Limited-Time Offer: Enjoy 50% Savings! - Ends In 0d 00h 00m 00s Coupon code: 50OFF
Free Exam Questions

CITM Exam Questions & Answers

EXIN EPI Certified Information Technology Manager  •  Exin

50 Questions 75 min Updated Sep 2026 99% Pass Rate
Get Full Access

100% money-back guarantee

Sample CITM Questions

Practice with real exam-style questions, each with the verified correct answer and explanation.

Q1 MultipleChoice

Lately, the support desk is receiving several requests for password resets from individuals who appear to be unknown to the organization. Possible criminal activities are suspected, and the organization wishes to address this issue in their information security awareness program. What is the area that requires awareness?

Correct Answer: D
Explanation:

Requests for password resets from unknown individuals suggest social engineering attacks, such as phishing or impersonation, where attackers manipulate users to gain unauthorized access. An information security awareness program should focus on educating staff about social engineering tactics to recognize and prevent such incidents.

E-mail usage (A), instant messaging (B), and internet usage (C) may be vectors for attacks, but the core issue is social engineering, which encompasses tactics used across these channels.

Q2 MultipleChoice

In vendor selection, what is the most important reason for a reference check?

Correct Answer: A
Explanation:

The most important reason for a reference check in vendor selection is to independently verify and validate a vendor's claim (A). Reference checks involve contacting the vendor's previous or current clients to confirm claims about performance, reliability, and service quality, ensuring the vendor can meet contractual obligations. This aligns with vendor management best practices to mitigate risks by validating vendor credibility.

Verify products by other customers (B): Too narrow; reference checks focus on overall performance, not just products.

Obtain financial information (C): Financial data is obtained through financial due diligence, not reference checks.

Identify customers not mentioned (D): Not a primary goal; the focus is on validating provided references.

Q3 MultipleChoice

When selecting a new vendor, continuity needs to be guaranteed as much as possible. At a minimum, which criteria are considered?

Correct Answer: D
Explanation:

To ensure continuity in vendor selection, the key criteria include head count (vendor's staffing capacity to deliver services), support (availability of ongoing technical and operational support), and financial stability (ensuring the vendor remains viable to provide services long-term). These factors directly impact the vendor's ability to maintain service delivery without interruptions, which is critical for business continuity.

Scope, maintenance, and price (A): Scope and price are important but don't directly ensure continuity; maintenance is a subset of support.

Terms and conditions, maintenance, and terms of engagement (B): These are contractual elements, but they don't fully address operational continuity like staffing or financial stability.

Price, training, and support (C): Training is less critical for continuity compared to staffing capacity or financial health.

According to vendor management frameworks, continuity is ensured by evaluating the vendor's operational capacity and long-term reliability, making head count, support, and financial stability the minimum criteria.

Q4 MultipleChoice

The team responsible for network security has proposed a firewall as the preferred control for the network perimeter. How is this type of control categorized?

Correct Answer: A
Explanation:

A firewall is categorized as a technical preventive control (A) in information security management. According to ISO/IEC 27001, preventive controls aim to stop security incidents before they occur, and technical controls involve technology-based solutions. A firewall prevents unauthorized access to the network perimeter by filtering traffic, making it a technical preventive control.

Physical detective control (B): Involves physical measures (e.g., cameras) to detect incidents, not applicable to firewalls.

Administrative deterrent control (C): Involves policies or procedures to discourage violations, not technology-based.

Physical corrective control (D): Addresses physical issues post-incident, not relevant to firewalls.

Q5 MultipleChoice

Before the marketing department will decide on a new advertising campaign, it wants to be able to gain more insights into the customer, being able to predict the products customers will purchase in the near future. What is a 'must-have' criterion in terms of the technology the marketing department is interested in?

Correct Answer: B
Explanation:

To predict future customer purchases, the marketing department requires advanced analytics (B), which involves sophisticated data analysis techniques, such as predictive modeling, machine learning, and data mining. These technologies enable the department to analyze customer behavior, identify patterns, and forecast purchasing trends, supporting targeted advertising campaigns.

Records Management System (RMS) (A): Focuses on managing and storing records, not predictive analysis.

Ad hoc analysis (C): Allows for on-demand, one-off queries but lacks the predictive capabilities of advanced analytics.

Business Intelligence (BI) (D): Provides reporting and historical data analysis but is less focused on predictive modeling compared to advanced analytics.

Advanced analytics aligns with IT strategy goals of leveraging data for competitive advantage, as it supports predictive insights critical for marketing decisions.

Get access to all 50 verified questions with detailed answers.

Unlock All CITM Questions

Frequently Asked Questions

The CITM is a professional certification offered by EXIN that validates an individual's knowledge and competency in IT management. It is designed for IT professionals who want to demonstrate their expertise in managing IT operations, services, and resources according to ITIL and other best practices.

While EXIN typically recommends having some IT management experience, there are no strict formal prerequisites for the CITM exam. However, candidates should have foundational knowledge of IT service management concepts and ideally some practical experience in IT operations or management roles.

The CITM exam is usually a multiple-choice test lasting 90 minutes with 60 questions. Candidates typically need to achieve a score of 65% or higher to pass the certification.

Preparation for the CITM exam should include studying official EXIN study materials, ITIL frameworks, and IT management best practices. Many candidates also benefit from taking instructor-led training courses, using practice exams, and gaining hands-on experience in IT management roles.

Yes, the CITM certification is recognized internationally as it is issued by EXIN, a globally respected certification body. It can enhance career prospects by demonstrating IT management competency, potentially leading to better job opportunities, higher salaries, and career advancement in IT management positions.
Exam Details
  • Exam CodeCITM
  • VendorExin
  • Total Questions50
  • Duration75 min
  • LanguageEnglish
  • Last UpdatedSep 4, 2026
4.9/5

Pass CITM First Time

Get all 50 exam questions with verified answers and 90-day free updates.

Buy Now & Pass
  • PDF + Practice Test Bundle
  • 90-Day Free Updates
  • 100% Money-Back Guarantee
  • Instant Download
  • 24/7 Customer Support
99% Pass Rate Trusted by 50,000+ IT professionals