • D.Eliminating the need for independent risk assessments

Domain: Information Security Program

Q4.A risk owner has been informed that a newly identified vulnerability in a critical business application has a high likelihood of exploitation. The cost to remediate the vulnerability exceeds the potential loss from exploitation. Which risk treatment option is MOST appropriate?

  • A.Implement the full remediation regardless of cost
  • B.Accept the risk with formal documentation and ongoing monitoring
  • C.Avoid the risk by decommissioning the business application
  • D.Transfer the risk by purchasing cyber insurance

Domain: Information Security Risk Management

Q5.During a confirmed ransomware incident affecting multiple departments, the CSIRT lead needs to communicate status updates. Multiple stakeholders are requesting information simultaneously, including the CEO, legal counsel, affected department heads, and the media. What communication approach is MOST appropriate?

  • A.Allow any incident response team member to respond to any stakeholder requests directly
  • B.Follow the pre-established communication plan with designated spokespersons and tiered messaging for each audience
  • C.Withhold all information until the incident is fully resolved to avoid premature disclosure
  • D.Share complete technical details with all stakeholders simultaneously for full transparency

Domain: Incident Management

Q6.An organization is deciding between adopting COBIT and ISO 27001 as its primary security governance framework. The organization is a publicly traded financial services firm subject to multiple regulatory requirements. Which factor is MOST important when making this selection?

  • A.Alignment of the framework with the organization's regulatory obligations and business goals
  • B.Which framework the organization's primary competitor uses
  • C.Availability of certification programs for the chosen framework
  • D.Total implementation cost including consulting and tooling

Domain: Information Security Governance

Q7.An organization is evaluating its service continuity management capabilities. The information security manager discovers that while disaster recovery plans exist for IT systems, there are no plans for maintaining critical business processes during an extended outage. What gap does this represent?

  • A.A business continuity planning gap where business process recovery is not addressed alongside IT disaster recovery
  • B.A disaster recovery planning deficiency requiring additional IT recovery procedures
  • C.An incident response gap in the escalation and communication procedures
  • D.A capacity planning issue affecting the organization's ability to scale during outages

Domain: Information Security Program

Q8.During a risk assessment workshop, a department head insists that the risk of a ransomware attack on their department is low because they have never experienced one. The security team's analysis indicates the risk is high. How should the risk manager handle this disagreement?

  • A.Present objective threat intelligence and industry data to support the risk rating methodology
  • B.Override the department head's opinion and record the risk as high
  • C.Escalate the disagreement to the CEO for a final decision
  • D.Accept the department head's lower risk rating to maintain the relationship

Domain: Information Security Risk Management

Q9.During a ransomware incident affecting operational technology (OT) systems at a manufacturing plant, the IT incident response team wants to immediately isolate the affected OT network. The plant manager warns that abrupt isolation could cause physical safety hazards. What should the incident commander prioritize?

  • A.Coordinating with plant operations to implement containment measures that maintain physical safety while limiting the spread of the ransomware
  • B.Immediately isolating the OT network regardless of the plant manager's safety warnings because cyber containment takes priority
  • C.Ignoring the ransomware and continuing normal operations to avoid any physical safety risks
  • D.Deferring all containment decisions to the IT team because cybersecurity incidents are an IT responsibility

Domain: Incident Management

Q10.An organization subject to PCI DSS requirements has recently migrated its payment processing to a cloud-based platform. The information security manager is determining how to address compliance in this new environment. Which approach BEST ensures continued PCI DSS compliance?

  • A.Review the cloud provider's Attestation of Compliance and document the shared responsibility matrix
  • B.Assume the cloud provider is fully responsible for PCI DSS compliance
  • C.Conduct annual on-site assessments of the cloud provider's data centers
  • D.Revert to on-premises payment processing to simplify compliance

Domain: Information Security Governance

Frequently Asked Questions

What is included in the free CISM - Certified Information Security Manager sample?

The free sample includes 10 syllabus-aligned practice questions, sample flashcards, and a preview chapter from the study guide. No account or payment is required to try the sample.

How many questions are in the full CISM - Certified Information Security Manager course?

The full course includes a comprehensive question bank covering all exam domains. You can see the total question count on the CISM - Certified Information Security Manager course page.

Are these official ISACA exam questions?

No. CertCrush questions are independently written and syllabus-aligned — they mirror the format, difficulty, and reasoning style of the official exam. We are not affiliated with or endorsed by ISACA.

Which domains does the CISM - Certified Information Security Manager course cover?

The course covers 4 exam domains: Information Security Governance, Information Security Risk Management, Information Security Program, Incident Management.

Can I study on mobile?

Yes. CertCrush is fully responsive and works on phones, tablets, and desktops. The timed exam, flashcards, and study guide all work on mobile without installing an app.

What happens when I create an account?

Creating a free account lets you access full courses, track your weak areas by domain, and resume practice sessions across devices. No credit card is required to register.