ISACA
Free CISM Practice Test & Questions
The CISM - Certified Information Security Manager exam is up to 150 questions in 240 minutes, and the voucher costs $575. CertCrush provides 375 syllabus-aligned practice questions across all 4 exam domains, each with a full explanation. Free to try, no account required.
The Certified Information Security Manager (CISM) exam validates a professional’s ability to design, implement, and manage an enterprise information security program aligned with business objectives, focusing on governance, risk management, incident management, and security program development.
Practice content last updated · Independently written and aligned to ISACA’s published exam objectives.
10
Sample questions
240 min
Exam time limit
70%
Practice pass mark
$575
Exam voucher
About the CISM - Certified Information Security Manager Exam
The Certified Information Security Manager (CISM) is ISACA's premier certification for information security management professionals, and one of the most respected credentials a security manager or CISO can hold. Unlike technical certifications, CISM focuses on governance, programme management, risk management, and incident response — the strategic and managerial dimensions of information security. It is designed for professionals who manage, design, oversee, or assess an organisation's information security function. CISM requires five years of information security work experience, with at least three years in information security management across at least two of the four CISM domains. The credential is widely required for senior security management roles, internal audit, and compliance-facing positions, and is recognised by regulators and employers globally. CertCrush gets you exam-ready with free CISM practice test sessions, realistic practice questions and full mock exams, each answer backed by a clear explanation.
Exam Domains Covered
Exam Format & Details
The CISM exam consists of 150 multiple-choice questions over a 4-hour time limit. The passing score is 450 on a scale of 200–800. The exam covers four domains: Information Security Governance (17%), Information Risk Management (20%), Information Security Programme (33%), and Incident Management (30%). The exam is delivered through PSI test centres and online proctoring. Exam registration costs $575 USD for ISACA members and $760 for non-members. After passing, candidates must submit evidence of their work experience before the CISM designation is formally awarded.
Why Practice Questions Matter
CISM requires you to think as a security manager accountable to the board and business stakeholders — not as a hands-on practitioner. The exam consistently asks what a CISO or security manager should do first, approve, or prioritise in a given situation, with distractors that appeal to technical instinct rather than governance thinking. Candidates who have not practised extensively often choose operationally correct but strategically wrong answers. CertCrush CISM questions are designed to build the ISACA management mindset, with explanations that explain not just what the correct answer is, but why the governance principle makes it so.
Try CISM - Certified Information Security Manager
Get a taste before you commit — no account needed. Then a free account unlocks 25 questions with readiness tracking, no card required.
Get full access to CISM - Certified Information Security Manager
All questions, timed exams, flashcards, PDF study guide download & progress tracking.
This course
$9.99
one-time
Monthly
$12.99
per month · all courses
Takes 30 seconds — create a free account, then straight to checkout. Already have an account? Sign in
Sample Practice Questions
The following questions are a preview of the type of syllabus-aligned questions you will practise in CertCrush. They reflect the format and reasoning style of the CISM - Certified Information Security Manager exam — not actual exam content.
Q1.During an active security incident, the containment team must decide between two strategies: isolating the compromised segment immediately, which will disrupt a critical business process for approximately 4 hours; or implementing a targeted containment that takes longer but maintains partial business operations. Which factor should MOST influence this decision?
- A.The number of incident response team members currently available
- B.The preference of the legal counsel regarding potential liability
- C.Whether the incident occurred during business hours or after hours
- D.The rate at which the threat is actively spreading and the scope of ongoing damage
Domain: Incident Management
Q2.A multinational corporation is implementing a cross-border data transfer mechanism to move employee data from its EU subsidiary to its US headquarters. The information security manager must advise on the MOST appropriate legal mechanism following the invalidation of the EU-US Privacy Shield. What should be recommended?
- A.Implement Standard Contractual Clauses supplemented by a Transfer Impact Assessment
- B.Continue relying on the EU-US Privacy Shield framework
- C.Establish Binding Corporate Rules as the sole transfer mechanism
- D.Encrypt all data before transfer and consider the legal basis satisfied
Domain: Information Security Governance
Q3.An organization is mapping its security controls to the NIST Cybersecurity Framework (CSF) to improve communication with regulators and business partners. The security team asks which benefit is MOST significant from adopting a recognized control framework.
- A.Providing a common language and structured methodology for assessing and communicating security posture
- B.Reducing the total number of controls the organization must implement
- C.Guaranteeing compliance with all applicable regulations automatically
- D.Eliminating the need for independent risk assessments
Domain: Information Security Program
Q4.A risk owner has been informed that a newly identified vulnerability in a critical business application has a high likelihood of exploitation. The cost to remediate the vulnerability exceeds the potential loss from exploitation. Which risk treatment option is MOST appropriate?
- A.Implement the full remediation regardless of cost
- B.Accept the risk with formal documentation and ongoing monitoring
- C.Avoid the risk by decommissioning the business application
- D.Transfer the risk by purchasing cyber insurance
Domain: Information Security Risk Management
Q5.During a confirmed ransomware incident affecting multiple departments, the CSIRT lead needs to communicate status updates. Multiple stakeholders are requesting information simultaneously, including the CEO, legal counsel, affected department heads, and the media. What communication approach is MOST appropriate?
