Try CISM - Certified Information Security Manager
Get a taste before you commit — no account needed. Then a free account unlocks 25 questions with readiness tracking, no card required.
Get full access to CISM - Certified Information Security Manager
All questions, timed exams, flashcards, PDF study guide download & progress tracking.
This course
$9.99
one-time
Monthly
$12.99
per month · all courses
Takes 30 seconds — create a free account, then straight to checkout. Already have an account? Sign in
ISACA · Exam reference
About the CISM - Certified Information Security Manager exam
The Certified Information Security Manager (CISM) exam validates a professional’s ability to design, implement, and manage an enterprise information security program aligned with business objectives, focusing on governance, risk management, incident management, and security program development.
10
Sample questions
120 min
Exam time limit
70%
Passing score
$575
Exam voucher
The Certified Information Security Manager (CISM) is ISACA's premier certification for information security management professionals, and one of the most respected credentials a security manager or CISO can hold. Unlike technical certifications, CISM focuses on governance, programme management, risk management, and incident response — the strategic and managerial dimensions of information security. It is designed for professionals who manage, design, oversee, or assess an organisation's information security function. CISM requires five years of information security work experience, with at least three years in information security management across at least two of the four CISM domains. The credential is widely required for senior security management roles, internal audit, and compliance-facing positions, and is recognised by regulators and employers globally.
Exam Domains Covered
Exam Format & Details
The CISM exam consists of 150 multiple-choice questions over a 4-hour time limit. The passing score is 450 on a scale of 200–800. The exam covers four domains: Information Security Governance (17%), Information Risk Management (20%), Information Security Programme (33%), and Incident Management (30%). The exam is delivered through PSI test centres and online proctoring. Exam registration costs $575 USD for ISACA members and $760 for non-members. After passing, candidates must submit evidence of their work experience before the CISM designation is formally awarded.
Why Practice Questions Matter
CISM requires you to think as a security manager accountable to the board and business stakeholders — not as a hands-on practitioner. The exam consistently asks what a CISO or security manager should do first, approve, or prioritise in a given situation, with distractors that appeal to technical instinct rather than governance thinking. Candidates who have not practised extensively often choose operationally correct but strategically wrong answers. CertCrush CISM questions are designed to build the ISACA management mindset, with explanations that explain not just what the correct answer is, but why the governance principle makes it so.
Sample Practice Questions
The following questions are a preview of the type of syllabus-aligned questions you will practise in CertCrush. They reflect the format and reasoning style of the CISM - Certified Information Security Manager exam — not actual exam content.
Q1.During an active security incident, the containment team must decide between two strategies: isolating the compromised segment immediately, which will disrupt a critical business process for approximately 4 hours; or implementing a targeted containment that takes longer but maintains partial business operations. Which factor should MOST influence this decision?
- A.The number of incident response team members currently available
- B.The preference of the legal counsel regarding potential liability
- C.Whether the incident occurred during business hours or after hours
- D.The rate at which the threat is actively spreading and the scope of ongoing damage
Domain: Incident Management
Q2.A multinational corporation is implementing a cross-border data transfer mechanism to move employee data from its EU subsidiary to its US headquarters. The information security manager must advise on the MOST appropriate legal mechanism following the invalidation of the EU-US Privacy Shield. What should be recommended?
- A.Implement Standard Contractual Clauses supplemented by a Transfer Impact Assessment
- B.Continue relying on the EU-US Privacy Shield framework
- C.Establish Binding Corporate Rules as the sole transfer mechanism
- D.Encrypt all data before transfer and consider the legal basis satisfied
Domain: Information Security Governance
Q3.An organization is mapping its security controls to the NIST Cybersecurity Framework (CSF) to improve communication with regulators and business partners. The security team asks which benefit is MOST significant from adopting a recognized control framework.
- A.Providing a common language and structured methodology for assessing and communicating security posture
- B.Reducing the total number of controls the organization must implement
- C.Guaranteeing compliance with all applicable regulations automatically
- D.Eliminating the need for independent risk assessments
Domain: Information Security Program
Q4.A risk owner has been informed that a newly identified vulnerability in a critical business application has a high likelihood of exploitation. The cost to remediate the vulnerability exceeds the potential loss from exploitation. Which risk treatment option is MOST appropriate?
- A.Implement the full remediation regardless of cost
- B.Accept the risk with formal documentation and ongoing monitoring
- C.Avoid the risk by decommissioning the business application
- D.Transfer the risk by purchasing cyber insurance
Domain: Information Security Risk Management
Q5.During a confirmed ransomware incident affecting multiple departments, the CSIRT lead needs to communicate status updates. Multiple stakeholders are requesting information simultaneously, including the CEO, legal counsel, affected department heads, and the media. What communication approach is MOST appropriate?
- A.Allow any incident response team member to respond to any stakeholder requests directly
- B.Follow the pre-established communication plan with designated spokespersons and tiered messaging for each audience
- C.Withhold all information until the incident is fully resolved to avoid premature disclosure
- D.Share complete technical details with all stakeholders simultaneously for full transparency
Domain: Incident Management
Frequently Asked Questions
What is included in the free CISM - Certified Information Security Manager sample?
The free sample includes 10 syllabus-aligned practice questions, sample flashcards, and a preview chapter from the study guide. No account or payment is required to try the sample.
How many questions are in the full CISM - Certified Information Security Manager course?
The full course includes a comprehensive question bank covering all exam domains. You can see the total question count on the CISM - Certified Information Security Manager course page.
Are these official ISACA exam questions?
No. CertCrush questions are independently written and syllabus-aligned — they mirror the format, difficulty, and reasoning style of the official exam. We are not affiliated with or endorsed by ISACA.
Which domains does the CISM - Certified Information Security Manager course cover?
The course covers 4 exam domains: Information Security Governance, Information Security Risk Management, Information Security Program, Incident Management.
Can I study on mobile?
Yes. CertCrush is fully responsive and works on phones, tablets, and desktops. The timed exam, flashcards, and study guide all work on mobile without installing an app.
What happens when I create an account?
Creating a free account lets you access full courses, track your weak areas by domain, and resume practice sessions across devices. No credit card is required to register.