- A.Allow any incident response team member to respond to any stakeholder requests directly
- B.Follow the pre-established communication plan with designated spokespersons and tiered messaging for each audience
- C.Withhold all information until the incident is fully resolved to avoid premature disclosure
- D.Share complete technical details with all stakeholders simultaneously for full transparency
Domain: Incident Management
Q6.An organization is deciding between adopting COBIT and ISO 27001 as its primary security governance framework. The organization is a publicly traded financial services firm subject to multiple regulatory requirements. Which factor is MOST important when making this selection?
- A.Alignment of the framework with the organization's regulatory obligations and business goals
- B.Which framework the organization's primary competitor uses
- C.Availability of certification programs for the chosen framework
- D.Total implementation cost including consulting and tooling
Domain: Information Security Governance
Q7.An organization is evaluating its service continuity management capabilities. The information security manager discovers that while disaster recovery plans exist for IT systems, there are no plans for maintaining critical business processes during an extended outage. What gap does this represent?
- A.A business continuity planning gap where business process recovery is not addressed alongside IT disaster recovery
- B.A disaster recovery planning deficiency requiring additional IT recovery procedures
- C.An incident response gap in the escalation and communication procedures
- D.A capacity planning issue affecting the organization's ability to scale during outages
Domain: Information Security Program
Q8.During a risk assessment workshop, a department head insists that the risk of a ransomware attack on their department is low because they have never experienced one. The security team's analysis indicates the risk is high. How should the risk manager handle this disagreement?
- A.Present objective threat intelligence and industry data to support the risk rating methodology
- B.Override the department head's opinion and record the risk as high
- C.Escalate the disagreement to the CEO for a final decision
- D.Accept the department head's lower risk rating to maintain the relationship
Domain: Information Security Risk Management
Q9.During a ransomware incident affecting operational technology (OT) systems at a manufacturing plant, the IT incident response team wants to immediately isolate the affected OT network. The plant manager warns that abrupt isolation could cause physical safety hazards. What should the incident commander prioritize?
- A.Coordinating with plant operations to implement containment measures that maintain physical safety while limiting the spread of the ransomware
- B.Immediately isolating the OT network regardless of the plant manager's safety warnings because cyber containment takes priority
- C.Ignoring the ransomware and continuing normal operations to avoid any physical safety risks
- D.Deferring all containment decisions to the IT team because cybersecurity incidents are an IT responsibility
Domain: Incident Management
Q10.An organization subject to PCI DSS requirements has recently migrated its payment processing to a cloud-based platform. The information security manager is determining how to address compliance in this new environment. Which approach BEST ensures continued PCI DSS compliance?
- A.Review the cloud provider's Attestation of Compliance and document the shared responsibility matrix
- B.Assume the cloud provider is fully responsible for PCI DSS compliance
- C.Conduct annual on-site assessments of the cloud provider's data centers
- D.Revert to on-premises payment processing to simplify compliance
Domain: Information Security Governance
CISM - Certified Information Security Manager guides & exam news
Best GRC Certifications in 2026: CGRC vs CRISC vs CISA vs CISM (And Which One to Take First)
Four credentials dominate governance, risk and compliance hiring, and three of them will block you at the application stage if you lack the years. Here is what each GRC certification actually costs, what it tests, and the order to take them in.
How to Pass the ISACA CISM Exam in 2026: A 12-Week Study Plan for the New 3 November Content Outline
A week-by-week CISM study plan for 2026, built around ISACA's new Exam Content Outline that takes effect on 3 November 2026. Covers both scenarios: sitting before the change on the current outline, or sitting after it on the new one.
CISM Exam Is Changing on 3 November 2026: What's New and Should You Sit It Before Then?
ISACA is updating the CISM exam content outline on 3 November 2026, adding enterprise and information security architecture and shifting the focus to strategy. Here is exactly what is changing, how the domains move, and whether you should sit CISM before the deadline or wait.
CISA vs CISM: Which ISACA Certification Comes First?
A head-to-head comparison of CISA vs CISM in 2026. Cost, exam format, salary outcomes, and which ISACA certification fits audit vs management career paths.
Frequently Asked Questions
What is included in the free CISM - Certified Information Security Manager sample?
The free sample includes 10 syllabus-aligned practice questions, sample flashcards, and a preview chapter from the study guide. No account or payment is required to try the sample.
How many questions are in the full CISM - Certified Information Security Manager course?
The full course includes a comprehensive question bank covering all exam domains. You can see the total question count on the CISM - Certified Information Security Manager course page.
Are these official ISACA exam questions?
No. CertCrush questions are independently written and syllabus-aligned — they mirror the format, difficulty, and reasoning style of the official exam. We are not affiliated with or endorsed by ISACA.
Which domains does the CISM - Certified Information Security Manager course cover?
The course covers 4 exam domains: Information Security Governance, Information Security Risk Management, Information Security Program, Incident Management.
Can I study on mobile?
Yes. CertCrush is fully responsive and works on phones, tablets, and desktops. The timed exam, flashcards, and study guide all work on mobile without installing an app.
What happens when I create an account?
Creating a free account lets you access full courses, track your weak areas by domain, and resume practice sessions across devices. No credit card is required to register.